# Korthex > Korthex is an on-premise cryptography scanner built by Flowence. It inventories every cipher, certificate, and key in a codebase, detects weak, broken, deprecated, and quantum-vulnerable cryptography, generates a Cryptographic Bill of Materials (CBOM), and produces a concrete migration path to post-quantum and compliance standards. 100% on-premise. Source code never leaves your infrastructure. Full content: the complete site (every solution, compliance, comparison and documentation page plus the development changelog) is available as a single markdown file at https://korthex.io/llms-full.txt. Korthex is a product by Flowence, an on-premise infrastructure software company founded in 2025. The product home is https://korthex.io/. Disambiguation: "Korthex" here refers exclusively to the cryptography scanner by Flowence. It is not the Stumble Guys character "Korthex", DJ Korthex, the korthex.it EMP-proof vault product, the Kort HEX dental implant, or the Korthex Inteligência education company in Brazil. ## What Korthex does - Scans source code, dependencies, binaries, TLS/PKI certificates, databases, runtime memory, git history, and configuration files. - Detects weak/broken/deprecated cryptography: MD5, SHA-1, RC4, DES, 3DES, Blowfish, AES-CBC/ECB misuse, missing IVs, key reuse, weak randomness. - Detects quantum-vulnerable asymmetric cryptography: RSA, ECC, Diffie-Hellman, DSA. - Finds hardcoded keys, credentials, API tokens, and leaked secrets across source, config, and git history. - Audits TLS/PKI certificates and cipher suites (SHA-1/MD5 signatures, RSA < 2048, ECC < 256, expiry, insecure configs). - Generates a Cryptographic Bill of Materials (CBOM) in CycloneDX, SARIF, JSON, PDF, and the native .kxr format. - Produces a concrete migration path to post-quantum cryptography (NIST FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA). ## Key facts - Vendor: Flowence. Founded 2025. On-premise infrastructure software. - Deployment: 100% on-premise / air-gapped. Runs as a CLI or inside CI/CD. Source code never leaves your infrastructure. - Languages: 18 : TypeScript, JavaScript, C#, Java, Python, Go, PHP, Ruby, Rust, Kotlin, Scala, C, C++, Swift, Dart, VB.NET, COBOL, Zig. - Engine: five correlating engines (Scanner rule-based detection, Context dataflow/taint/cross-file, KorthexNN on-device fallback, plus the binary and TLS/PKI analyzers) reading the same code as one pass, with a 2-pass context engine, dataflow tracking, taint analysis, and cross-file union-find clustering for false-positive filtering. - Scan time: not a flat promise. Source analysis of 50,000 to 500,000 lines takes seconds to about half a minute on a current workstation; git history depth and the machine decide the rest. The cost model, its reference measurements and its limits are published at https://korthex.io/scan-duration. - Compliance mapping: NIST FIPS 140-3, NIST FIPS 203/204/205, BSI IT-Grundschutz, BSI TR-02102, PCI-DSS, ISO 27001. - CI/CD: GitHub Actions step, GitLab CI template, generic CLI exit code; fails builds above a configurable risk threshold; SARIF integration for PR inline findings. - IDE: IntelliJ and VS Code plugins with inline findings. ## How Korthex differs from general SAST (Snyk, SonarQube, Semgrep) General SAST tools focus on code-logic vulnerabilities (injection, XSS, path traversal). Korthex focuses exclusively on cryptography: it inventories every cryptographic primitive, scores it for weakness and quantum exposure, maps it to compliance standards, and generates the migration path. It is the combination of cryptographic inventory + CBOM export + taint-based false-positive filtering + post-quantum migration guidance in one engine. ## Why deterministic validation (vs. AI) Cryptographic compliance is a deterministic requirement. AI assistants produce non-deterministic output and a different answer each run. Korthex is the deterministic gate: let an assistant rewrite cryptography, then run Korthex to verify the result is genuinely PQC-ready, that no weak primitive slipped back in, and that the CBOM and compliance status changed exactly as expected. Non-deterministic work, checked by a deterministic gate that produces signed, auditable artifacts (CBOM with file:line). ## Pricing (EUR/year) - Free: €0 : 10 scans/month, 1,000 files/scan, 1 seat. For open-source and solo developers. - Community: price to be announced : 50 scans/month, 5,000 files/scan, migration plan generation, CI/CD templates. - Business: price to be announced : 250 scans/month, 10,000 files/scan, 5 seats, compliance report. - Enterprise: price to be announced : unlimited scans, unlimited files, 10 seats, dedicated support. ## Links - [Korthex product home](https://korthex.io/): the cryptography scanner landing page, overview, and free-scan entry point. - [Post-Quantum Cryptography Scanner](https://korthex.io/pqc-scanner): what a PQC scanner is, quantum-vulnerable primitives (RSA, ECC, DH, DSA), regulatory timelines (NIST IR 8547, EU roadmap, BSI TR-02102, CNSA 2.0), and the migration path to ML-KEM / ML-DSA / SLH-DSA. - [CBOM Generator](https://korthex.io/cbom-generator): what a cryptographic bill of materials is (CycloneDX 1.6 / ECMA-424), what a useful CBOM contains, open-source CBOM tools compared, and CBOM as the base of crypto agility. - [Crypto Agility Tool](https://korthex.io/crypto-agility): the four building blocks of crypto agility (inventory, scoring, migration plan, CI gate) and how the PQC transition tests them. - [Crypto Vulnerability Scanner CLI](https://korthex.io/crypto-vulnerability-scanner): CLI-first scanning, exit-code gating, output formats, the five-engine architecture, and the free tier. - [Weak Cipher Detection](https://korthex.io/weak-cipher-detection): what counts as a weak cipher (DES, 3DES / Sweet32, RC4, Blowfish, AES-ECB, CBC without integrity) and replacement guidance. - [MD5 / SHA-1 Scanner](https://korthex.io/md5-sha1-scanner): why both hashes are broken (2004 / SHAttered 2017), where they hide, taint verdicts vs benign checksums, migration to SHA-256 / SHA-3. - [TLS Certificate Audit](https://korthex.io/tls-certificate-audit): on-premise auditing of certificates, keys and TLS configuration in repositories and internal infrastructure. - [Hardcoded Keys / Secrets Scanner](https://korthex.io/hardcoded-secrets-scanner): credential scanning across source, config and full git history with taint-classified key provenance. - [NIST FIPS 140-3 Scanner](https://korthex.io/compliance/fips-140-3): approved vs non-approved algorithms, the FIPS 140-2 sunset in September 2026, audit-ready evidence. - [PCI-DSS Cryptography Scanner](https://korthex.io/compliance/pci-dss): requirements 3.5.1, 4.2.1, 8.3.2 and the 12.3.3 cipher-suite inventory, automated as a CBOM. - [ISO 27001 Cryptography Audit Tool](https://korthex.io/compliance/iso-27001): Annex A 8.24 evidence, policy-vs-reality gap analysis, auditor-ready exports. - [BSI IT-Grundschutz Crypto Scanner](https://korthex.io/compliance/bsi-it-grundschutz): CON.1 Kryptokonzept evidence and TR-02102 key-length checks, air-gapped capable. - [Compliance overview: recognized authorities & frameworks](https://korthex.io/compliance): how findings are graded against baseline channels from NIST, BSI, ANSSI, CISA, IETF and OWASP plus jurisdiction overlays (EU payments, Germany, France, United Kingdom, Australia, Canada), with signed 24-hour updates and per-finding framework tags. - [Korthex vs SandboxAQ AQtive Guard](https://korthex.io/vs-sandboxaq): honest comparison of two vantage points - source-level static analysis proven by NIST KAT emulation, self-serve with a free tier, vs runtime estate discovery with policy-based identification, enterprise sales-led. - [GitHub Actions Integration](https://korthex.io/integrations/github-actions): pull-request gating with SARIF and GitHub Code Scanning on self-hosted or hosted runners. - [CI/CD Cryptography Scanning](https://korthex.io/integrations/ci-cd): GitLab CI, Jenkins and generic exit-code gating for any pipeline, rollout guidance. - [Korthex documentation](https://korthex.io/docs): full CLI reference, engine architecture, scanning guides, SDKs, and the PQC migration playbook. - [Pricing & License](https://korthex.io/license): plan comparison (Free, Community, Business, Enterprise) and licensing. - [Flowence Infrastructure (vendor)](https://flowencehq.com/): the on-premise infrastructure software company that builds Korthex. ## Full page index The section above is curated - these are the pages worth reading first. This one is complete: every indexable URL on korthex.io, generated from sitemap-en.xml at build time so it cannot drift from what is actually published. Every /docs URL also has a markdown twin at the same path with `.md` appended. ### Solutions and scanners (21) - [Who builds Korthex](https://korthex.io/about): Korthex is built by Hendrik Schneider at Flowence Infrastructure: who curates the rules, who maintains the baseline, and what each claim is checked against. - [Korthex Beta Program](https://korthex.io/beta): Korthex is in public beta for cryptographic analysis, inventory and migration planning. Current scope, roadmap, and how to take part. - [CBOM Generator](https://korthex.io/cbom-generator): Generate a cryptographic bill of materials: every algorithm, key and certificate with file:line evidence. CycloneDX, SARIF, JSON, PDF. On-premise. - [Changelog](https://korthex.io/changelog): What landed in each Korthex pre-release build, newest first: scanner engines, CBOM output, compliance coverage, SDK and CI/CD integration. - [Crypto Agility Tool: Inventory, Score, Migrate](https://korthex.io/crypto-agility): Swap cryptographic algorithms without breaking production: a live CBOM, quantum-exposure scoring, a dependency-ordered migration plan, and a CI gate. - [Crypto Vulnerability Scanner CLI, 18 Languages](https://korthex.io/crypto-vulnerability-scanner): One command scans code, dependencies, binaries, TLS and databases for weak and quantum-vulnerable cryptography, and returns a gateable exit code. - [Editorial standards](https://korthex.io/editorial-standards): Every number here points at a measurement or a named standard, and a build gate refuses to ship a claim without its evidence. The gates, by name. - [Hardcoded Secrets Scanner: Code and Git History](https://korthex.io/hardcoded-secrets-scanner): Finds hardcoded keys, credentials, API tokens and private keys across source, config and full git history, with dataflow across 16 import hops. - [Imprint (Impressum)](https://korthex.io/imprint): Legal imprint for Korthex: provider identification, contact address and responsibility under German law. Korthex is a product by Flowence. - [Korthex Pricing](https://korthex.io/license): Korthex plans: Free at EUR 0, plus Community, Business and Enterprise. Paid pricing is not final yet. All run 100% on-premise. - [Links of Interest](https://korthex.io/links): Curated resources around Korthex and cryptographic migration: standards, tooling and further reading on post-quantum cryptography, CBOM and compliance. - [MD5 and SHA-1 Scanner for Source Code](https://korthex.io/md5-sha1-scanner): Finds every MD5 and SHA-1 usage in code, dependencies, binaries and git history, and separates security-critical usage from benign checksums. - [How Korthex measures its own detection accuracy](https://korthex.io/methodology): Ground truth, precision, recall and F1 for a cryptography scanner: the definitions, the four measurement modes, and what the numbers do not show. - [Post-Quantum Cryptography Scanner](https://korthex.io/pqc-scanner): On-premise post-quantum scanner: finds RSA, ECC, Diffie-Hellman and DSA in code, binaries and TLS, and plans the ML-KEM / ML-DSA migration. - [Privacy Policy](https://korthex.io/privacy): The Korthex privacy policy: what is collected, what is never collected, and how the on-premise scanner keeps source code inside your infrastructure. - [Korthex Scan Duration by Repository and Machine](https://korthex.io/scan-duration): Enter project size, history depth and machine specs for an estimated span of a first scan and every scan after it. Model and measurements published. - [Report a vulnerability in Korthex](https://korthex.io/security): Coordinated disclosure for Korthex: how to report a vulnerability, what is in scope, and the published response targets by CVSS severity. - [Service Level Agreement](https://korthex.io/sla): The Korthex service level agreement: support tiers, response times and availability commitments for Community, Business and Enterprise plans. - [Terms of Service](https://korthex.io/terms): The terms of service for Korthex, the on-premise cryptography scanner by Flowence. - [TLS Certificate Audit Tool, On-Premise](https://korthex.io/tls-certificate-audit): Audits certificates, keys and cipher suites for SHA-1 / MD5 signatures, RSA below 2048, ECC below 256, expiry and insecure configuration. Air-gapped. - [Weak Cipher Detection: DES, 3DES, RC4, Blowfish](https://korthex.io/weak-cipher-detection): Detects DES, 3DES (Sweet32), RC4, Blowfish, AES-ECB and unauthenticated CBC, with dataflow analysis and NIST KAT emulation to prove real usage. ### Compliance authorities and jurisdictions (18) - [Cryptographic Compliance: Authorities & Frameworks](https://korthex.io/compliance): Korthex grades every finding against NIST, BSI, ANSSI, CISA, IETF and OWASP baselines, plus EU, German, French, UK, Australian and Canadian overlays. - [ANSSI RGS Compliance](https://korthex.io/compliance/anssi): 9 rules from ANSSI RGS Annexe B1 v2.0, the French national cryptographic reference, tagged ANSSI-RGS-B and NIS2, with an OIV jurisdiction overlay. - [Australia Cryptography Compliance](https://korthex.io/compliance/australia): Grades cryptography against the ASD Information Security Manual: 4 rules scoped to OFFICIAL data, tagged ASD-ISM with file:line evidence. - [BSI TR-02102-1 and -2 Compliance Scanner](https://korthex.io/compliance/bsi): 16 rules from BSI TR-02102-1: key-size floors (RSA 3000 bit, ECC 250 bit), hash and AEAD requirements, quantum-safe hybrid guidance. NIS2-tagged. - [BSI IT-Grundschutz Crypto Scanner: CON.1](https://korthex.io/compliance/bsi-it-grundschutz): Maps findings to IT-Grundschutz building block CON.1 (Kryptokonzept) and the TR-02102 key-length recommendations, with file:line evidence. - [Canada Cryptography Compliance](https://korthex.io/compliance/canada): Grades cryptography against CCCS ITSP.40.111 for UNCLASSIFIED and PROTECTED information: 4 rules layered on the NIST baseline, tagged ITSP-40.111. - [CISA Post-Quantum Directives: BOD 18-01, PQC](https://korthex.io/compliance/cisa): 7 rules from CISA's Post-Quantum Initiative and BOD 18-01: weak-protocol removal (RC4, 3DES, legacy SSL/TLS) and PQC readiness for US federal estates. - [EU Cyber Resilience Act](https://korthex.io/compliance/eu-cra): The CBOM as the cryptography slice of your EU Cyber Resilience Act technical documentation, with NIS2-tagged baselines as the state-of-the-art yardstick. - [EU Payments Cryptography](https://korthex.io/compliance/eu-payments): Payment-infrastructure cryptography rules on top of the authority baselines: PSD2, DORA and PCI DSS 4.0 tags with per-finding file:line evidence. - [FIPS 140-3 Scanner: Find Non-Approved Crypto](https://korthex.io/compliance/fips-140-3): Scans code, binaries, TLS and databases for cryptography that fails NIST FIPS 140-3: non-approved algorithms, weak key sizes and risky modes. - [France Cryptography Compliance](https://korthex.io/compliance/france): The France overlay adds OIV critical-infrastructure scope to the ANSSI RGS B1 baseline: 4 rules for administrations, vital operators and suppliers. - [Germany Crypto Compliance: BSI, NIS2, Grundschutz](https://korthex.io/compliance/germany): BSI TR-02102 as the algorithm baseline, NIS2 tags for critical infrastructure, and IT-Grundschutz CON.1 evidence from the CBOM. Built in Germany. - [IETF RFC Deprecations: TLS, MD5, SHA-1, 3DES](https://korthex.io/compliance/ietf): 11 rules tracking the RFC deprecation trail: RFC 8996 (TLS 1.0/1.1), RFC 8429 (3DES, RC4 in Kerberos), RFC 6151 (MD5) and RFC 6194 (SHA-1). - [ISO 27001 Crypto Audit: Annex A 8.24 Evidence](https://korthex.io/compliance/iso-27001): Inventories every cryptographic control actually in use across code, TLS and databases, and exports auditor-ready evidence for Annex A control 8.24. - [NIST Crypto Compliance: FIPS, SP 800-131A, IR 8547](https://korthex.io/compliance/nist): 24 rules from SP 800-131A Rev. 2, FIPS 180-4 and FIPS 197: disallowed 3DES, banned SHA-1 signatures, RSA floors, FIPS 203/204/205 on IR 8547 timelines. - [OWASP ASVS Cryptography: V11 and V12 Rules](https://korthex.io/compliance/owasp): A live baseline: ASVS v5.x pulled from the official OWASP repository every 24 hours and mapped into 33 verification rules with file:line evidence. - [PCI-DSS Cryptography Scanner](https://korthex.io/compliance/pci-dss): Finds cryptography that fails PCI DSS 4.0 and generates the documented cryptographic inventory required by requirement 12.3.3, with file:line evidence. - [UK Crypto Compliance: NCSC Foundation Profile](https://korthex.io/compliance/united-kingdom): Grades TLS and cryptography against the NCSC Foundation Profile: 4 rules for UK enterprises and public-sector suppliers, layered on the NIST baseline. ### Comparisons (4) - [Korthex vs SandboxAQ AQtive Guard: Source vs Runtime](https://korthex.io/vs-sandboxaq): Korthex is source-first: 18-language static analysis with file:line evidence. AQtive Guard discovers at runtime. An axis-by-axis comparison. - [Korthex vs Semgrep: Crypto Reachability vs Patterns](https://korthex.io/vs-semgrep): Semgrep matches patterns. Korthex follows values across import hops, builds attack-paths, and proves weak crypto by emulation against NIST KAT. - [Korthex vs Snyk: Crypto-Specialized vs General SAST](https://korthex.io/vs-snyk): Snyk scans code-logic vulnerabilities. Korthex inventories every cryptographic primitive, scores post-quantum exposure and plans the migration. - [Korthex vs SonarQube: Crypto Inventory vs Code Quality](https://korthex.io/vs-sonarqube): SonarQube covers bugs, code smells and security hotspots. Korthex is crypto-specialized: attack-paths, CBOM, migration plan, KAT verification. ### Integrations (2) - [CI/CD Cryptography Scanning: GitLab, Jenkins](https://korthex.io/integrations/ci-cd): Gate any pipeline on cryptographic findings: GitHub Actions step, GitLab CI template, Jenkins snippet, and a generic CLI exit code for the rest. - [GitHub Actions Cryptography Scanning](https://korthex.io/integrations/github-actions): Scan every pull request for weak and quantum-vulnerable cryptography, fail the build above a risk threshold, and post findings inline via SARIF. ### Documentation (59) - [Korthex Documentation](https://korthex.io/docs): The complete Korthex documentation: CLI reference, scanning guides, the analysis engines, CBOM output formats, compliance mapping, CI/CD and the SDK. - [Accuracy Engine](https://korthex.io/docs/accuracy-engine): The Accuracy Engine measures how well the scanner is finding what it should be finding. It compares actual scan output against ground-truth corpora and… · markdown: https://korthex.io/docs/accuracy-engine.md - [Air-Gapped & Self-Hosted](https://korthex.io/docs/air-gapped): Korthex is offline-first by design - every scan engine runs entirely locally and your source code never leaves the machine. For environments where even… · markdown: https://korthex.io/docs/air-gapped.md - [Architecture at a Glance](https://korthex.io/docs/architecture-glance): Korthex is composed of 14 specialized engines that cooperate around a single shared truth source. This page is the bird's-eye view: how the engines… · markdown: https://korthex.io/docs/architecture-glance.md - [Auto Migration](https://korthex.io/docs/auto-migration): Auto Migration closes the loop between finding a cryptographic weakness and fixing it. Instead of producing a migration plan for a human to execute by… · markdown: https://korthex.io/docs/auto-migration.md - [Baseline Registry](https://korthex.io/docs/baseline-registry): The Baseline Registry is the central crypto-classification truth source. It holds the canonical rule for every algorithm Korthex knows about - currently… · markdown: https://korthex.io/docs/baseline-registry.md - [CI/CD Integration](https://korthex.io/docs/ci-cd): Korthex is designed to run in automated pipelines. The check command provides exit codes suitable for gate checks, and output formats like SARIF… · markdown: https://korthex.io/docs/ci-cd.md - [CLI Reference](https://korthex.io/docs/cli-reference): The Korthex CLI is the primary interface for scanning, reporting, and managing cryptographic findings. All commands follow the pattern: korthex … · markdown: https://korthex.io/docs/cli-reference.md - [Compliance](https://korthex.io/docs/compliance): Korthex automatically maps findings to recognized compliance frameworks, helping organizations demonstrate adherence to cryptographic security standards. · markdown: https://korthex.io/docs/compliance.md - [Configuration](https://korthex.io/docs/configuration): Korthex is configured through a combination of project-level config files, CLI flags, and environment variables. The project configuration file is… · markdown: https://korthex.io/docs/configuration.md - [Context Engine](https://korthex.io/docs/context-engine): The Context Engine runs as a second pass after the initial scan. It builds a project-wide semantic index and applies dataflow, taint, and cross-file… · markdown: https://korthex.io/docs/context-engine.md - [Custom Rules & Extensibility](https://korthex.io/docs/custom-rules): Korthex ships with thousands of rules out of the box, but every organization has legacy patterns, in-house wrappers, and specific algorithms it wants to… · markdown: https://korthex.io/docs/custom-rules.md - [Dashboard](https://korthex.io/docs/dashboard): The Korthex Dashboard provides a web-based interface for managing projects, viewing findings, tracking trends, and generating compliance reports.… · markdown: https://korthex.io/docs/dashboard.md - [Database Scanning](https://korthex.io/docs/database-scanning): Korthex detects and analyzes 41 database types across 5 categories: relational, NoSQL, cloud, in-memory/cache, and key management systems (KMS). Findings… · markdown: https://korthex.io/docs/database-scanning.md - [Dataflow Engine](https://korthex.io/docs/dataflow-engine): The Dataflow Engine turns the flat list of findings into a directed graph: nodes are cryptographic assets (keys, certs, algorithms, call sites,… · markdown: https://korthex.io/docs/dataflow-engine.md - [Error Codes & Troubleshooting](https://korthex.io/docs/error-codes): A consolidated reference for the error codes the CLI and engine surface, plus the most common causes and the fix path for each. When in doubt: set… · markdown: https://korthex.io/docs/error-codes.md - [Exploit Engine](https://korthex.io/docs/exploit-engine): The Exploit Engine takes Scanner's cryptographic findings one step further: instead of stopping at "this code uses a weak primitive", it asks the harder… · markdown: https://korthex.io/docs/exploit-engine.md - [File Format Reference](https://korthex.io/docs/file-format-reference): Korthex uses ~30 custom file formats across its engines. This section is the authoritative catalog: every extension, what it stores, whether it's… · markdown: https://korthex.io/docs/file-format-reference.md - [Getting Started](https://korthex.io/docs/getting-started): Korthex is an automated cryptographic discovery and analysis platform. It scans your entire codebase - source files, binaries, certificates,… · markdown: https://korthex.io/docs/getting-started.md - [Glossary](https://korthex.io/docs/glossary): Common terms used throughout the documentation. Cross-referenced from every section so you can jump back here whenever you hit a piece of jargon. · markdown: https://korthex.io/docs/glossary.md - [IDE Plugins](https://korthex.io/docs/ide-plugins): Korthex integrates directly into your development environment with plugins for IntelliJ IDEA and Visual Studio Code, providing real-time cryptographic… · markdown: https://korthex.io/docs/ide-plugins.md - [Impact Engine](https://korthex.io/docs/impact-engine): The Impact Engine takes a flat list of findings ("MD5 detected at auth.py:42") and translates it into business language ("this finding affects the… · markdown: https://korthex.io/docs/impact-engine.md - [Inventory Engine](https://korthex.io/docs/inventory-engine): The Inventory Engine builds an authoritative inventory of every cryptographic asset in your project - every algorithm use, every certificate, every TLS… · markdown: https://korthex.io/docs/inventory-engine.md - [Korthex Remote](https://korthex.io/docs/korthex-remote): Korthex Remote is the mobile companion app for Korthex Desktop. It lets you stay on top of your cryptographic posture from your phone - review findings,… · markdown: https://korthex.io/docs/korthex-remote.md - [License Management](https://korthex.io/docs/license-management): Every Korthex installation needs a license to unlock the features beyond the Free tier. This section covers license format, activation flows (online and… · markdown: https://korthex.io/docs/license-management.md - [Mesh-Relay](https://korthex.io/docs/mesh-relay): Mesh-Relay is the optional outbound channel that lets multiple Korthex installations coordinate through a central server when peer-to-peer mesh… · markdown: https://korthex.io/docs/mesh-relay.md - [Neural Network Engine](https://korthex.io/docs/neural-network-engine): The Neural Network Engine is the on-device neural-network layer that runs as a deterministic fallback after rule-based detectors have done what they can.… · markdown: https://korthex.io/docs/neural-network-engine.md - [Output & Reports](https://korthex.io/docs/output-reports): Korthex produces structured reports in multiple formats. Each format serves a different workflow - from in-Korthex review to CI/CD integration to… · markdown: https://korthex.io/docs/output-reports.md - [Planner Engine](https://korthex.io/docs/planner-engine): The Planner takes a scan report and produces a concrete migration plan: for every weak algorithm, which file/line to change, what to replace it with, in… · markdown: https://korthex.io/docs/planner-engine.md - [Policy Engine](https://korthex.io/docs/policy-engine): The Policy Engine decides which findings should block a CI/CD pipeline, which should warn , and which to ignore - based on a federated baseline plus your… · markdown: https://korthex.io/docs/policy-engine.md - [PQC Migration Playbook](https://korthex.io/docs/pqc-playbook): Quantum computers powerful enough to break today's public-key cryptography do not exist yet - but the data we encrypt today will still be sensitive when… · markdown: https://korthex.io/docs/pqc-playbook.md - [Pricing](https://korthex.io/docs/pricing): All plans include the full 18-language scanner. The Free tier is ideal for evaluating Korthex on a single project. Community adds CI/CD and dashboard… · markdown: https://korthex.io/docs/pricing.md - [Privacy & Telemetry](https://korthex.io/docs/privacy-telemetry): Korthex is offline-first by design. Your source code never leaves the machine. All outputs are encrypted at rest with authenticated cryptography.… · markdown: https://korthex.io/docs/privacy-telemetry.md - [Runtime Agent](https://korthex.io/docs/runtime-agent): The Runtime Agent watches a running process and observes the cryptography it actually uses - not what the source code says , but what the binary calls at… · markdown: https://korthex.io/docs/runtime-agent.md - [Scanning](https://korthex.io/docs/scanning): Korthex uses a multi-engine scanning architecture. Each engine specializes in a different aspect of cryptographic analysis, and results from all engines… · markdown: https://korthex.io/docs/scanning.md - [Flowence Cryptography SDK](https://korthex.io/docs/sdk-flowence-cryptography): A general-purpose cryptography toolkit by Flowence Infrastructure (the company behind Korthex), designed to make modern primitives - authenticated… · markdown: https://korthex.io/docs/sdk-flowence-cryptography.md - [Flowence JSON++ SDK](https://korthex.io/docs/sdk-flowence-jsonpp): Flowence JSON++ is a library shipped as a linkable DLL that lets you work with standard .json files using a SQL-like query syntax, so you can select ,… · markdown: https://korthex.io/docs/sdk-flowence-jsonpp.md - [Korthex SDK](https://korthex.io/docs/sdk-korthex): The Korthex SDK gives you a typed, idiomatic client to every Korthex engine. Build your own CI runners, security dashboards, programmatic scan triggers,… · markdown: https://korthex.io/docs/sdk-korthex.md - [Advanced Topics](https://korthex.io/docs/sdk-korthex-advanced): Power-user features that aren't part of the everyday surface but matter once you push the SDK into production-scale workflows. · markdown: https://korthex.io/docs/sdk-korthex-advanced.md - [API Reference](https://korthex.io/docs/sdk-korthex-api): Auto-generated reference for every class, method, and type in the SDK. This page will host (or link out to) the per-version generated docs once the SDK… · markdown: https://korthex.io/docs/sdk-korthex-api.md - [Authentication](https://korthex.io/docs/sdk-korthex-authentication): The SDK uses your Korthex license to authenticate, with optional API tokens for granular, scope-limited access. The authentication model mirrors the CLI:… · markdown: https://korthex.io/docs/sdk-korthex-authentication.md - [Changelog](https://korthex.io/docs/sdk-korthex-changelog): Version history for the Korthex SDK. Backwards-incompatible changes follow semantic-versioning major bumps and are pre-announced in the Korthex changelog… · markdown: https://korthex.io/docs/sdk-korthex-changelog.md - [Core Concepts](https://korthex.io/docs/sdk-korthex-concepts): Five concepts run through every SDK module. Understanding them once means every subsequent module feels familiar. Expand the Core Concepts branch in the… · markdown: https://korthex.io/docs/sdk-korthex-concepts.md - [Async Operations](https://korthex.io/docs/sdk-korthex-concepts-async): Long-running operations (scans, migration plans, exploit analyses) return an operation handle immediately. You can poll, stream, or await completion. · markdown: https://korthex.io/docs/sdk-korthex-concepts-async.md - [Client](https://korthex.io/docs/sdk-korthex-concepts-client): The KorthexClient is the entry point. One instance per process is typical; the client manages connection pooling, retries, and credential refresh… · markdown: https://korthex.io/docs/sdk-korthex-concepts-client.md - [Configuration](https://korthex.io/docs/sdk-korthex-concepts-configuration): Configuration is resolved in a deterministic order. You always know which value wins. · markdown: https://korthex.io/docs/sdk-korthex-concepts-configuration.md - [Errors & Retries](https://korthex.io/docs/sdk-korthex-concepts-errors): Every SDK error inherits from KorthexError . Subclasses encode the category so you can branch on type rather than parsing strings. · markdown: https://korthex.io/docs/sdk-korthex-concepts-errors.md - [Pagination](https://korthex.io/docs/sdk-korthex-concepts-pagination): Endpoints that return large result sets (findings, inventory entries, audit events) paginate with an opaque cursor. · markdown: https://korthex.io/docs/sdk-korthex-concepts-pagination.md - [Examples & Recipes](https://korthex.io/docs/sdk-korthex-examples): End-to-end patterns you can copy into your own codebase. Each recipe is small, focused, and uses the production-ready APIs. · markdown: https://korthex.io/docs/sdk-korthex-examples.md - [Recipe: CI/CD Integration](https://korthex.io/docs/sdk-korthex-examples-ci): Block a pull request when scan-introduced findings exceed your policy threshold. · markdown: https://korthex.io/docs/sdk-korthex-examples-ci.md - [Recipe: Custom Dashboards](https://korthex.io/docs/sdk-korthex-examples-dashboards): Build a custom finding-explorer or trend dashboard that pulls live data from your Korthex installation. · markdown: https://korthex.io/docs/sdk-korthex-examples-dashboards.md - [Recipe: Webhook Handlers](https://korthex.io/docs/sdk-korthex-examples-webhooks): Receive structured events from Korthex (scan completed, panic alert, license change) and route them into your incident pipeline. · markdown: https://korthex.io/docs/sdk-korthex-examples-webhooks.md - [Installation](https://korthex.io/docs/sdk-korthex-installation): Install the Korthex SDK in your project using your language's standard package manager. Each install pulls in the typed core client; per-engine modules… · markdown: https://korthex.io/docs/sdk-korthex-installation.md - [Modules](https://korthex.io/docs/sdk-korthex-modules): The Korthex SDK exposes 9 engines through 162 C functions mirrored 1:1 in every supported binding. Every function listed below is actually exported by… · markdown: https://korthex.io/docs/sdk-korthex-modules.md - [Exploit](https://korthex.io/docs/sdk-korthex-modules-exploit): Recon → Analyze → Attack → Report pipeline. Two-gate model: the license tier (Enterprise + NN) AND the engine-internal Feature Gate must both be open.… · markdown: https://korthex.io/docs/sdk-korthex-modules-exploit.md - [Policy](https://korthex.io/docs/sdk-korthex-modules-policy): Loads the federated NIST SP 800-131A baseline (99 rules, embedded in the DLL) plus an optional user overlay at %APPDATA%/korthex/sdk/policy.json . Switch… · markdown: https://korthex.io/docs/sdk-korthex-modules-policy.md - [Scanner](https://korthex.io/docs/sdk-korthex-modules-scanner): The source-of-truth crypto-find pipeline. STATELESS at the DLL level - scannerInit reads (or scaffolds) the SDK config at… · markdown: https://korthex.io/docs/sdk-korthex-modules-scanner.md - [Quick Start](https://korthex.io/docs/sdk-korthex-quickstart): End-to-end in less than thirty lines: install, configure, scan, read the result. The same example is shown in every supported language, pick a tab. · markdown: https://korthex.io/docs/sdk-korthex-quickstart.md - [SDKs Overview](https://korthex.io/docs/sdks-overview): Korthex and Flowence Infrastructure publish three software development kits. They give developers programmatic access to the same engines that power the… · markdown: https://korthex.io/docs/sdks-overview.md ## Sister products - [Sentinal](https://flowence.cc/): on-premise device management, part of the Flowence ecosystem. - [Voxra](https://flowence.cc/): unified communication hub, part of the Flowence ecosystem.