Open source orchestration · managed research

    Find vulnerabilities thatsurvive review.

    Kritt breaks a codebase into focused security tasks, runs AI agents in parallel, and turns their work into ranked, verified findings. Self-host the open-source engine or let our researchers run it for you.

    License

    AGPL-3.0

    Targets

    Local + GitHub

    Output

    Ranked findings

    release-candidate-42

    security workflow

    live
    01

    Map attack surface

    12 tasks
    02

    Fan out agent research

    running
    03

    Verify exploit paths

    3 candidates
    04

    Rank + de-duplicate

    1 high
    highconfidence 0.92

    State transition can bypass finality check

    Verified path · duplicate check passed · report draft ready

    Open source · AGPL-3.0

    The research loop,made inspectable.

    open·kritt is the open-source distillation of our internal workflow: decompose the codebase, run agents against focused tasks, and turn their output into ranked findings you can inspect and extend.

    Explore open·krittRead the launch storyCodex + Claude Code harnesses
    quick startself-hosted
    $ git clone https://github.com/Kritt-ai/open-kritt
    $ cd open-kritt
    $ ./kritt setup
    ✓ model access configured
    ✓ local workspace ready
    $ ./kritt start
    → UI running at localhost:5173

    Focused workflows

    Turn a broad review into small, typed prompt steps that agents can reason about well.

    Parallel agent runs

    Fan work out across functions, files, and hypotheses, then recombine the useful results.

    Verification passes

    Run post-scripts per finding to validate exploitability, build a PoC, or draft a report.

    Your severity rules

    Rank, normalize, and de-duplicate findings against the impact criteria that matter to you.

    Choose your path

    Use the engine your way.

    Run open·kritt on your own infrastructure, or have our security research team operate a managed scan for you. Managed engagements start with a short call to align on scope, authorization, and timing.

    Run it yourself

    open·kritt

    FreeAGPL-3.0

    Self-host the orchestration and choose your models, workflows, repositories, and severity rules.

    • Local or remote repositories
    • Bring Codex or Claude Code
    • Custom workflows and agent skills
    View on GitHub
    Teams & continuous coverage

    Enterprise

    Contact us

    Tailored security research for teams that need CI/CD, release coverage, custom volumes, and SLAs.

    • Dedicated support
    • PR and release scanning
    • Custom volumes and SLAs
    Contact us
    Projects & ecosystems

    Helped secure production code across leading networks.

    Research track record

    Built from real security work.

    Kritt was shaped by the same workflows our team uses in public bug-bounty research. The Blockian record shows the kind of verified, high-impact work the system was built to support.

    Managed research

    Start with a conversation, not an account.

    Book a demo and we will scope the engagement directly with you before any work or payment begins.

    01

    Book a demo

    Choose a time and tell us what kind of code security problem you are trying to solve.

    02

    Share the scope

    We align on repositories, languages, lines of code, authorization, priorities, and timing.

    03

    Confirm the engagement

    You receive a clear plan covering deliverables, commercial terms, and the path to kickoff.

    One next step

    Book a demo

    Talk directly with the team that will scope and operate the research, from initial priorities through kickoff and reporting.

    Book a demo
    FAQ

    Straight answers.

    What changes between running the open-source platform yourself and asking Kritt to run a managed scan.

    Your next security run

    Bring us your hardest codebase.Let’s scope the right engagement.

    Tell us what you are protecting, where the risk is concentrated, and what success looks like. We will map the right managed research plan with you.