How Guardn processes your code
Guardn is a security scanner that finds vulnerabilities, secrets, and misconfigurations in source code. It uses a three-layer detection pipeline:
Layer 1: Pattern Engine – 300 hand-authored regex rules across 7 categories. Runs in under 100ms for typical files. Every rule includes severity, remediation guidance, and compliance mappings.
Layer 2: ML Classification – CycleCore SecurityGates (15 gates) and SafetyGates (25 gates) add machine learning detection for patterns that regex cannot catch. Runs server-side via API.
Layer 3: PQ Attestation – Scan results are cryptographically signed using ML-DSA-65 (NIST FIPS 204) via CycleCore PQCaaS. Creates a tamper-proof, quantum-resistant audit trail.
Each layer is independently useful. The CLI runs Layer 1 locally with zero network calls. The web IDE and API add Layers 2 and 3 when enabled.
Guardn is transparent about data flow. Here is exactly what happens:
Web IDE (real-time scanning): Code is sent from the browser to the Guardn server on each edit (debounced). The regex engine runs server-side. When SecurityGates and SafetyGates are enabled, code is also sent to CycleCore ML APIs (sg-api.cyclecore.ai, sf-api.cyclecore.ai) for classification. Source code is not stored permanently – only scan results (findings, scores, metadata) are persisted to SQLite when scan history is enabled.
CLI and pre-commit hook: Scans run entirely locally using the bundled 300-rule engine. No network calls. No telemetry. The only external call is PQ attestation if you explicitly enable it.
PQ Attestation: A SHA-256 hash of the scan result is sent to CycleCore's attestation API for signing. The source code is never sent for attestation – only the result digest.
Scan history: When enabled, scan findings (rule ID, severity, file path, line number, message) are stored in a server-side SQLite database. Source code is not stored in history.
The realtime scan pipeline (/api/scan/realtime) processes code in this order:
scanString(code, filename) applies all 300 rules. Returns findings with rule ID, severity, line/column, matched text (redacted), and remediation.SG-* findings merged into results. 15 gates covering WAF, leak, and injection patterns.SF-* findings. 25 gates covering content safety.calculateScore(findings) computes a 0-100 security score. Penalties: critical (-25), high (-15), medium (-8), low (-3), info (-1).All gate calls (SG, SF, PQ) are feature-flagged. If a gate is down or disabled, the pipeline continues without it.
300 rules across 7 categories (plus custom rules). These are the actual counts from the engine:
Insecure Patterns (74 rules) – eval(), innerHTML, weak crypto, hardcoded IPs, debug flags, unsafe deserialization, prototype pollution.
Secrets (51 rules) – API keys, tokens, private keys, connection strings across 30+ providers (AWS, GCP, Azure, Stripe, GitHub, Slack, etc.).
Injection (64 rules) – SQL injection, XSS, command injection, SSRF, path traversal, template injection, XXE, open redirect, CORS misconfiguration.
Infrastructure-as-Code (51 rules) – Terraform, Kubernetes, Docker, Helm misconfigurations. Privileged containers, missing resource limits, exposed ports, insecure storage.
AI Code Risks (25 rules) – Hallucinated packages, unsafe tool invocation, PII in prompts, AI generation markers, credential exfiltration, unvalidated model output.
Software Composition (20 rules) – Known vulnerable package versions, outdated base images, dependency confusion indicators.
Credentials (15 rules) – Hardcoded passwords, default credentials, connection strings with embedded passwords.
Severity breakdown: 91 critical, 127 high, 69 medium, 9 low, 4 info.
Guardn ships through multiple channels:
CLI – Install globally or as a dev dependency:
``
npm install -D @guardn/cli
npx @guardn/cli scan .
npx @guardn/cli scan src/ –min-severity high –format sarif
``
Pre-commit hook – Scans staged files before every commit:
``
npx @guardn/cli hooks install
`
Blocks commits with critical/high findings. Configure thresholds in .guardn.yml. Bypass with GUARDN_SKIP=1`.
Web IDE – Paste or edit code at guardn.io with real-time scanning, auto-fix suggestions, and PQ attestation.
Grade page – Quick scan with a letter grade. No login required.
GitHub Action – Add to any CI pipeline. Supports SARIF upload to GitHub Security tab.
API – POST /api/scan/realtime for programmatic access. Returns JSON with findings, score, and attestation.
32 rules have auto-fix functions that can patch findings in place. Auto-fix works through the web IDE:
Auto-fix is deterministic – no AI generation. Each fix function is a code transform specific to the rule (e.g., replacing eval() with JSON.parse(), moving secrets to environment variables, adding CSRF tokens).
Authentication: API endpoints require authentication when AUTH_ENABLED=true. Grade page is public.
Attestation: All scan results can be signed with ML-DSA-65 (post-quantum). Chain integrity is verifiable via guardn verify.
No telemetry: No usage analytics, no phone-home. The CLI makes zero network calls unless you enable attestation.
Feature flags: SecurityGates, SafetyGates, attestation, scan history, and other features are individually toggleable via environment variables. Only enable what you need.
Content firewall: Production deploys pass a 7-gate content firewall that strips agent IDs, internal names, paths, build-machine paths, personal identifiers, and secrets before deployment.
Every scan result carries a cryptographic signature proving its integrity. Signatures are verifiable independently of Guardn.