Verified
The available evidence establishes the security property or finding.
Z-Key Code is a local-first, offline-capable security assessment product for sensitive source code. Normal scanning, findings and reports remain local.
Find what can be established. Identify what requires review. Keep sensitive code local.
Mumbai
Z-Key was introduced publicly at a Mumbai technology exhibition.
Why Z-Key
Some organisations cannot—or simply do not want to—send sensitive source code and security findings outside their environment. Z-Key is being built for those teams: financial services, privacy-conscious SaaS, consultancies, agencies, and enterprise development groups.
How it works
1. Select project
2. Local assessment
3. Evidence-backed findings
4. Offline Intelligence
5. Local reports
Connectivity is used for approved account, licensing, trial and device-activation functions where applicable. Normal source assessment does not use a cloud-analysis fallback.
Evidence model
Z-Key distinguishes established evidence from strong signals and controls that require human context.
The available evidence establishes the security property or finding.
Strong signals exist, but the available context does not support absolute certainty.
The control depends on runtime, business, or architectural context that requires human verification.
Categories include access control, authentication and sessions, sensitive-data exposure, file and document security, payment and business-logic signals, secrets, dependencies, insecure patterns, and relevant architecture observations. Coverage is not exhaustive; complex controls may be marked Review Required.
Z-Key Infrastructure is being developed to bring a local-first evidence model to assets, services, certificates, network exposure, security changes and audit-readiness evidence. It is not customer-ready.
Register interestZ-Key Code is not generally available. Preview capacity may be limited and participation is subject to acceptance.