open·kritt
Self-host the orchestration and choose your models, workflows, repositories, and severity rules.
- Local or remote repositories
- Bring Codex or Claude Code
- Custom workflows and agent skills
Kritt breaks a codebase into focused security tasks, runs AI agents in parallel, and turns their work into ranked, verified findings. Self-host the open-source engine or let our researchers run it for you.
License
AGPL-3.0
Targets
Local + GitHub
Output
Ranked findings
release-candidate-42
security workflow
Map attack surface
Fan out agent research
Verify exploit paths
Rank + de-duplicate
State transition can bypass finality check
Verified path · duplicate check passed · report draft ready
open·kritt is the open-source distillation of our internal workflow: decompose the codebase, run agents against focused tasks, and turn their output into ranked findings you can inspect and extend.
Turn a broad review into small, typed prompt steps that agents can reason about well.
Fan work out across functions, files, and hypotheses, then recombine the useful results.
Run post-scripts per finding to validate exploitability, build a PoC, or draft a report.
Rank, normalize, and de-duplicate findings against the impact criteria that matter to you.
Run open·kritt on your own infrastructure, or have our security research team operate a managed scan for you. Managed engagements start with a short call to align on scope, authorization, and timing.
Self-host the orchestration and choose your models, workflows, repositories, and severity rules.
We run the research workflow and deliver a written report of the high-impact findings we validate.
Tailored security research for teams that need CI/CD, release coverage, custom volumes, and SLAs.
Kritt was shaped by the same workflows our team uses in public bug-bounty research. The Blockian record shows the kind of verified, high-impact work the system was built to support.
Book a demo and we will scope the engagement directly with you before any work or payment begins.
Choose a time and tell us what kind of code security problem you are trying to solve.
We align on repositories, languages, lines of code, authorization, priorities, and timing.
You receive a clear plan covering deliverables, commercial terms, and the path to kickoff.
Talk directly with the team that will scope and operate the research, from initial priorities through kickoff and reporting.
What changes between running the open-source platform yourself and asking Kritt to run a managed scan.
Tell us what you are protecting, where the risk is concentrated, and what success looks like. We will map the right managed research plan with you.