KORTHEXDocumentation

Docs / OUTPUT & MIGRATION

OUTPUT & MIGRATION

File Format Reference

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex uses ~30 custom file formats across its engines. This section is the authoritative catalog: every extension, what it stores, whether it's encrypted, whether it's user-editable, and the recommended tooling for inspecting it. User-edit policy. Every Korthex-generated .json file can be user-edited, but this is not recommended unless you know what you are doing - the engines validate strictly and a malformed file will be rejected on next load. Encrypted formats ( .kxi , .kxg , etc.) cannot be hand-edited at all: any modification invalidates the integrity check and the file is refused on load.

Encrypted Core Formats

All encrypted with authenticated cryptography. Sealed with a key derived from your license + machine binding so a file is only readable on the installation that produced it (or on an installation explicitly authorized to consume it, e.g. via a .kxw workspace bundle).

ExtensionPurposeEngineUser-editable
.krxScan report. Also serves as the canonical container for migration plans.Scanner / PlannerNo
.kxiCryptographic-inventory snapshot. Backs CycloneDX / SPDX exports.InventoryNo
.kxgDataflow graph (with sub-variants below). Magic 'KXGRAPH\0' when plaintext.DataflowNo
.kxnnNeural Network model weights + vocabulary + signature.Neural NetworkNo
.kxnn.sigDetached signature over .kxnn. Refuses to load on mismatch.Neural NetworkNo
.kxaExploit-Engine attack-pattern database. Korthex-internal key.ExploitNo
.kxtEncrypted HTML report template.ReportNo
.kxjsEncrypted JS bundle for report templates.ReportNo
.kxcssEncrypted CSS for report templates.ReportNo
.kxvViewer-bundle: report + assets in a single sealed container.ReportNo
.kxpEncrypted, canonical policy file. The .korthex_policy.json variant is its human-editable plain-JSON equivalent.PolicyNo
.kxmMesh / migration container.Mesh-RelayNo
.kxwWorkspace bundle. Passphrase-encrypted; portable across machines.DashboardNo
.krxrRuntime-Agent encrypted report (V3).Runtime AgentNo

.kxg Sub-variants

The Dataflow Engine emits one file per analysis domain. All share the .kxg container but represent different slices of the crypto graph. The Dashboard renders all six variants in a single graph view. The CLI emits them individually so you can pick the slice you need for headless processing.

ExtensionDomainCaptures
.kxg.codeSource code analysisHow cryptographic values move through the code: variable assignments, function returns, import chains.
.kxg.binaryCompiled-binary analysisCrypto usage discovered via AST / bytecode / IL inspection.
.kxg.runtimeRuntime tracesAlgorithms actually invoked when the program executes (from the Runtime Agent).
.kxg.configConfiguration-file dataflowWhere keys, certs, and crypto settings flow between config files and code.
.kxg.tlsTLS endpoint dataflowCert chains, cipher suites, endpoint relationships.
.kxg.gitGit-history dataflowWhen algorithms were introduced, rotated, or removed across the repo's history.

Working Artifacts & Caches

The scan caches live in <project>/.korthex_cache/ , next to the code they describe - not under .korthex/ and not in your user profile. They accelerate subsequent scans; all of them are safe to delete, and Korthex rebuilds whatever is missing on the next run. These caches are not redacted. Cache entries store symbol names, file paths and finding payloads of the scanned project in the clear, because they are a verbatim projection of your own source tree. Secret values are never written in the clear - the redaction rule that governs reports governs the caches too. If you scan third-party code under contract, treat .korthex_cache/ as being as sensitive as the checkout itself and delete it with the checkout.

ExtensionPurposeEngineEncrypted
.kxcbContext bundle: the binary projection of the project index, restored instead of re-derived.ContextNo (binary)
.kxcsicSemantic-IR cache, one entry per file content hash. Skips the tree-sitter parse and IR walk for unchanged bytes.ScannerNo (binary)
.kxcfhFile-hash snapshot. The content-hash set the delta scan compares against.ScannerNo (binary)
.kxcfPer-file findings cache. Supplies the results for files the delta scan does not re-analyze.ScannerNo (binary)
.kxgdcGit commit delta store: per-commit scan results keyed by commit OID.Git HistoryNo (binary)
.kxfhScan history: finding-ID sets for delta tracking. Plain JSON.ScannerNo
.kxsimMigration-simulation persistence. Re-loadable; tracks incremental simulation state.Migration SimYes
.kxcveBundled NVD / CPE / KEV / EPSS cache.Impact / ScannerNo (binary blob)

Updater Artifacts

The Korthex updater creates several short-lived files during an in-place update. These are cleaned up automatically on a successful run; you'll only see them after a failed update. # If an update fails mid-way, recover with: korthex-updater rollback

ExtensionPurposeCleanup
.kxsvSigned version manifest (versions.bin.kxsv). Lists current vs available builds.Survives updates.
.kxbakBackup of the previous version. Used by korthex-updater rollback.Retained until the next successful update.
.kxtmpTransient download / unpack staging file.Deleted on update success.
.kxoldOld-version remnant scheduled for deletion at next launch.Deleted on next startup.

Data Templates & Drop-ins

Korthex's report templates can ingest JSON payloads via drag-and-drop in the Dashboard. The suggested filename on save uses a Korthex-prefixed extension that's still plain JSON underneath - humans get a recognizable name, machines see standard JSON. Korthex also ships encrypted data-template formats used by the report-templating system internally:

Suggested filenameSchemaUsed by
.kxgraph.jsonDataflow graph payload (kxg-code.schema.json)dataflow_code_analysis_template.html
.kxreport.jsonImpact audience-tailored report (krx-impact-audience.schema.json)impact_audience_template.html
.kxcompliance.jsonCompliance impact payload (krx-impact-compliance.schema.json)impact_compliance_template.html
.kxmp.codeCode migration plan (contracts/code.schema.md)migration_code_template.html
.kxmp.binaryBinary migration plan (contracts/binary.schema.md)migration_binary_template.html
.kxmp.certCertificate migration plan - cert-as-object (contracts/cert.schema.md)migration_cert_template.html
.kxmp.configConfig migration plan (contracts/config.schema.md)migration_config_template.html
.kxmp.gitGit history migration plan (contracts/git.schema.md)migration_git_template.html
.kxmp.tlsTLS protocol-layer migration plan (contracts/tls.schema.md)migration_tls_template.html
ExtensionPurpose
.kxtEncrypted HTML template (static-key encrypted at build time).
.kxjsEncrypted JavaScript bundle for templates.
.kxcssEncrypted CSS for templates.

User-Editable Files

These files are explicitly designed to be edited by hand. They live at the project root or in your home directory. Korthex re-reads them on every run so changes take effect immediately. The general rule: any .json file Korthex writes can be hand-edited, but doing so without understanding the schema causes the engine to reject the file on next load. There is no separate validation command: the file is checked where it is used, so run korthex check --policy after major changes — it fails hard on a bad file rather than quietly falling back.

FilePurposeEdit guidance
.korthexignorePath-ignore rules (gitignore syntax).Safe to edit. Korthex automatically respects .gitignore too.
.korthex_policy.jsonOrganizational policy: allowed algorithms, key sizes, deprecation deadlines, exemptions, algorithm aliases.Edit-heavy by design. JSON Schema published; the file is checked where it is used - korthex check --policy <file> fails hard rather than falling back.
.korthex_ground_truth.jsonGround-truth dataset for the Accuracy Engine.Editable for advanced users running their own measurement campaigns.
.korthex_gui.cfgDesktop UI privacy / GUI prefs.Editable. Restart Korthex Desktop after editing.
mock-findings.jsonFixture for testing IDE plugin integration without running a real scan.Developer-only file. Safe to delete.
.korthex/config.jsonPer-project configuration (engines on/off, output paths, severity filters).Safe to edit. CLI: korthex config set <key> <value>.

Korthex Airgapped File Formats

When running Korthex in airgapped mode, several file types are generated to ensure a clean and secure installation without any network connection. All you need is your airgapped machine and a second device with the Customer Dashboard open - file transfer between the two (e.g. via USB drive) is all it takes to complete the setup.

File formatExplanationUsed by
.kxeditionAllows Korthex to detect an airgapped installationKorthex Installation Detection
.kxpsRepresents the current safety status of your machine. Generated by Korthex-Preflight.exeKorthex License Server
.kxreqGenerated by the Korthex airgapped installation wizard when exporting the installation hashKorthex License Server
.krxlicContains the installation key for your specific installation. Automatically generated by the Korthex License Server using the .kxreq and .kxps filesKorthex License System

Flowence Shared Formats

Korthex uses Flowence Infrastructure's shared compressed-JSON format for large reference tables (CVE / KEV / EPSS, baseline algorithm tables). The .cjsn format is the Flowence JSON++ SDK's output. See the SDKs section for details on the broader Flowence file-tool ecosystem.

ExtensionPurposeEncrypted
.cjsnFlowence JSON++ columnar-compressed JSON. Stores the algorithm-baseline tables (hash.cjsn, symmetric.cjsn, asymmetric.cjsn, protocols.cjsn, jurisdiction-specific.cjsn) and CVE/KEV/EPSS caches.No (compression only)

Cheatsheet: Which Tool Reads What

Three of the seven have no CLI verb at all. .kxi and .kxw are app-only; .krxr has no viewer on either side yet. If a pipeline needs one of them, read the file directly - there is no command waiting to be discovered.

I have aRead it on the CLI withRead it in an app in
.krx reportkorthex decrypt <path>Desktop → Reports. The screen lists the .krx files already in the workspace folder and decrypts the one you pick; neither app takes a file upload.
.kxi inventoryNo CLI reader.Inventory, in both apps - Files / Census / PQC Readiness / Snapshot Diff. The Web Dashboard also accepts a .kxi upload.
.kxg dataflow graphkorthex dataflow view <path>Desktop → Dataflow. The Web Dashboard route is disabled today.
.kxsim simulationkorthex sim inspect <path>Desktop → Migration → Simulation (and Diff). The Plans tab does not read .kxsim, and the Web plans page is driven by the API rather than by the file.
.kxfh history fileNo reader needed - it is a plain JSON array. Any JSON tool opens it.Nothing reads this file directly. The Trends view is fed by the API, not by scan_history.kxfh.
.kxw workspace bundleNo CLI reader.Desktop → workspace switcher → Import workspace. It is in the switcher, not under Settings, and the Web Dashboard has no workspace import.
.krxr runtime reportNo CLI reader.Nothing reads it yet. The Runtime screens export runtime-report.json / .html; the .krxr container is written by the engine and has no client-side viewer.