Documentation

Install it, see how the agent graph works, and read exactly what's verified before a finding gets reported.

Ryvx runs autonomous LLM agents that recon a target, hunt for vulnerabilities, validate each one with a working proof-of-concept, CVSS-score it, and suggest a concrete code fix — for source code, local apps, live URLs you're authorized to test, or a whole bug bounty program's scope.

The actual bet isn't "more autonomous than the next tool." It's three things held together: every finding is gated behind a working exploit, not an unconfirmed suspicion; every exploit against a production-tagged target needs a live human to say yes first; and every tool call any agent makes is written to an append-only audit log, so a scan's actions can be defended after the fact. These pages document how each of those actually works, not just that they exist.

Start here

What's proven, and what only compiles

A tool built around "PoC or it didn't happen" should hold its own claims to the same standard. Several pieces of Ryvx — the ticket-tracker integrations, the hosted/billing path, one reverse-engineering tier, bug bounty scope mode — are finished and tested but have never been run against anything real yet, and published benchmark recall numbers were withdrawn after an audit found the runs behind them were cut short. See the About page for the full capability audit, and the post on withdrawing those numbers for what that looked like in practice.