adense
Open console Get started
Security verification for AI-built software

You ship overnight.
We verify in minutes.

AI made building software an overnight task. Security review still takes weeks and six figures. Kadense closes that gap — a full standards-mapped assessment of your codebase, in minutes, sealed with a badge your customers can verify themselves.

Read-only assessment · your code never leaves the sandbox · destroyed after the run

cadence · live assessment 58 / 142 assessing
00:41 PASS CRYPTOGRAPHY TLS enforces modern cipher suites
00:47 FAIL INPUT VALIDATION concatenated query reaches user input — src/repo/orders.py:112
00:52 PASS AUTHENTICATION password hashing uses a memory-hard KDF
00:58 PARTIAL SESSION SameSite missing on legacy cookie path
01:04 PASS SUPPLY CHAIN lockfile pinned, no unresolved advisories
58/142 applicable checks · 3 independent passes each · cross-validated
Assessed continuouslyAuthenticationCryptographyInput validationSession managementAccess controlSecrets handlingSupply chainLogging & monitoringConfigurationData protectionAPI surfaceLLM surface
562
Security checks
17
Frameworks & standards
Minutes
Not weeks. Every window.
Verifiable
Public badge, immutable scope

The problem

Shipping changed. Security review didn't.

AI-assisted development turned feature work from a multi-week team effort into an overnight task. But the code it produces still ships with hardcoded secrets, missing auth, injection paths and default configs — and the only established way to check was a consultancy engagement priced and paced for a slower era.

Traditional assessment
Turnaround2–6 weeks
Cost per engagementR80k–R150k
FrequencyOnce a year
OutputStatic PDF, outdated on arrival
Customer trust signalA report, shared manually
Kadense
TurnaroundMinutes
CostA fraction, per month
FrequencyOn your cadence — recurring
OutputLive console, file & line cited
Customer trust signalPublicly verifiable badge

Philosophy

An instrument, not an inspector.

Kadense sits between development and deployment as a quality gate. It measures — it never modifies. Four principles govern every assessment and every badge we issue.

01

Read-only, by design

Your code is staged in an isolated, no-network sandbox, analysed, and destroyed after the run. We never modify, execute against your infrastructure, or retain source. We assess, score, and report — nothing else.

02

Evidence, or it didn't happen

Every finding cites the file and line it came from. Every check runs through multiple independent passes and is cross-validated; agreement between passes becomes a confidence score you can see. No vibes, no black box.

03

The badge is earned, never sold

A badge issues only when every gate clears: the severity-weighted score meets threshold, zero critical or high failures remain, and confidence is sufficient. There is no manual override — not for us, not for you.

04

Honest about scope

A badge records an assessed posture at a point in time, against a recorded, immutable scope — and says so publicly. What was assessed, what was excluded and why, and when it expires are visible to every verifier. Trust comes from precision, not promises.

No overclaiming

What Kadense is — and what it is not.

In a category full of bold claims, precision is the differentiator. Here is exactly where we stand.

Kadense is
A grounded assessment tool. It reasons about your codebase against recognised international frameworks and explains why — citing file and line — rather than pattern-matching.
A visibility layer. One honest, shared picture of posture, findings and progress — for the CTO, the security lead, and the engineers.
A simplifier. A slow, siloed, jargon-heavy process, distilled per team into something they can read and act on — continuously.
Kadense is not
A penetration-testing firm. Our external check is non-intrusive and detect-only — extra evidence, never a claim of human-grade offensive testing.
A certification body. We are not SOC 2 or ISO auditors, and the badge never claims you are compliant or certified.
A guarantee of security. We show what was checked and what the posture is. Remediation stays yours — with exact instructions.
A noisy checkbox scanner. Findings are reasoned and evidence-cited — not a wall of alerts.

What it does

A grounded assessment of your codebase. Plus proof your live surface was looked at.

Pillar 1 · the core

Grounded codebase assessment

Upload a codebase and get a reasoned, framework-mapped posture score, evidence-cited findings, and a prioritised remediation queue — with fix instructions your team can paste into their own tools. Recurring on a cadence, so posture is tracked over time instead of measured once a year.

17
frameworks & standards, 562 mapped checks
Minutes
to a reasoned verdict — not 2–6 weeks
file:line
every finding cites its evidence
Pillar 2 · supporting

Non-intrusive external evidence check

At go-live, a defined, detect-only check of your public surface — TLS posture, exposed paths, security headers — adds a layer of evidence that your live system was looked at. Scope is signed, every target ownership-verified, every action logged to a forensic timeline.

An evidence layer — not a penetration test, and never sold as one.

Why "Kadense"

One assessment proves a moment. A cadence proves a posture.

No assessment — human or machine — finds everything on the first pass. We don't pretend otherwise. The answer isn't a perfect single run; it's security through repetition: regular, scheduled re-assessment that keeps your posture current, visible, and on the record.

You define your cadence in the console — weekly, monthly, per release. Assessment windows open on schedule, your team is notified, and every window is recorded. Miss one, and it's flagged in your report and visible to anyone verifying your badge. The rhythm is the product.

Assessment cadence — payments-api MONTHLY
!
MARAPRMAY · MISSEDJUNJUL · OPEN
Window open — 4 days remaining. Team notified.
Run now
Missed windows are flagged in the assessment report and visible on badge verification. Verifiers always see the date of the last completed run.

How it works

Submit your codebase. Get a verdict.

Independent of your pipeline — upload or connect whenever a window opens, on demand or on schedule. No CI/CD integration required.

1

Connect

Upload a ZIP or connect your repository. Every one of the 562 checks is carried through the run against your whole codebase. Typically 150–200 turn out to actually apply — and each of the rest is marked not-applicable with its reason, judged against your code rather than assumed away beforehand.

2

Assess

Contextual analysis — architecture, data flows, auth model, crypto — not pattern-matching. Multiple independent passes per check, cross-validated in an isolated sandbox.

3

Score & report

A severity-weighted score, findings with file:line citations, remediation guidance, and a live console that tracks what cleared between runs — no static PDFs.

4

Badge issues

When every gate clears, a verification badge issues automatically — with an immutable scope record your customers and their procurement teams can check independently.

Not one framework. Seventeen. 562 checks mapped across our framework set — every one carried per assessment, each marked applicable or not with its reason
OWASP ASVSv5.0
ISO/IEC 270012022
PCI-DSSv4.0
SOC 22017
NIST SSDFv1.1
POPIA2013
OWASP API Top 102023
OWASP LLM Top 102025
…and more+ standards

Validation

Calibrated against independent pentesters.

We built AI-generated applications ourselves and commissioned independent, third-party penetration testing firms to assess them. Their findings became our calibration baseline: the engine is tuned until it identifies the same issues — the same injection paths, the same session flaws, the same misconfigurations — with the goal of being as true as a manual pentest, or truer.

The difference isn't what gets found. It's when — and how often. A pentest is a snapshot you commission once a year; Kadense repeats the measurement on every scheduled window.

How the measurement works
Controlled apps, known ground truth
We author the applications, plant the weaknesses, and record them as labels before the engine ever sees the code. Every verdict is scored against a set of answers fixed in advance.
The production engine, unmodified
The harness drives the same engine, the same prompts and the same gates a customer run uses. There is no benchmark-only path to tune, and the corpus carries no hints for a model to read.
Missed and over-flagged, both counted
A planted weakness the engine fails to raise counts against it exactly as a finding it raises without cause. Abstention is recorded as abstention, never rounded into a pass.
Until a run is published, we quote no figure. Recall and precision are measured per run and published in full — method, corpus size and thresholds alongside the result — on the benchmark page.
Framework coverage grows continuously. The metrics behind our seventeen international frameworks are reviewed and extended on an ongoing basis, and every assessment covers the entire submitted codebase — not a sample.
A CVE engine tracks the threat landscape. Newly disclosed vulnerabilities and zero-days are monitored as they emerge; once a patch or mitigation standard exists, it is folded into the check set the same way. As threats evolve, the checks evolve with them.
See our benchmark methodology & published results The real engine, measured against controlled apps with known ground truth.

Org-wide visibility

No more building in isolation.

Teams, contractors and individual builders now ship production software in parallel — often without anyone watching the whole board. Kadense groups every application into projects and shows your entire development stack in one view: who's assessed, who's badged, who's drifting, and where the next window falls.

Acme Corp — all projects 9 applications · 3 teams · org posture 72
Payments team3 apps
payments-api76
billing-svc97
ledger-core91
Next window: 18 Jul · 1 badge issued
Platform team4 apps
customer-portal54
ingest-workerrun…
auth-gateway95
1 app below threshold · window open now
Contractors2 apps
mobile-bff68
promo-site
1 app never assessed · flagged
For the CTO / VP Eng

Confidence the team is shipping sound systems — without standing up a security function. A signal, not a project: posture per app, trend per team, one number for the board.

For the CISO / security lead

Continuous visibility across many apps and teams with the noise cut down — reasoned findings, evidence you can point to, and a queue that tracks who is fixing what.

For the IT officer / small team

The depth of a security expert without the headcount or the six-figure engagement — in plain language, with "I'm not sure" always a valid answer.

The badge

A trust signal your customers can check themselves.

Anyone — a customer, a procurement team, an auditor — can verify a Kadense badge and see exactly what it covers: assessment date, expiry, files and stack assessed, checks applied and excluded, score and confidence. No source code is ever exposed.

We're equally clear about what it isn't: not a guarantee of zero vulnerabilities, not a runtime assessment, not coverage for code we never saw. That honesty is the point — a trust signal that overclaims is worthless.

verify.cadence.dev/b/7F3K-A2M9 Valid
Verified
payments-api
Acme Corp (Pty) Ltd
Static assessment · Pillar 1 · issued 28 Jun 2026 · expires 28 Jun 2027
Security score96%
ConfidenceHIGH · 91%
Checks applied142
Excluded (N/A)218
Files assessed412 · 96k LOC
Critical / high fails0
CadenceMonthly · 11/12
Last completed run28 Jun 2026
Scope recorded immutably at issue. Point-in-time static assessment of the submitted codebase; runtime and infrastructure outside code are not covered. Verifiers see the date of the last completed run — missed assessment windows are flagged here and in the report. Revocable on evidence of misrepresentation.
01

Grounded, not pattern-based

Multiple independent passes reason about each applicable check and are cross-validated; agreement becomes a confidence score you can see. Every verdict cites the file and line it came from.

02

We get tested too

Kadense itself is independently penetration-tested. We don't say "trust us" — we hold ourselves to the same scrutiny we help you build towards.

03

Honest by design

Fail-closed engine, findings that quote their evidence, a badge that states its own limits, and code that is never stored — deleted after every run, with the deletion logged.

If you can build it overnight, you can verify it before breakfast.

Register your application, run your first assessment, and see exactly where you stand — in minutes.

Run your first assessment Open the console