Docs / OUTPUT & MIGRATION
OUTPUT & MIGRATION
File Format Reference
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex uses ~30 custom file formats across its engines. This section is the authoritative catalog: every extension, what it stores, whether it's encrypted, whether it's user-editable, and the recommended tooling for inspecting it. User-edit policy. Every Korthex-generated .json file can be user-edited, but this is not recommended unless you know what you are doing - the engines validate strictly and a malformed file will be rejected on next load. Encrypted formats ( .kxi , .kxg , etc.) cannot be hand-edited at all: any modification invalidates the integrity check and the file is refused on load.
Encrypted Core Formats
All encrypted with authenticated cryptography. Sealed with a key derived from your license + machine binding so a file is only readable on the installation that produced it (or on an installation explicitly authorized to consume it, e.g. via a .kxw workspace bundle).
| Extension | Purpose | Engine | User-editable |
|---|---|---|---|
| .krx | Scan report. Also serves as the canonical container for migration plans. | Scanner / Planner | No |
| .kxi | Cryptographic-inventory snapshot. Backs CycloneDX / SPDX exports. | Inventory | No |
| .kxg | Dataflow graph (with sub-variants below). Magic 'KXGRAPH\0' when plaintext. | Dataflow | No |
| .kxnn | Neural Network model weights + vocabulary + signature. | Neural Network | No |
| .kxnn.sig | Detached signature over .kxnn. Refuses to load on mismatch. | Neural Network | No |
| .kxa | Exploit-Engine attack-pattern database. Korthex-internal key. | Exploit | No |
| .kxt | Encrypted HTML report template. | Report | No |
| .kxjs | Encrypted JS bundle for report templates. | Report | No |
| .kxcss | Encrypted CSS for report templates. | Report | No |
| .kxv | Viewer-bundle: report + assets in a single sealed container. | Report | No |
| .kxp | Encrypted, canonical policy file. The .korthex_policy.json variant is its human-editable plain-JSON equivalent. | Policy | No |
| .kxm | Mesh / migration container. | Mesh-Relay | No |
| .kxw | Workspace bundle. Passphrase-encrypted; portable across machines. | Dashboard | No |
| .krxr | Runtime-Agent encrypted report (V3). | Runtime Agent | No |
.kxg Sub-variants
The Dataflow Engine emits one file per analysis domain. All share the .kxg container but represent different slices of the crypto graph. The Dashboard renders all six variants in a single graph view. The CLI emits them individually so you can pick the slice you need for headless processing.
| Extension | Domain | Captures |
|---|---|---|
| .kxg.code | Source code analysis | How cryptographic values move through the code: variable assignments, function returns, import chains. |
| .kxg.binary | Compiled-binary analysis | Crypto usage discovered via AST / bytecode / IL inspection. |
| .kxg.runtime | Runtime traces | Algorithms actually invoked when the program executes (from the Runtime Agent). |
| .kxg.config | Configuration-file dataflow | Where keys, certs, and crypto settings flow between config files and code. |
| .kxg.tls | TLS endpoint dataflow | Cert chains, cipher suites, endpoint relationships. |
| .kxg.git | Git-history dataflow | When algorithms were introduced, rotated, or removed across the repo's history. |
Working Artifacts & Caches
The scan caches live in <project>/.korthex_cache/ , next to the code they describe - not under .korthex/ and not in your user profile. They accelerate subsequent scans; all of them are safe to delete, and Korthex rebuilds whatever is missing on the next run. These caches are not redacted. Cache entries store symbol names, file paths and finding payloads of the scanned project in the clear, because they are a verbatim projection of your own source tree. Secret values are never written in the clear - the redaction rule that governs reports governs the caches too. If you scan third-party code under contract, treat .korthex_cache/ as being as sensitive as the checkout itself and delete it with the checkout.
| Extension | Purpose | Engine | Encrypted |
|---|---|---|---|
| .kxcb | Context bundle: the binary projection of the project index, restored instead of re-derived. | Context | No (binary) |
| .kxcsic | Semantic-IR cache, one entry per file content hash. Skips the tree-sitter parse and IR walk for unchanged bytes. | Scanner | No (binary) |
| .kxcfh | File-hash snapshot. The content-hash set the delta scan compares against. | Scanner | No (binary) |
| .kxcf | Per-file findings cache. Supplies the results for files the delta scan does not re-analyze. | Scanner | No (binary) |
| .kxgdc | Git commit delta store: per-commit scan results keyed by commit OID. | Git History | No (binary) |
| .kxfh | Scan history: finding-ID sets for delta tracking. Plain JSON. | Scanner | No |
| .kxsim | Migration-simulation persistence. Re-loadable; tracks incremental simulation state. | Migration Sim | Yes |
| .kxcve | Bundled NVD / CPE / KEV / EPSS cache. | Impact / Scanner | No (binary blob) |
Updater Artifacts
The Korthex updater creates several short-lived files during an in-place update. These are cleaned up automatically on a successful run; you'll only see them after a failed update. # If an update fails mid-way, recover with: korthex-updater rollback
| Extension | Purpose | Cleanup |
|---|---|---|
| .kxsv | Signed version manifest (versions.bin.kxsv). Lists current vs available builds. | Survives updates. |
| .kxbak | Backup of the previous version. Used by korthex-updater rollback. | Retained until the next successful update. |
| .kxtmp | Transient download / unpack staging file. | Deleted on update success. |
| .kxold | Old-version remnant scheduled for deletion at next launch. | Deleted on next startup. |
Data Templates & Drop-ins
Korthex's report templates can ingest JSON payloads via drag-and-drop in the Dashboard. The suggested filename on save uses a Korthex-prefixed extension that's still plain JSON underneath - humans get a recognizable name, machines see standard JSON. Korthex also ships encrypted data-template formats used by the report-templating system internally:
| Suggested filename | Schema | Used by |
|---|---|---|
| .kxgraph.json | Dataflow graph payload (kxg-code.schema.json) | dataflow_code_analysis_template.html |
| .kxreport.json | Impact audience-tailored report (krx-impact-audience.schema.json) | impact_audience_template.html |
| .kxcompliance.json | Compliance impact payload (krx-impact-compliance.schema.json) | impact_compliance_template.html |
| .kxmp.code | Code migration plan (contracts/code.schema.md) | migration_code_template.html |
| .kxmp.binary | Binary migration plan (contracts/binary.schema.md) | migration_binary_template.html |
| .kxmp.cert | Certificate migration plan - cert-as-object (contracts/cert.schema.md) | migration_cert_template.html |
| .kxmp.config | Config migration plan (contracts/config.schema.md) | migration_config_template.html |
| .kxmp.git | Git history migration plan (contracts/git.schema.md) | migration_git_template.html |
| .kxmp.tls | TLS protocol-layer migration plan (contracts/tls.schema.md) | migration_tls_template.html |
| Extension | Purpose |
|---|---|
| .kxt | Encrypted HTML template (static-key encrypted at build time). |
| .kxjs | Encrypted JavaScript bundle for templates. |
| .kxcss | Encrypted CSS for templates. |
User-Editable Files
These files are explicitly designed to be edited by hand. They live at the project root or in your home directory. Korthex re-reads them on every run so changes take effect immediately. The general rule: any .json file Korthex writes can be hand-edited, but doing so without understanding the schema causes the engine to reject the file on next load. There is no separate validation command: the file is checked where it is used, so run korthex check --policy after major changes — it fails hard on a bad file rather than quietly falling back.
| File | Purpose | Edit guidance |
|---|---|---|
| .korthexignore | Path-ignore rules (gitignore syntax). | Safe to edit. Korthex automatically respects .gitignore too. |
| .korthex_policy.json | Organizational policy: allowed algorithms, key sizes, deprecation deadlines, exemptions, algorithm aliases. | Edit-heavy by design. JSON Schema published; the file is checked where it is used - korthex check --policy <file> fails hard rather than falling back. |
| .korthex_ground_truth.json | Ground-truth dataset for the Accuracy Engine. | Editable for advanced users running their own measurement campaigns. |
| .korthex_gui.cfg | Desktop UI privacy / GUI prefs. | Editable. Restart Korthex Desktop after editing. |
| mock-findings.json | Fixture for testing IDE plugin integration without running a real scan. | Developer-only file. Safe to delete. |
| .korthex/config.json | Per-project configuration (engines on/off, output paths, severity filters). | Safe to edit. CLI: korthex config set <key> <value>. |
Korthex Airgapped File Formats
When running Korthex in airgapped mode, several file types are generated to ensure a clean and secure installation without any network connection. All you need is your airgapped machine and a second device with the Customer Dashboard open - file transfer between the two (e.g. via USB drive) is all it takes to complete the setup.
| File format | Explanation | Used by |
|---|---|---|
| .kxedition | Allows Korthex to detect an airgapped installation | Korthex Installation Detection |
| .kxps | Represents the current safety status of your machine. Generated by Korthex-Preflight.exe | Korthex License Server |
| .kxreq | Generated by the Korthex airgapped installation wizard when exporting the installation hash | Korthex License Server |
| .krxlic | Contains the installation key for your specific installation. Automatically generated by the Korthex License Server using the .kxreq and .kxps files | Korthex License System |
Flowence Shared Formats
Korthex uses Flowence Infrastructure's shared compressed-JSON format for large reference tables (CVE / KEV / EPSS, baseline algorithm tables). The .cjsn format is the Flowence JSON++ SDK's output. See the SDKs section for details on the broader Flowence file-tool ecosystem.
| Extension | Purpose | Encrypted |
|---|---|---|
| .cjsn | Flowence JSON++ columnar-compressed JSON. Stores the algorithm-baseline tables (hash.cjsn, symmetric.cjsn, asymmetric.cjsn, protocols.cjsn, jurisdiction-specific.cjsn) and CVE/KEV/EPSS caches. | No (compression only) |
Cheatsheet: Which Tool Reads What
Three of the seven have no CLI verb at all. .kxi and .kxw are app-only; .krxr has no viewer on either side yet. If a pipeline needs one of them, read the file directly - there is no command waiting to be discovered.
| I have a | Read it on the CLI with | Read it in an app in |
|---|---|---|
| .krx report | korthex decrypt <path> | Desktop → Reports. The screen lists the .krx files already in the workspace folder and decrypts the one you pick; neither app takes a file upload. |
| .kxi inventory | No CLI reader. | Inventory, in both apps - Files / Census / PQC Readiness / Snapshot Diff. The Web Dashboard also accepts a .kxi upload. |
| .kxg dataflow graph | korthex dataflow view <path> | Desktop → Dataflow. The Web Dashboard route is disabled today. |
| .kxsim simulation | korthex sim inspect <path> | Desktop → Migration → Simulation (and Diff). The Plans tab does not read .kxsim, and the Web plans page is driven by the API rather than by the file. |
| .kxfh history file | No reader needed - it is a plain JSON array. Any JSON tool opens it. | Nothing reads this file directly. The Trends view is fed by the API, not by scan_history.kxfh. |
| .kxw workspace bundle | No CLI reader. | Desktop → workspace switcher → Import workspace. It is in the switcher, not under Settings, and the Web Dashboard has no workspace import. |
| .krxr runtime report | No CLI reader. | Nothing reads it yet. The Runtime screens export runtime-report.json / .html; the .krxr container is written by the engine and has no client-side viewer. |