Noctrodex SAST
Sovereign, air-gapped Static Application Security Testing for 16 GB local hardware — deterministic vulnerability analysis, taint tracking, and fully offline local scanning.
// What it is
Noctrodex SAST reads your source code and finds security-relevant defects before anything ships — without your code ever leaving the machine. It runs locally, air-gapped, on modest hardware (16 GB), so proprietary and regulated codebases are analysed on infrastructure you control. No cloud upload, no per-query metering, no phone-home.
// Key capabilities
- Deterministic vulnerability analysis — repeatable results you can gate a pipeline on, not a black-box score that changes run to run.
- Taint tracking — follows untrusted input from source to sink to surface injection, traversal, and unsafe-flow classes with the path that proves them.
- Offline local scanning — point it at a project directory and scan; the engine and its rule corpus are on-device.
- Multi-language — parses Python, JavaScript/TypeScript, Go, Java, C/C++, Bash, PHP and more via bundled grammars.
- War Room GUI + CLI — a desktop War Room for interactive review, and a scriptable CLI for CI and batch runs.
// How it runs
The product ships as a single signed installer for Windows (.msi) and Linux (.deb), with a compiled, obfuscated engine — no source exposure, no interpreter to manage. The optional Helix AI model is a separate, on-device download tied to your account. Everything executes on your perimeter.
// Licensing
Noctrodex SAST is a commercial release under account-based, device-locked licensing: you create an account, buy a licence, and activate it on your device — activation is offline (you paste a device code and install a signed licence file back). One active device at a time, with unlimited moves. Your licence is valid for one year.
Ready to run it on your own hardware?
Create your account and buy a licence — downloads unlock on your account page after purchase.
⚡ Create Account & Buy Licence →Already have an account? Sign in. Questions first? Contact us.