SakaForge

Continuous Access Control Verification

Continuous Access Control Verification for Every PR.

SakaForge deploys an adversarial twin into your preview environment to prove your APIs enforce strict object ownership. Confirmed exploits only, automated 4-way patches, and tamper-proof evidence streamed directly to Vanta & Drata for SOC 2 CC6.1 / CC7.1.

Preview — no login required
$ git diff — app.ts
- const project = await db.project.findUnique({ where: { id } });
+ const project = await db.project.findFirst({ where: { id, ownerId: user.id } });
$ npx sakaforge scan --preview $URL
› 200 OK · leak verified via JSON diff · fresh-state replay 2/2 → BOLA confirmed
› HMAC a8f3…9c1e · cURL redacted → audit-trail.jsonl
Try the raw CLI output before giving GitHub access → Watch 60s theft below

Ephemeral execution in your GitHub Actions · data never leaves your boundary

What it does

  • Checks.

    Creates owner and attacker in your running app.

  • Proves.

    A finding counts only if the request returned 200, data leaked, and replay matched.

  • Fixes.

    Prepares a patch and runs 4 roles: owner, attacker, admin, guest.

  • Signs.

    Streams verified compliance evidence for CC6.1/CC7.1 directly to your auditor in Vanta/Drata.

Results · August 2026

Measured on real apps

Four numbers that show how well the engine stops others' data from leaking. Each number is from a real run.

0%

false positives

52 controls on clean apps — zero noisy alerts.

15

real vulnerabilities

across 10 foreign and vulnerable apps, each with behavioral proof.

20/20

runs in a row

20 targets, 0 network failures, full pipeline with no manual setup.

202

auto checks

engine tests pass after every change — from detection to boundaries.

Ordinary scanner

  • −looks for code patterns — many rules, little value
  • −“maybe here’s a problem” — developer decides
  • −doesn’t check if someone else got your data
  • −noise: 50 alerts, 45 false

SakaForge

  • +checks behavior in a running app — like a real attacker
  • +“here’s the data someone else got” — with proof
  • +finding only after three conditions: 200 + leak + replay
  • +clean app stays silent — no noise
Verified: npx tsx benchmark/verify-run.ts benchmark/results/sakaforge-2026-08-16.json → 0 FP
Leaderboard → Last scan: 2026-08-23 · commit 51dede59 · HMAC a8f3…9c1e

Honest about limits: numbers are real runs on foreign authorized and local apps. 20+ external client projects await owner consent — when they appear, numbers will be replaced with their results.

Proof-Gated Exploit Engine

No Heuristics. No Guesswork.

Traditional scanners flag code patterns and report "potential risks." SakaForge executes real adversarial transactions and alerts only when all 3 verification conditions are met. If any condition fails — the gate remains silent.

Zero-Noise Verification Policy: alerts triggered only on confirmed, reproducible data leaks.

See verification →
1

Verified 200 OK Response

Attacker receives successful response for unauthorized resource. 401/403/404 — not counted, gate silent.

2

Provable Data Leak

Response payload contains victim data — verified via deep JSON diff against owner reference state (or provable state mutation: created/deleted object).

3

Fresh-State Replay (2/2)

Exploit is automatically re-executed on newly seeded entities to eliminate state contamination. Both replays must be identical — one fail = no finding. Zero noise in your PRs.

Deterministic

no heuristics

Reproducible

fresh-state 2/2

HMAC

signed every step

Evidence: redacted cURL + tamper-proof audit-trail.jsonl with HMAC-SHA256 per step. If any condition fails, gate remains silent.

Live agent • as in video, but real

Watch the agent pull code and break it

One focus at a time. No noise. Hover — pause. Click a dot — switch stage.
Run live check in dashboard →

Remotion render 60s • code → attack → proof → fix • скачать mp4 • вставь в письмо как превью

Live theft on your preview: two users, one theft, cURL proof in 60 sec. No demo call needed.

commit 51dede59 • tree digest 9c1e…a8f3 • HMAC signed • replay 2/2 • < 60s • press ← →

Pricing — runs on your GitHub Actions

Pay for the license, not our servers

Running on your own GitHub Actions runners ensures zero compute markup and guarantees your data never leaves your infrastructure boundary.

Developer

$0

Free

Unlimited Public Repos · 1 Private Repo · 50 scans/mo · Basic Proofs

Start free →

Team · popular

$29/dev/mo

or $299/repo/mo

Unlimited PR Gates · Proof Engine · Auto-Fix Generation · 30-day Audit Trail

Choose Team →

Compliance

$1,500/mo

For Series A–B undergoing SOC 2

Multi-repo · Vanta & Drata Evidence Stream · Signed HMAC Chains · Priority Support

Choose Compliance →

Enterprise

Custom

Scale-ups & FinTech

Dedicated Runner / On-Prem · Zero-Data-Retention LLM · 99.9% SLA · Custom Auth Adapters

Contact →

Overage $0.60/scan. Pilot design-partner: Free → $12k/yr if 2+ BOLA before audit.

How it works

Checks the way an attacker does

Four steps. No configs, no babysitting — the engine deploys the check on every PR preview itself.

01

Preview launched

Your PR creates a preview. SakaForge connects, sees changed files and pins the exact commit.

02

Two users

Registers owner and attacker in the same running app — two real sessions.

03

Attack & proof

Finding only after three conditions: request returned 200, data leaked, replay matched.

04

Fix verified

Patch is rerun as owner, attacker, admin and guest. All pass — fix goes to PR.

Trust Center · last updated 2026-08-27

Security you can verify in 5 minutes

No PDFs and promises. Every claim below is verifiable — run the verifier, check the HMAC, or request the doc. Built for procurement that opens /trust before the sales call.

Request docs →

External posture

Grade A · verified

Last scan 2026-08-23. HMAC-SHA256 chain, replay 2/2, 52 controls on clean apps — 0 FP. Verify: npx tsx benchmark/verify-run.ts

View raw result →

Certifications

SOC 2 Type II — In Preparation

Audit Period Q4 2026. Continuous control evidence available via vendor-neutral Vanta integration (Custom Tests API / Evidence Upload). Full report NDA-gated when available.

ISO 27001 aligned · controls mapped, cert not yet issued. No badge theater.

Compliance mapping

  • SOC 2 CC6.1 & CC6.3 — Logical Access Enforcement & Authorization Boundaries
  • SOC 2 CC7.1 — Vulnerability Identification & Remediation in CI/CD
  • PCI DSS 4.0.1 (Req 6.3.2 & 11.3) — Custom Software Security & Authenticated Testing
Request DPA →

Core controls — 10 that procurement always asks

  • • Encryption: TLS 1.3 in transit, AES-256-GCM at rest, HSM keys
  • • Auth: MFA enforced, SSO (SAML/OIDC) on Business+
  • • Access: RBAC least-privilege, 4-way check per fix
  • • Logging: HMAC chain per scan, append-only audit-trail.jsonl
  • • Infra: ephemeral Docker per PR, clean DB, deny-egress
  • • Backup: RPO 24h / RTO 4h, last DR test 2026-08-15

Sub-processors · updated within 30 days

Only services where SakaForge transfers customer data. Preview infra (Vercel/Neon) runs in your boundary and is not a SakaForge sub-processor.

  • • OpenRouter (LLM patch generation, Zero-Data-Retention) — US — only when fix is AI-generated, otherwise not used
  • • AWS/GCP (HMAC audit-trail storage, if you opt into hosted evidence) — EU/US per tenant
  • • GitHub (optional code checkout via App) — US/EU — only with your explicit App install

Customer data residency: EU/US per tenant. Full list + DPA on request.

Data boundary guarantee

Ephemeral execution. All attack transactions run inside isolated runner containers with automatic state teardown. No source code or customer DB dumps are ever stored on SakaForge servers.

Incident & disclosure

No significant incidents last 12 months. Disclosure: security@sakaforge.art · security.txt at /.well-known/security.txt · PGP on request. SLA: first response <24h.

Try it yourself

See how the engine checks your app

Sign up and run the live demo: the agent will walk through the check step by step, right in your browser.

Open dashboard →

FAQ

Questions & answers

Will it slow down our CI?

No. SakaForge runs on the preview in parallel with CI — never inside it. Hard 300-second budget for pilots (target 180s after optimization) and delta-only scanning keep it bounded. Non-blocking mode available.

How do you guarantee zero false positives?

A vulnerability is reported only when three conditions hold at once: the request returned 200, private data leaked (or state changed), and the exact attack replayed twice with identical results.

How do you get access to our code?

Only via the GitHub App you install or explicit owner consent tied to the exact deployed commit. Public code or URL is not permission.

Will test users pollute staging?

No. Every run ends with automatic cleanup of created entities, and calls to payment/SMS gateways are mocked.