Archie — a continuous white-box security audit run by offensive agents
Archie logo Archie v0.9 · PRIVATE BETA
CONTINUOUS WHITE-BOX AUDIT · RUN BY OFFENSIVE AGENTS

An audit that never stops,and never leaves your {{ typed }}

Archie learns how your system is actually wired, sends offensive-security agents down the paths that matter, and proves every finding before it reaches your team. It runs inside your infrastructure, on your own model.

Request access See a real finding

DEPLOYMENT

SaaS · Private VPC · On-prem or air-gapped runner

MODEL

Bring your own LLM, or route every call through your gateway

FRAMEWORKS

SOC 2 · PCI-DSS · KVKK · BDDK · NCA ECC · SAMA CSF · DORA · NIS2 · CRA

01 / THE PROBLEM

Scanners answer with volume. Pentests answer once a year.

OPTION A

Static analysis produces thousands of matches per repository. Most are unreachable. Triage capacity, not detection capacity, decides what gets fixed, and triage capacity is a person.

OPTION B

The annual test is thorough and attested, and it describes one week of one branch. The report is accurate on the day it is signed and stale by the next release.

MEANWHILE

Most new code is written with model assistance and merged in hours. The commit rate has outrun the audit cadence, and the gap is measured in months.

02 / THE REFRAME

The bottleneck is not detection. It is proof.

A team cannot act on a finding it cannot trust. So the real issue waits in the same backlog as the noise, and the backlog is triaged by whoever has time. Archie is built around the step that decides whether a finding gets fixed: showing the path that reaches it.

03 / HOW IT WORKS

Learn first. Attack second. Prove last.

01
PERSISTENT GRAPH

Learn

Archie builds a persistent graph of the system: what each function can reach, where trust ends, which inputs are attacker-controlled, what changed since the last scan. The graph survives between scans and grows with every commit.

graph.build repo=payments-api entrypoints 412 trust edges 1,884 delta vs prev +37 nodes · 98.1% reused
02
OFFENSIVE AGENTS

Attack

Offensive-security agents traverse the graph and probe the paths that exist, rather than matching patterns line by line. They start where an attacker starts: at an entry point, with the reach the code actually gives them.

attack.run agents=6 paths walked 1,203 hypotheses 58 reached sink 11 · dead ends 1,145
03
VERIFIER

Prove

A verifier challenges every hypothesis before a human sees it. It re-walks the path, checks the guard conditions the agent claimed were absent, and discards anything it cannot demonstrate end to end.

verify.pass in=11 proven 4 unreachable 5 accepted 2 · queued 4

Illustrative log output. Structure is real, the repository is not.

04 / A REAL FINDING, END TO END

One finding, from the HTTP entry point to the control it breaks.

This is what arrives in the queue. Not a rule name and a line number. The reachable path, the guard that was missing, the verifier's attempt, and the control the finding breaks.

FINDING
ARC-2417
SEVERITY
HIGH
CONFIDENCE
0.94
STATUS
VERIFIED
CLASS
CWE-22

Unauthenticated path traversal writes outside the upload root

A filename taken from a multipart request reaches Path.resolve() without normalisation. The endpoint is reachable before the auth filter, so the write happens with service credentials and no user context.

REACHABLE PATH · 4 HOPS
01HttpEndpointPOST /api/v2/profile/avatar · routes/profile.kt:41
02ProfileUpload.store()upload/ProfileUpload.kt:88 · filename passed through unmodified
03Path.resolve(userInput)io/StorageRoot.kt:23 · no normalize(), no root containment check
04FileOutputStreamio/StorageRoot.kt:31 · sink · write with service credentials
trace: entry → sinkHIGH 0.94
HttpEndpoint → ProfileUpload.store()
→ Path.resolve(userInput) → FileOutputStream
WHY IT SURVIVED TRIAGE
  • The route is registered outside the authenticated filter chain.
  • The verifier re-walked the path and found no containment check on any hop.
  • A traversal sequence in the filename resolves outside the upload root in the same runtime configuration used in production.
  • No compensating control was declared for this path in the knowledge base.
CONTROLS BROKEN
PCI-DSS 6.2.4Injection and path handling in bespoke software
SOC 2 CC8.1Change control before deployment
KVKK Art. 12Technical measures for personal-data storage
OWASP A01Broken access control
DELIVERED AS
PR check · Jira ticket · SARIF entry · audit record line

Illustrative finding. The format is what Archie produces; the repository is fictional.

05 / THE PRODUCT

One scan, from clone to verified finding.

The findings view, the intelligence dashboard, and the checks it drops into your pipeline. Real screens from a real audit run.

{{ currentShot.cap }}
{{ currentShot.label }}: {{ currentShot.cap }}
06 / YOUR PERIMETER, YOUR MODEL

No source and no model call leaves infrastructure you control.

Reachability lives in the graph, not in a context window. That is why Archie holds up on non-frontier and local models, and why a fully in-perimeter deployment is economically real rather than a checkbox.

SAAS

Managed by us, single-tenant per customer, region of your choosing.

PRIVATE VPC

Runs in your cloud account. Your network policy, your key management, your logs.

ON-PREM RUNNER

Air-gapped operation supported. The graph is stored on your storage and never replicated out.

YOUR MODEL

Bring your own LLM, or route every call through the gateway you already audit.

Works with your model, or your gateway
Your own API keys Azure OpenAI AWS Bedrock Anthropic Self-hosted OSS models LiteLLM / custom gateway
07 / THE VERIFIER AND THE TRIAGE FLEET

Nothing reaches your queue that Archie could not prove.

NON-REACHABLEDropped. No path exists from any entry point.
ACCEPTEDDropped. Covered by a control recorded in your knowledge base.
UNPROVENHeld. Returned to the attack phase instead of the queue.
PROVENQueued, with the path and the control attached.

Existing scanners are an input to this process. Archie takes their output as a hypothesis and applies the same verification to it, which turns a long match list into a short proven list.

The knowledge base feeds triage: it learns from your documents, design meetings, whitepapers and product definitions, so an issue that is accepted by design is dropped before it ever reaches your queue.

Cohort precision figures are published once the beta cohort is large enough to state them with a method.

08 / MEMORY COMPOUNDS

The third audit is cheaper and sharper than the first.

Every commit adds to what Archie already understands. The graph is not rebuilt for each scan, so a later scan spends its budget on what changed and on the paths it has not yet walked. Nothing is relearned from scratch, and coverage accumulates instead of resetting.

SCAN 1 → SCAN 3 ILLUSTRATIVE
Compute cost per scan
Paths covered
SCAN 1SCAN 2SCAN 3

No recall loss

Findings from the first commit stay reachable at commit five hundred. Nothing falls out of context as the codebase grows.

No lost in the middle

Reachability is graph state, not a prompt window. An entry point found early is still connected to a sink found late.

Works on any model

The hard part is structural, not linguistic, so Archie holds up on smaller, non-frontier models, not just the newest flagship.

09 / COVERAGE

What Archie reads today.

LANGUAGE FRAMEWORKS BUILD SYSTEMS Java / KotlinSpring, Jakarta EE, KtorMaven, Gradle C# / .NETASP.NET CoreMSBuild, NuGet TypeScript / JavaScriptNode, Express, NestJS, Next.jsnpm, pnpm, yarn PythonDjango, FastAPI, Flaskpip, Poetry, uv Gonet/http, Gin, EchoGo modules PHPLaravel, SymfonyComposer Infrastructure as codeTerraform, Kubernetes manifests—

If your stack is not listed, tell us what it is. Graph construction is per-language and we add languages against real repositories, not roadmaps.

10 / COMPLIANCE

Every finding carries the control it breaks.

Mapping is configured against the frameworks you are audited under, so a finding arrives already attributed to the control your auditor will ask about.

SOC 2CC · TYPE II

Findings mapped to the Common Criteria, with the change-control evidence a Type II period needs.

PCI-DSS 4.0REQ 6

Requirement 6 secure-development coverage against the code in scope, on every merge.

HIPAA§164.308

Technical safeguards traced to the paths that touch protected health information.

FedRAMPSI · RA

SI and RA control families, with the machine-readable record as continuous-monitoring input.

KVKKART. 12

Article 12 technical measures, evidenced against the code paths that reach personal data.

BDDK IS auditCONTINUOUS

Evidence for the mandatory information-systems audit, produced continuously instead of in the weeks before it.

Annual pentestCOMPLEMENT

Archie does not replace it. It covers the eleven months between tests and hands the tester a current map.

TCMBPAYMENTS

Payment and e-money institution requirements on secure software development and data localisation.

Saudi NCA ECCECC

Essential Cybersecurity Controls, including the application-security and vulnerability-management domains.

SAMA CSFMATURITY

Cyber Security Framework maturity evidence for member organisations, per repository.

Saudi PDPLDATA

Personal-data protection obligations traced to the code that processes the data.

UAE IA · DESC · Qatar NIAIN-COUNTRY

National control mappings, with in-country deployment so nothing crosses the border.

Cyber Resilience Act2026–27

Reporting obligations apply from September 2026 and the main obligations from December 2027. Vulnerability handling has to be a process, and the process needs a record.

DORAICT RISK

ICT risk management for financial entities, with testing evidence per release rather than per year.

NIS2SUPPLY CHAIN

Supply-chain and secure-development duties for essential and important entities.

EU AI ActAI SYSTEMS

Model routing and logging that hold up when the AI system itself is in scope.

11 / IN YOUR PIPELINE

Runs where your code already runs.

TRIGGERS
On pull requestOn merge to a protected branchNightly against a branchOn demand, before a release gate
ARRIVES AS
PR check with the path inlineTicket in your trackerSARIF for your existing dashboardAudit record entry
INTEGRATIONS
GitHub GitLab Bitbucket Azure DevOps Jenkins Jira Linear Slack SARIF Webhooks
12 / WHERE ARCHIE SITS

Four categories do this work. Each is good at something Archie is not.

A pentest carries human attestation Archie cannot provide. A black-box agent finds what only runtime reveals. A scanner is fast, cheap and broad. Archie is the one that has both the source and the attacker's reach.

  ANNUAL PENTEST
AND PTaaS
BLACK-BOX
PENTEST AGENTS
AI SAST AND
REACHABILITY
ARCHIE
ContinuousPoint in timeContinuousContinuousContinuous Source-awareSometimes, by scopeNoYesYes, persistent graph Proves exploitabilityYes, by handYes, at runtimeReachability, not exploitYes, verified path Runs in your perimeterTesters on site or via VPNUsually vendor-hostedMostly SaaSSaaS, VPC or on-prem Works on your own modelNot applicableVendor modelVendor modelYour LLM or gateway Leaves an audit recordAttested report, annualFindings logFindings logMachine-readable, per scan
13 / THE RECORD

Every scan leaves a machine-readable record, not a PDF.

The record holds what was attempted, what was proven, what was dropped and why, and the cost of each category. The auditor gets provenance for every claim. Finance gets a line item per outcome.

◆Queryable by commit, by control, by severity, by path.
◆Retained on your storage under your retention policy.
◆Exportable for the independent audit without a rewrite.
scan recordEGRESS: NONE
scan_id 2026-08-14T02:11Z/payments-api commit 9f4c1ab categories injection proven 2 dropped 41 access_control proven 1 dropped 17 secrets proven 0 dropped 9 deserialize proven 1 dropped 6 model customer-gateway/local-70b egress none

Illustrative record. Cost figures are per-customer and appear in your own record.

14 / PRICING

One annual agreement, priced per repository.

Archie is sold direct while we are in private beta. Scope, deployment model and audit cadence are agreed with your security team before the first scan.

THE AGREEMENT
Custom
Annual, based on repository count and scan cadence.
+Priced per repository, agreed for the year
+No per-seat fees. Invite the whole security team
+No finding quotas and no per-scan metering
+Deployment model and audit cadence agreed with your security team before the first scan
+If you run your own model, inference cost is yours and stays on your bill
Talk to the team
WHAT A PILOT LOOKS LIKE
Week 1One repository connected. Deployment model chosen. Graph built.
Week 2First audit runs. We walk every finding with your team, line by line.
Week 3Mapping tuned to your frameworks. Accepted-by-design controls recorded.
Week 4Second scan on the same repository. You compare the two records and decide.
Deployment: SaaS, private VPC or on-prem runner.
You keep the report either way.
15 / QUESTIONS

The questions a sceptic asks first.

Does this replace our penetration test? +

No. A regulator-mandated test requires human-attested methodology and sign-off from a qualified tester, and Archie provides neither. Archie covers the eleven blind months in between, and hands your tester a current map of the system on the day they start.

Do the agents hallucinate findings? +

Agents propose. They do not publish. A separate verifier re-walks the claimed path against the graph and discards anything it cannot demonstrate end to end. A finding you receive comes with the path, and the path is checkable by hand in a few minutes.

We already run Semgrep and Snyk. What changes? +

Keep them. Archie treats their output as hypotheses and puts it through the same verification as its own, which turns a long match list into a short proven list. You are not asked to remove a tool that already works.

Where does our code go? +

Wherever you decide. In a private VPC or on-prem deployment, source and model calls stay inside your network and the graph is written to your storage. Egress is recorded in the scan record, and in an air-gapped deployment it is none.

Which models does it need? +

Reasoning is bounded by the graph rather than by context length, so Archie runs on non-frontier and locally hosted models. Bring your own, or route every call through the gateway your security team already audits.

What happens to the graph if we leave? +

It is yours. The graph and every scan record are exportable in documented formats, and in a self-hosted deployment they never left your storage to begin with. Termination terms are in the agreement, not in a support ticket.

Why buy in private beta? +

Because at v0.9 you influence what gets built, the mapping is tuned to your frameworks by us rather than by you, and the pilot costs you one repository and four weeks. If the first audit does not hold up, you keep the report and we stop.

Archie logo

Point Archie at one repository.

We run the first audit with you, walk every finding together, and you keep the report either way.

{{ ctaMsg }}
Response within one business day · NDA on request, before any access · Private beta · v0.9