Skip to main content
Design Partner Preview

Your code doesn’t have to leave your environment to be reviewed.

Z-Key Code is a local-first, offline-capable security assessment product for sensitive source code. Normal scanning, findings and reports remain local.

Find what can be established. Identify what requires review. Keep sensitive code local.

Mumbai

Introduced publicly in Mumbai. Now entering Design Partner validation.

Z-Key was introduced publicly at a Mumbai technology exhibition.

Why Z-Key

Cloud security is useful. It is not right for every codebase.

Some organisations cannot—or simply do not want to—send sensitive source code and security findings outside their environment. Z-Key is being built for those teams: financial services, privacy-conscious SaaS, consultancies, agencies, and enterprise development groups.

How it works

A local assessment workflow, end to end.

1. Select project

2. Local assessment

3. Evidence-backed findings

4. Offline Intelligence

5. Local reports

Connectivity is used for approved account, licensing, trial and device-activation functions where applicable. Normal source assessment does not use a cloud-analysis fallback.

Evidence model

Security tools shouldn’t pretend certainty they don’t have.

Z-Key distinguishes established evidence from strong signals and controls that require human context.

Verified

The available evidence establishes the security property or finding.

Probable

Strong signals exist, but the available context does not support absolute certainty.

Review Required

The control depends on runtime, business, or architectural context that requires human verification.

Your source stays where you work.

  • Local scanning, findings, history and reports
  • Offline Intelligence for evidence-backed guidance
  • Optional local model architecture where supported
  • No cloud fallback for normal local assessment

What it looks for

Categories include access control, authentication and sessions, sensitive-data exposure, file and document security, payment and business-logic signals, secrets, dependencies, insecure patterns, and relevant architecture observations. Coverage is not exhaustive; complex controls may be marked Review Required.

In development

Code is only one part of the attack surface.

Z-Key Infrastructure is being developed to bring a local-first evidence model to assets, services, certificates, network exposure, security changes and audit-readiness evidence. It is not customer-ready.

Register interest

Currently available through controlled preview engagements.

Z-Key Code is not generally available. Preview capacity may be limited and participation is subject to acceptance.