Skip to content
NoHack CodeWhite-box · SAST · SCA · Secrets

Audit the code the way an attacker reads it.

NoHack Code turns your repository into a code graph, finds every entry point, and follows each one through its full call chain before a model judges it. Injection findings carry a deterministic taint proof. Dependencies and secrets are audited in the same pass.

language families with semantic parsers
9
language families with semantic parsers
analysis tiers, matched to parser depth
3
analysis tiers, matched to parser depth
dependency ecosystems, plus containers
16
dependency ecosystems, plus containers
CVSS on every finding
v4.0
CVSS on every finding
01

From repository to proven finding.

Deterministic where it can be, agentic where it has to be.

  1. 01 · index

    Index the code graph

    Language-specific parsers for JS/TS, Java, PHP, Go, Python, Ruby, C#, Rust, and C/C++ produce one normalized graph of functions, calls, and types.

  2. 02 · map

    Map every entry point

    Framework-aware route detection for Spring, Express, ASP.NET, Flask, Rails, Actix, and more, plus non-HTTP entry points like gRPC, queue consumers, WebSockets, and scheduled jobs.

  3. 03 · profile

    Profile the application

    The agent works out what the app is, how it authenticates, and which classes of bug matter for it, so effort goes where the risk is.

  4. 04 · analyse

    Analyse with the full chain

    Each endpoint is judged with its pre-stitched call chain. Where the graph is thin, the agent explores outward with code search and read tools.

  5. 05 · prove

    Prove the data flow

    Injection-class findings get a deterministic taint path from source to sink. Fail-closed: a sanitizer only counts if it transforms the value that reaches the sink.

  6. 06 · rate

    Rate, fix, retest

    CVSS v4.0 scored from the vector, a specific fix for your code, and a retest that reports fixed, still present, or uncertain.

02

What ships with every audit.

Call-chain context

The model sees how input actually travels through your code, not one file at a time. Pattern matching alone is where false positives come from.

Three tiers of analysis

Semantic analysis on a strong graph, agentic exploration from each endpoint when the graph is partial, and full-repository exploration as a last resort.

Beta

Dependency reachability

Vulnerable packages ranked by function-level reachability, CISA KEV, and EPSS, with an upgrade path and a CycloneDX SBOM.

Verified secrets

TruffleHog detectors across the repository. Verified secrets are raised as high severity, and raw values are redacted before they are stored.

Strict, standard, comprehensive

Pick how much evidence a finding needs before it is reported. Triage states (confirmed, won’t fix, false positive, duplicate) stick across audits.

SARIF out

Export to SARIF 2.1.0 for GitHub code scanning, or CSV and DOCX for the people who read reports.

03

A taint path, not a guess.

What an injection finding carries when it reaches your queue.

  • 01 · Taint path

    Source, every call in between, and the sink, with file and line for each hop.

  • 02 · Rating

    A CVSS v4.0 vector chosen metric by metric, with the score computed from it, not estimated.

  • 03 · Fix

    A change written for your code, not a link to a cheat sheet.

  • 04 · Retest

    After you push the fix, a retest reports fixed, still present, or uncertain, and adjusts the rating if the fix is partial.

CriticalTaint verifiedSample finding

SQL injection in order search

endpoint
POST /api/orders/search
weakness
CWE-89
cvss
9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

01 · Taint path · white-boxno sanitizer on path

  1. sourcereq.body.qroutes/orders.ts:42
  2. →OrderService.search(q)services/order.ts:88
  3. →buildFilter(q)services/order.ts:131
  4. sinkdb.raw(`…LIKE '%${q}%'`)db/orders.ts:57

02 · Rating · CVSS v4.09.3 critical

AV:N
route is reachable from the internet
PR:N
no auth middleware on the route chain
VC:H
attacker-controlled SQL reads every order
VI:H
same statement allows writes to orders

03 · Fix · db/orders.ts

- db.raw(`SELECT * FROM orders WHERE name LIKE '%${q}%'`)+ db('orders').whereLike('name', `%${q}%`)
NH-2291-007sha256:76e7…ca71Retest after fix

04 · Questions

What teams ask before an audit.

Something else? Email us.

Which languages are supported?

Dedicated semantic parsers cover JavaScript and TypeScript, Java, PHP, Go, Python, Ruby, C#, Rust, and C/C++. For other languages the agent falls back to agentic exploration of the repository.

How is this different from a rule-based SAST tool?

Rules match patterns in a file. NoHack Code judges each entry point with the call chain that reaches it, profiles what the application is, and attaches a deterministic taint proof to injection findings. A finding explains why it is exploitable, not just where it matched.

Does our code leave our environment?

With the self-hosted deployment, no: the platform runs in your own cloud or data centre, and every agent can be routed through your own model gateway. On the hosted platform, code is processed by the model providers the platform is configured with. Tell us your requirements and we will walk you through them.

What happens when an audit hits its budget?

It pauses and resumes from where it stopped, so the work already done is not paid for twice. A capped audit is never reported as clean.

Security at the speed you ship.

Bring a repository, a web app, or an APK. We will walk you through a real audit of it.