KORTHEXDocumentation

Docs / FUNDAMENTALS

FUNDAMENTALS

Architecture at a Glance

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex is composed of 14 specialized engines that cooperate around a single shared truth source. This page is the bird's-eye view: how the engines connect, what flows between them, and when each runs.

The Pipeline

Every Korthex run starts at the Scanner and fans out to the analytical engines. The Baseline Registry sits underneath as the shared truth source - every other engine consults it. Input Source code · Binaries · Configuration · Runtime processes ↓ Stage 1 Scanner AST · Binary · Runtime · TLS · Git · Config ↓ Stage 2 Context Engine Dataflow · Taint analysis · Cross-file clustering · FP filtering ↓ Stage 3 - analytical fan-out Inventory CBOM · SBOM Impact Audience reports Dataflow Graph queries Policy CI gate · SARIF Planner Migration plan Neural Network On-device hints Runtime Agent Live observation Exploit PoC evidence ↓ Shared truth source - consulted by every stage above Baseline Registry 11 500+ algorithm rules · classification · min-key-bits · deadlines Side-band engines Accuracy Engine - precision/recall/F1 measurement against ground-truth corpora. Mesh-Relay - outbound event forwarding for fleet-scale Enterprise deployments. Auto Migration (V2) - consumes Planner output, executes context-aware code rewrites with diff-review.

Engine Roles

EngineAsksAnswersProduces
ScannerWhat crypto is used and where?Per-file findings.Findings JSON / .krx
Context EngineWhich findings actually matter?Reduced false positives, clusters, cross-file groupings.Enriched findings
Baseline RegistryIs this algorithm strong enough?recommended / acceptable / deprecated / disallowed.Lookup table
InventoryWhat cryptography do we have, in total?Comprehensive crypto-asset list..kxi + CycloneDX + SPDX
ImpactWhat's the business impact?Per-audience risk reports.JSON / PDF per audience
DataflowHow does this key flow through the system?Graph of crypto relationships..kxg.* (6 variants)
PolicyDoes this scan pass our rules?BLOCK / WARN / ALLOW verdicts.SARIF / JUnit / JSON + exit code
PlannerHow do we fix it?Sequenced migration plan with hours + deadlines..krx (plan) + PDF
Neural NetworkHow confident is this detection?On-device ML hints for ambiguous patterns.Predictions consumed by other engines
Runtime AgentWhat does the code do at runtime?Live observations from a running process..krxr
ExploitIs this finding actually exploitable?Proof-of-concept evidence per finding.SARIF / JSON
Auto Migration (V2)Can we just fix it?Context-aware automatic rewrites.Working-tree diff
AccuracyIs the scanner getting better?Precision / recall / F1 measurement.Measurement JSON
Mesh-RelayHow do multiple installations coordinate?Forwarded scan events.Wire events (signed)

When Each Engine Runs

PhaseEngines active
ScanScanner -> Context Engine -> Neural Network Engine (hints) -> Baseline Registry (lookups throughout).
Post-scan analyticsInventory, Impact, Dataflow, Policy, Planner, Exploit. Each runs independently against the scan output.
MigrationPlanner produces the plan; (V1) Migrate simulate previews; (V2) Auto Migration executes; Accuracy measures success.
OperationsRuntime Agent (on-demand against live processes). Mesh-Relay (continuous, when enabled).
MaintenanceAccuracy Engine (regression testing). Baseline-Registry refresh (monthly update bundles).

Key Architectural Decisions

Offline-first. Every engine runs locally. No source code or scan data leaves the machine unless you opt in to telemetry, the Dashboard, or Mesh-Relay. Single truth source. The Baseline Registry is the only place algorithm classification lives. Severity, ELS, compliance verdicts, and migration recommendations all derive from it - so they stay consistent. Stable file formats. Every Korthex artifact has a defined extension, format, and compatibility policy. See File Format Reference . CI-native. Every analytical engine that produces output produces SARIF as an option, so findings flow into the platform you already use. Fail-closed where it matters. Exploit Engine is gated by default; Mesh-Relay requires a TLS pin file or refuses to start; license issues stop the engine rather than continuing degraded. On-device ML. The Neural Network Engine never sends inputs over the network - only optional model-version checks with explicit consent.