Committed credentialsNinety-six patterns anchored to how each vendor writes its keys — AWS, Google, GitHub, Stripe, Slack, private keys, connection strings — graded by whether git is actually tracking the file.
Credentials in git historyThe key committed on Tuesday, deleted on Wednesday, never rotated — gone from the files and still in every clone.
Credentials with no vendorA credential-shaped name assigned a value with the randomness of a generated key — your own internal token.
Vulnerable dependenciesEvery installed package against OSV, across twenty lockfiles and manifests, re-ordered by what CISA and FIRST say is actually being exploited.
Supply chainInstall scripts that run before anybody reads them, names one character from a popular package, code trying not to be read.
CodeLine by line in forty-one languages and template engines — JavaScript to Lua, Groovy, Apex, Vue and Svelte, EJS, Jinja and Razor — followed across files.
BugsMistakes that are not attacks, in sixty-seven languages and five data formats: a merge committed with its conflict markers in, JSON or TypeScript that no longer parses — checked by the parsers that run them — and logic that cannot be what was meant: a value compared with itself, if (x = 0), a loop counting away from its bound. On Juliet's logic-error cases it finds 89.5% with no false alarms.
Second readerOptional and off until you switch it on: a model reads up to forty files a scan for the bugs no rule can name. On your own machine it sends nothing anywhere; with a hosted API, the window says where the files go before they are sent. Everything it reports is marked as a judgement.
AI toolingMCP servers that fetch and run whatever the registry serves today, agent rules files, and characters in them a reviewer cannot see.
Mobile applicationsCleartext traffic, backups anyone can pull, debuggable builds, components any app can call.
Devices and control systemsMQTT brokers, PLC protocols, firmware builds and bootloaders.
Containers and pipelinesUnpinned base images, credentials baked into layers, the Docker socket, workflows checking out a fork with secrets in scope.
InfrastructureTerraform and Kubernetes: ingress from anywhere graded by the port it opens, public buckets, privileged pods, Secrets carrying their values.
Listening ports and this machineThe socket table on all three platforms — never sending a packet — the Docker daemon, a kubeconfig, key files anybody can read.
Cloud accountsAWS, GCP, Azure, DigitalOcean, Cloudflare, Kubernetes, Oracle and Alibaba — read-only, with credentials already on this machine, plus the audit trail for an attack in progress.
Repository settingsBranch protection, what a workflow may do, deploy keys — asked of GitHub, because no file in the repository holds them.
A live siteCertificate expiry, TLS version, security headers, cookie flags, CORS, and a fixed list of files that should never be served. Refuses to run until you have proved the host is yours.