About
Who builds Korthex
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex is being developed by Flowence Infrastructure, a company founded in 2025 and based in Germany. Currently, Korthex is being developed solely by its founder. This means he writes the scanner, curates the baseline rules, and maintains this website.
Why this product exists?
Every organisation knows roughly which libraries it depends on. Almost none can answer which cipher, which key length, and which certificate is actually in use, at which line of which file. That question became urgent the moment NIST published FIPS 203, 204 and 205, because a migration plan needs an inventory first, and the inventory did not exist.
Korthex was built to answer it from the source rather than from the network: static analysis over 18 languages, binaries, databases, TLS material and git history, on the machine that holds the code. That constraint - nothing leaves the machine - is the reason the product is on-premise rather than SaaS, and it is why there is no cloud tier to sign up for.
Who is responsible for what
- Rule curation: which authority baseline a finding is graded against, and in which order. The priority chain is NIST, then BSI, IETF, OWASP, CISA, ANSSI, and last the Korthex-curated set.
- The baseline registry: 11,664 rules across 25 headers, re-checked on a 24-hour cycle and shipped as signed updates.
- The published ladder: 35 documented status rows, held against the engine's own enum by a build gate that fails on any drift.
- This site: every page, both languages, and the build gates that keep its claims honest.
How to check the claims rather than trust them
Three pages carry the evidence rather than the assertion, and they are the ones worth reading before the marketing copy.
- Scan duration: a cost model derived from named measurements, including the point where the model stops and says so.
- Editorial standards: the build gates that refuse to ship a claim without its evidence, named individually.
- Measurement methodology: how accuracy is defined, what is measured against, and what the measurement does not show.
Contact
Correction, question, or a claim on this site you can disprove: contact@flowencehq.com. Security reports have their own channel, described on the security page and in /.well-known/security.txt.
The full provider identification, including postal address and the person responsible for editorial content under Section 18(2) MStV, is in the imprint.
Frequently asked questions
Who develops Korthex?
Hendrik Schneider, at Flowence Infrastructure - a sole proprietorship registered in Recklinghausen, Germany, founded in 2025. Korthex is one of its products.
Is Korthex an open-source project?
No. Korthex is proprietary software with a free tier that carries the complete detection engine. The rule baselines it grades against are public standards - NIST, BSI, IETF, OWASP, CISA and ANSSI - and every finding names the rule it came from.
Where is Korthex developed?
In Germany. That matters for two of its users in particular: BSI TR-02102 and IT-Grundschutz are the baseline the product was designed around first, and the on-premise architecture means no scan data crosses a border because none of it leaves the machine.