Code Security

Secure every change, no matter which AI wrote it.

CodeMarine continuously checks the code AI produces, the packages it adds and the actions it takes. Known risks are caught locally on every change. Frontier models investigate the hard cases.

Every AI can write code. CodeMarine secures what lands.One continuous check across agents, editors and CI.

ClaudeCodexCursorWindsurf
Code, packages and actions

CodeMarineOne independent security layer

  • 01

    Secure every changeFind security problems in code as agents work.

  • 02

    Check what entersVerify packages, MCP servers, skills and instructions.

  • 03

    Guard dangerous actionsBlock known destructive commands on supported paths.

One codebase. One policy. Every AI.Workspace · Hooks · CI

A security system, not a collection of scanners.

Code, dependencies, actions and model investigations share the same policy and evidence.

01 Current

Code Integrity

Local-first scanning, shared rule execution, structural confirmation and graph context across the workspace.

02 Current

Supply Chain

Package identity, provenance, manifests, lockfiles, install behavior and AI tool configuration.

03 Beta

Runtime Policy

Deterministic action evaluation and provider adapters for defined pre-execution paths.

04 Planned

Tool and Authority

Governed MCP and API paths with scoped credentials and trusted target context.

05 Planned

Evidence

Revision-bound proof, action receipts, operational health and explicit coverage gaps.

06 Planned

Frontier Intelligence

Focused escalation, model investigation, isolated remediation and deterministic patch validation.

Fast checks first. Deeper intelligence by policy.

Local checks cover the continuous path. Selected cases move to an approved model.

  1. 01
    EVENTA file, dependency or action changes

    CodeMarine records the workspace and revision context.

  2. 02
    LOCAL DECISIONDeterministic engines evaluate it

    Known policy produces a reproducible result.

  3. 03
    BRANCHAct now or escalate

    Clear findings warn or block. Ambiguous cases can move to an approved model.

  4. 04
    VALIDATECodeMarine checks the outcome

    A patch must pass the deterministic gate and match the expected revision.

  5. 05
    RETAINEvidence becomes durable

    Verified discoveries can become regression fixtures and new controls.

Local-first by default. Connected when the workflow needs it.

CodeMarine separates local deterministic work from optional managed intelligence and model calls. A team can choose the right privacy and cost boundary for each workspace.

Code scans run locally. Frontier investigation only sends approved, bounded context.
Current

Local deterministic path

High-frequency code, dependency and policy checks run without sending every change to a model.

Current

Managed intelligence

Signed updates and service-backed features can extend local checks where configured.

Planned

Optional specialist models

Small local security models can help narrow candidate files. Their output remains probabilistic evidence.

Planned

Frontier investigation

Approved models receive bounded context for novel or high-impact cases.

The author changes. The security contract does not.

One policy follows the workspace. Provider integrations add earlier control where the host supports it.

Developer

Quiet during normal work

Continuous checks stay close to the workspace. High-confidence catastrophe policy can intervene on supported paths without turning every command into a permission ceremony.

Engineering

One view across agent choice

Teams can adopt different frontier tools while code, dependency and action evidence converge on one policy model.

Security

Coverage you can challenge

Per-surface status separates capability, setup, health and proof.

Put one security contract around your AI toolchain.

Start with continuous deterministic protection. Add provider-specific controls as each surface becomes proof-backed.

Sarge, the CodeMarine guardian