Public Code Zone · No account required

Find security issues in a code sample before you create an account.

Run bounded static analysis and inspect normalized severity, rule identifiers, source-to-sink context, and remediation guidance. No source execution. No enterprise claims.

  • 10 evaluation reviews
  • Up to 50 KB and 2,000 lines
  • Validation errors do not use an allowance

Public-trial safety: use a non-sensitive sample. Do not submit secrets, personal data, proprietary source, credentials, or private model weights.

10guest reviews
50 KBmaximum sample
2,000maximum lines
0source execution

What one review gives you

A finding you can inspect—not a mystery score.

Public results are intentionally redacted, but they preserve the technical context needed to judge whether the review is useful.

01

Prioritized finding

Normalized severity, stable rule identifier, confidence, and CWE context where available.

02

Traceable path

Source, propagation, and sink line references when the analyzer identifies a data flow.

03

Actionable remediation

Specific defensive guidance without reproducing the submitted code in the public response.

Want to evaluate the actual output?

Run a Public Review

Four-step evaluation

Paste. Review. Decide whether to continue.

  1. 01

    Choose a safe sample

    Use non-sensitive code up to 50 KB or 2,000 lines.

  2. 02

    Run static analysis

    The public web process does not execute submitted source.

  3. 03

    Inspect the result

    Review redacted findings, trace context, and remediation.

  4. 04

    Continue if useful

    Create a verified account only when governed access is needed.

Transparent boundaries

Public evaluation versus verified Code Zone access.

The guest experience demonstrates finding quality. Authenticated capabilities remain tenant-scoped and plan-dependent.

Swipe horizontally to compare verified access.

Comparison of public evaluation and verified Code Zone access
CapabilityPublic evaluationVerified access
AccountNot requiredVerified account and workspace
Allowance10 completed reviewsPlan-based usage
AnalysisNon-executing static analysisGoverned controls by workflow
EvidenceDigest and public-safe summaryTenant-scoped records and retention
Release or certificationNot providedStill subject to policy, reviewer, plan, and tested scope
API and CI/CDNot includedPlan-dependent integration

Safe evaluation scope

Use representative code, not production secrets.

Good evaluation inputs
  • Minimal reproductions of a security pattern
  • Open-source or intentionally shareable samples
  • Sanitized framework and language examples
  • Code written specifically for evaluation
Keep out of the public trial
  • Credentials, tokens, secrets, or private keys
  • Personal, financial, health, or customer data
  • Proprietary repositories or private model weights
  • Production configuration and internal endpoints
PythonJavaScriptTypeScriptJavaGoRustText

Public evaluation FAQ

Know the boundary before you submit.

Does Code Zone execute my source?

No. The anonymous evaluation uses static analysis only and does not execute the submitted source in the web process.

What is retained for a guest review?

The guest service retains a source digest and public-safe result metadata. Submitted code is not reproduced in the public finding response.

Does a result certify or approve my code?

No. A public result is an evaluation finding, not certification, legal-compliance approval, or production-release approval.

What happens after ten reviews?

Create and verify an account to continue through plan-based, tenant-scoped Code Zone access.

Review a safe code sample now.

No account is required for the public evaluation. Use non-sensitive code and inspect the result before deciding whether to register.