APEX runs your code — fuzzing and symbolic execution — and proves every finding with a reproducing input.
● Free up to 10 findings. No signup.
APEX verifies code by executing it. It runs your program against thousands of inputs, reaches places your tests never touch, and returns the exact input that reproduces each finding. Everything runs on your machine — not a line of code goes out.
Static analyzers read code and infer from patterns. APEX executes it and hands back the file or line it crashes on. Run it yourself — you see the same thing.
CWE Top 25 (2024) — the full registry. OWASP Top 10 (2021) — the official MITRE mapping. NIST SSDF practices. Over 60 detectors; ASVS coverage is 22%, and we print the honest number instead of a checkmark.
Coverage across 11–12 languages, MC/DC, mutation testing. The coverage gate fails the build — the standard stops being a verbal agreement.
10 major open-source projects. 12,656 findings, zero engine crashes.
Green tests tell you the code does what you checked. APEX shows you everything else it does.
One engine, different peaks. Every product runs your code and proves the finding with a reproducing input. All local.
One product is released so far. The other peaks are in the works — we announce a product only when it can prove a finding, not before.
Two things are fixed: the free tier is permanent, not a trial, and the scan always runs to completion. Packaging can still move — sign up before launch and your price is the launch price or lower, held 12 months.
How the free limit works. APEX scans the whole project and shows the total it found. For every finding you see the name, file, line and severity. Only the proof and the remediation hint are hidden — those unlock on a paid plan. We never hide the fact that a problem exists.
Three steps. The code goes nowhere: APEX is a program on your machine.
APEX is a tool for the agent. It runs locally, needs no API key, and works with any MCP host.
One stanza in your agent's config. The engine exposes 33 tools — audit, coverage, fuzzing, symbolic, taint, reach.
Your agent runs apex.audit and gets findings with a reproducing input on each one.
One message. No newsletter, no sequence, no sharing the address.
One message when the command works. Nothing before it.
APEX runs the code and obtains the concrete input that breaks it. Hence fewer false positives: if we show a crash, it is real, and you can reproduce it yourself.
Only vulnerabilities and real defects. Code-quality remarks and complexity metrics do not count and are always shown.
Yes. The internet is needed once — at purchase. After that the licence is verified on your machine against a built-in signature. Air-gapped environments are supported.
Test execution and coverage — 11–12 languages: Python, JavaScript/TypeScript, Java, Go, Rust, C, C++, C#, Kotlin, Ruby, Swift. Depth varies: C, C++ and Rust get the full set, including memory fuzzing.
Where proof is attached there are no false positives by definition — you can reproduce the crash. Some detectors work on patterns and can be wrong; those findings are marked separately.
The $10 plan is for personal, non-commercial use. Company use needs a team licence: $100 a month or $1,000 a year per organisation, with no limit on machines.
Card payment through a payment partner. After paying you receive a licence file by email — activated with one command. No calls to our server during operation.