Docs / FUNDAMENTALS
FUNDAMENTALS
Getting Started
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex is an automated cryptographic discovery and analysis platform. It scans your entire codebase - source files, binaries, certificates, dependencies, and configuration - to produce a complete Cryptographic Bill of Materials (CBOM) with severity-ranked findings and compliance mapping. Whether you need to prepare for post-quantum migration, satisfy NIST or BSI audit requirements, or simply understand where cryptography lives in your software, Korthex gives you a single, automated workflow to get there. Documentation Notice This documentation reflects the current production-ready state of Korthex. Features visible on the website that are not yet documented here are actively in development and will be added once they reach a stable release. Until the official launch on 12.08.2026 , the documentation is updated continuously as features are finalized. Last update: 08.07.2026
Overview
Korthex is an integrated platform for understanding and improving the cryptography in your software. It scans, classifies, reports, and (in V2) migrates - entirely on-device, with your source code never leaving the machine. Scanning & analysis Source-code scanning across 18 languages: JavaScript, TypeScript, C#, Java, Python, Go, PHP, Ruby, Rust, Kotlin, Scala, C++, C, Swift, Dart, VB.NET, COBOL, and Zig. Binary scanning of compiled artifacts (.NET IL, JVM bytecode, native PE/ELF binaries) when source isn't available. Database scanning across 41 database types (relational, NoSQL, cloud, in-memory, and KMS). Configuration scanning for hardcoded secrets, weak settings, and TLS misconfigurations. Git-history scanning for previously committed secrets, removed crypto, and key rotations. Runtime observation via the Runtime Agent - what your binary actually calls at runtime, not just what the source says. Context-aware analysis via the Context Engine: dataflow, taint tracking, and cross-file clustering to dramatically reduce false positives. Neural Network assistance - on-device ML hints classify ambiguous patterns and identify custom crypto wrappers. Understanding what you have Inventory Engine - an authoritative crypto-asset inventory with CycloneDX CBOM and SPDX SBOM export. Dataflow Engine - a graph view of how keys, certificates, and crypto values flow across your code, configs, infrastructure, and runtime. Impact Engine - per-finding business-impact scoring with audience-tailored reports for CISO, CTO, CFO, and board. Baseline Registry - the central truth source: 11 500+ algorithm rules classifying every primitive as recommended, acceptable, deprecated, or disallowed. Governance & remediation Policy Engine - CI/CD gate with BLOCK / WARN / ALLOW verdicts. Configurable per organization via .kxp or its plain-JSON equivalent. Planner Engine - sequenced migration plans with engineer-hour estimates and deadline-driven prioritization. Auto Migration (V2) - context-aware automatic code rewrites with diff-review workflow and built-in rollback. V1 supports plan + simulate today. Exploit Engine - turns findings into demonstrable proof-of-concept evidence on source or binary targets (gated by license + Terms of Service). Accuracy Engine - measurement framework (precision / recall / F1) for regression-testing scan quality. Compliance, output & integration Compliance mapping - automatic NIST FIPS 203/204/205, BSI IT-Grundschutz, plus per-finding citations. Output formats - native encrypted .krx reports, CycloneDX CBOM, SPDX SBOM, SARIF 2.1.0. Plain JSON and PDF export is an Enterprise-tier feature. CI/CD-native - SARIF output drops directly into GitHub Code Scanning and Azure DevOps; JUnit XML for generic runners. IDE plugins for IntelliJ IDEA and Visual Studio Code with inline findings and real-time scanning. Web Dashboard for projects, trends, compliance, dataflow graphs, plan management. Self-hostable in Enterprise. Korthex Remote - Android mobile companion for live monitoring, remote scan triggering, and panic alerts. Mesh-Relay - cross-installation event coordination for fleet-scale deployments (Enterprise). Privacy posture Offline-first by design. Every engine runs locally. Source code, scan data, and findings never leave the machine unless you explicitly opt in to the Dashboard or Mesh-Relay. Air-gapped operation supported - full Enterprise installation with no network presence required. Telemetry is opt-in only and disabled by default; structural metadata only when enabled, never source content.
Installation
System Requirements Windows # Download and run the installer irm https://api.korthex.flowence.cc/api/version/install.ps1 | iex macOS / Linux curl -fsSL https://api.korthex.flowence.cc/api/version/install.sh | bash Container There is no published korthex/cli image. Install into a base image with the same script the Linux installer uses. docker run --rm -v "$(pwd):/workspace" -w /workspace ubuntu:22.04 bash -c ' apt-get update -qq && apt-get install -y -qq curl ca-certificates curl -fsSL https://api.korthex.flowence.cc/api/version/install.sh | bash export PATH="$HOME/.korthex/bin:$PATH" korthex scan . ' After installation, run korthex version to verify the CLI is on your PATH. What the installer verifies Both installers consume the same signed release channel as the desktop auto-updater. They fetch the signed release manifest, verify its detached Ed25519 signature against a public key pinned inside the script itself - the production key only, unless you deliberately opt in to the dev and test keys - and only then download the artifact, which is checked both against the SHA-256 recorded in the signature-verified manifest and against its own detached signature. Freshness and rollback, precisely. The manifest carries an expiry ( notValidAfter ) and a monotonic sequence , and both are read on every run - but they do not protect the same install equally. The sequence is trust-on-first-use : a first install on a clean machine has no stored high-water mark to compare against, so it records the sequence it is given rather than rejecting it. Rollback detection therefore begins with the second run against the same KORTHEX_HOME . On a first install the only bound on an older but still validly signed release is the expiry window - currently 90 days , so a release withdrawn less than 90 days ago can still be served to a fresh machine by whoever controls the channel. The installer is fail-closed : a missing signature, a signature that does not verify, a hash mismatch, or the absence of any usable verification tool aborts the install with a non-zero exit code and writes nothing to disk. There is no "continue anyway" path, so bytes substituted or tampered with in transit - by a compromised CDN, mirror, or proxy - are rejected before anything is written. What the script cannot do is vouch for what happens after it exits: its guarantee covers the bytes it installs, not every update your machine later accepts. Verification needs OpenSSL (3.x or 1.1.1) or Python 3 on macOS/Linux. Windows PowerShell needs nothing extra - the script carries its own verifier. Each is proven against a known-answer test before it is trusted, and the install aborts if none passes.
| Component | Requirement |
|---|---|
| OS | Windows 10+, macOS 12+, Linux (glibc 2.31+) |
| RAM | 8 GB minimum, 16 GB recommended |
| Disk | 500 MB for installation, plus free space for reports |
| Scan cache | Written to <project>/.korthex_cache/ and sized by the project, not by the installation: a semantic-IR entry per source file, plus one record per commit where a git history is scanned. On a large monorepo with deep history this reaches hundreds of megabytes. Safe to delete at any time. |
| Runtime | JVM 17+ (bundled with installer) |
| Variable | Purpose |
|---|---|
| KORTHEX_HOME | Install directory (default: ~/.korthex, %USERPROFILE%\.korthex on Windows) |
| KORTHEX_CDN | Release CDN base (default: https://cl.korthex.flowence.cc) |
| KORTHEX_SERVER | Backend base used as manifest fallback (default: https://api.korthex.flowence.cc) |
| KORTHEX_NO_MODIFY_PATH | Set to 1 to leave PATH untouched |
Quick Start
Get your first scan result in a few commands. How long the scan itself runs depends on the repository and the machine; the cost model behind it is published at korthex.io/scan-duration. # 1. Navigate to your project cd /path/to/your/project # 2. Run a scan korthex scan . # 3. View the report korthex reports --latest This scans all supported files in the current directory, produces a .kxr report, and opens the finding summary. By default, results are written to .korthex/reports/ . The first scan is a full analysis: there is no cache yet, so Korthex builds one in .korthex_cache/ while it works. Every later scan is incremental by default - it re-analyzes the files whose content changed plus everything importing them, and reuses the cached findings for the rest. The report is the same either way; only the time differs.