MAGDOX · security for software and connected devices

Security for your code.
Intelligence for your firmware.

Find vulnerabilities, understand your components and give the people shipping a release the context to act. Magdox brings you two focused products: Code Security for source repositories and FDIE for firmware.

Self-service for both products. Enterprise deployment and contract options.

MAGDOX Code Security

Keep analysis in your development environment. Bring the team into the review.

The magdox CLI examines source, dependencies, secrets and configuration on the developer machine or CI runner, so engineers investigate without sending the repository away. Upload findings only when the team needs shared triage; matched source snippets stay off by default.

Inside a supported flow finding

Illustrative investigation

A request value reaches a database operation

  1. 01 / Input

    Where the application receives the value

  2. 02 / Transformation

    How it is changed, checked or passed onward

  3. 03 / Operation

    The security-sensitive use the reviewer must inspect

Location
File & line

Assessment
Severity & confidence

Coverage
Method & limits

Conceptual example. Flow evidence is available only for supported analysis paths.

Languages and frameworks

14
Languages, all with data-flow rules
32
Configuration and template families
2,107
Rule definitions
221
Distinct CWE references

Languages

  • Python
  • Java
  • JavaScript
  • Go
  • PHP
  • C#
  • TypeScript
  • C
  • C++
  • Kotlin
  • Ruby
  • Swift
  • Rust
  • Scala

Frameworks named in selected rules

  • Spring
  • Express
  • Laravel
  • ASP.NET
  • Rails
  • Devise
  • JSP
  • Thymeleaf
  • Twig
  • Blade

Infrastructure, configuration and templates

  • Terraform
  • Kubernetes
  • Dockerfile
  • Docker Compose
  • GitHub Actions
  • Dependency manifests
  • Desktop configuration
  • Ansible
  • nginx
  • HTTP headers
  • Android manifest
  • CI pipelines
  • CloudFormation
  • Bicep
  • OpenAPI
  • Pulumi
  • SQL
  • SSH configuration
  • Crossplane
  • Serverless Framework
  • HTML
  • Shell scripts
  • PowerShell
  • iOS property list
  • Jenkins
  • Maven
  • Spring properties
  • ASP.NET configuration
  • PHP configuration
  • Java templates
  • PHP templates
  • JavaScript templates

Published source inventory. Installed bundle versions and per-language analysis coverage can differ.

Inspect the coverage

AI support

Inventory AI usage, connect coding agents and review with your own model.

Each capability stays separate from detection: the scanner remains responsible for its findings, and a model verdict never removes a finding or changes its severity.

AIBOM

AI and ML inventory

Recognised AI SDK and model patterns in supported source and dependency files, exported as JSON or CycloneDX ML-BOM.

Pattern-based risk labels do not establish actual data transfer, model versions or complete coverage. Run aibom separately.

Explore the inventories

MCP

Coding agents

Let a configured coding assistant request local scans through MCP, inspect the findings, work on a correction and rescan. Setup guidance covers Claude Code, Codex and other MCP-capable hosts; Claude Code is the end-to-end validated host.

A secure-coding prompt guides behaviour; it is not an enforced merge control.

Explore agent workflows

Optional, opt-in

AI review with your own model

Bring your own provider key (Anthropic, OpenAI-compatible services such as Groq, Gemini, Azure or a local Ollama, or AWS Bedrock). For each finding the model adds an advisory verdict, likely real, likely false positive or needs review, with a reason, and can propose a fix that the engine re-scans before it is marked verified.

Off until you approve a repository. Code excerpts go only to the provider you chose, with recognised secrets redacted first. A verdict never removes a finding or changes its severity, and a verified fix still needs your review before it is applied.

Read the AI integration guide

FDIE · Firmware Delta Intelligence Engine

Know what is inside a device image and what changes between releases.

FDIE analyses supported firmware images, identifies components and candidate vulnerabilities, and compares each release with the last. Start with an image you are authorised to assess; source code is not required.

Firmware review workflow
  1. 01 / Discover

    Recover components and security evidence from authorised images.

  2. 02 / Investigate

    Bring static, runtime and vulnerability context into one review.

  3. 03 / Compare

    Follow release changes and retain the analyst's decision.

Frameworks and images

60
Technical checks in the source suite
11
Framework mapping profiles

Images and containers

  • Embedded Linux images
  • Vendor update wrappers
  • Raw images
  • Nested archives

Filesystems

  • SquashFS
  • UBI/UBIFS
  • JFFS2
  • CramFS
  • RomFS
  • ext2/3/4
  • FAT12/16/32… and more

Assessment views

  • CRA disclosure review
  • TARA
  • MITRE EMB3D

MCU and RTOS images yield recoverable metadata and supported static checks. Recognition does not establish complete extraction.

Mappings identify technical references, not certification. Assess the edition and product applicability separately.

Inspect the mapped checks

Access and evaluation

Try the product on work your engineers can verify.

Code Security offers a 14-day self-service trial with a card; cancel before it ends to avoid the first charge. FDIE is paid at checkout, and its first payment is refunded in full on request within 14 days if your organisation has analysed three or fewer new images. Enterprise evaluations, on-premises requirements and procurement terms can be arranged with our team.

How do we start with Code Security?

Start a Team or Business subscription from the Code Security console, with a 14-day trial through Dodo Payments. A card is required; cancel before the trial ends to avoid the first charge. Downloading the public CLI launcher does not itself grant private engine or rule access. Contact us for Enterprise or offline deployment.

Does the source repository leave our environment?

Analysis runs on your machine or CI runner. Results stay local unless you request --upload. Code snippets are off by default and require --include-code plus permission on the receiving repository. --show-payload prints a redacted preview, not the exact upload body, and prevents sending it. Authentication, rule downloads and the vulnerability database download can still contact the platform. The optional AI review sends code excerpts only to the provider you configured, and only for repositories you approved.

How should we evaluate FDIE?

Choose an authorised representative firmware image and, where possible, a related release pair. Inspect extraction, identified components, findings and unassessed work before using the result in a release decision.

Are the products one shared dashboard?

No. Magdox supplies two products with distinct applications, subscriptions and evidence stores. Their product information, pricing, documentation and legal documents are combined on this website.

Choose your starting point

Begin with a repository or a firmware image.

Code Security

Review code and configuration locally, then decide what your organisation should see in the console.

Get Started with Magdox

FDIE

Analyse a supported firmware image and follow the components, findings and changes behind a release.

Go to FDIE
Discuss an Enterprise deployment