MAGDOX · security for software and connected devices
Security for your code. Intelligence for your firmware.
Find vulnerabilities, understand your components and give the people shipping a release the context to act. Magdox brings you two focused products: Code Security for source repositories and FDIE for firmware.
Self-service for both products. Enterprise deployment and contract options.
MAGDOX Code Security
Keep analysis in your development environment. Bring the team into the review.
The magdox CLI examines source, dependencies, secrets and configuration on the developer machine or CI runner, so engineers investigate without sending the repository away. Upload findings only when the team needs shared triage; matched source snippets stay off by default.
Inventory AI usage, connect coding agents and review with your own model.
Each capability stays separate from detection: the scanner remains responsible for its findings, and a model verdict never removes a finding or changes its severity.
AIBOM
AI and ML inventory
Recognised AI SDK and model patterns in supported source and dependency files, exported as JSON or CycloneDX ML-BOM.
Pattern-based risk labels do not establish actual data transfer, model versions or complete coverage. Run aibom separately.
Let a configured coding assistant request local scans through MCP, inspect the findings, work on a correction and rescan. Setup guidance covers Claude Code, Codex and other MCP-capable hosts; Claude Code is the end-to-end validated host.
A secure-coding prompt guides behaviour; it is not an enforced merge control.
Bring your own provider key (Anthropic, OpenAI-compatible services such as Groq, Gemini, Azure or a local Ollama, or AWS Bedrock). For each finding the model adds an advisory verdict, likely real, likely false positive or needs review, with a reason, and can propose a fix that the engine re-scans before it is marked verified.
Off until you approve a repository. Code excerpts go only to the provider you chose, with recognised secrets redacted first. A verdict never removes a finding or changes its severity, and a verified fix still needs your review before it is applied.
Know what is inside a device image and what changes between releases.
FDIE analyses supported firmware images, identifies components and candidate vulnerabilities, and compares each release with the last. Start with an image you are authorised to assess; source code is not required.
Application engineers, product-security teams and device manufacturers need different inputs and deliverables. Our solution pages explain the practical workflow for each, from the first evaluation to the evidence handed to a release owner.
Try the product on work your engineers can verify.
Code Security offers a 14-day self-service trial with a card; cancel before it ends to avoid the first charge. FDIE is paid at checkout, and its first payment is refunded in full on request within 14 days if your organisation has analysed three or fewer new images. Enterprise evaluations, on-premises requirements and procurement terms can be arranged with our team.
Start a Team or Business subscription from the Code Security console, with a 14-day trial through Dodo Payments. A card is required; cancel before the trial ends to avoid the first charge. Downloading the public CLI launcher does not itself grant private engine or rule access. Contact us for Enterprise or offline deployment.
Does the source repository leave our environment?+
Analysis runs on your machine or CI runner. Results stay local unless you request --upload. Code snippets are off by default and require --include-code plus permission on the receiving repository. --show-payload prints a redacted preview, not the exact upload body, and prevents sending it. Authentication, rule downloads and the vulnerability database download can still contact the platform. The optional AI review sends code excerpts only to the provider you configured, and only for repositories you approved.
How should we evaluate FDIE?+
Choose an authorised representative firmware image and, where possible, a related release pair. Inspect extraction, identified components, findings and unassessed work before using the result in a release decision.
Are the products one shared dashboard?+
No. Magdox supplies two products with distinct applications, subscriptions and evidence stores. Their product information, pricing, documentation and legal documents are combined on this website.
Choose your starting point
Begin with a repository or a firmware image.
Code Security
Review code and configuration locally, then decide what your organisation should see in the console.