~/security$ cat security.md

cat security.md

Security and penetration tests. Then AI that never sees the payload.

Pentest is a CodeStrux engagement, not a side note. We probe the stack you actually run. On confidential systems, agents see metadata only; the CodeStrux Tech team approves the script; the records never enter the model.

security/pentestcore

$ pentest --env

Security and penetration tests are how we earn the right to operate a stack. We test hosts, networks, identity, secrets, and the path from laptop to prod — the environment that is running, not a slide deck. Findings stay with the operators. We sit with the team that owns the box until exposure is closed.

security/metadata

$ describe --schema

Agents consume metadata only: shapes, schemas, volumes, column names — enough to predict how an extraction script should look. Not the confidential records. The model never receives the payload it is helping us reach.

security/review

$ review --human

The CodeStrux Tech team reads that script against human criteria before anything runs. An agent can propose; it cannot execute. Approval is a person, not a temperature setting.

security/run

$ run --compare

The approved script runs in the trusted environment, where the data already lives. We compare the extract against what the agent needed. If it is wrong, we correct the script and try again. Agents still never receive the data — not on the first pass, not on the retry.

security/why

$ why

This is how we take full advantage of LLMs — the speed of a proposed script, the coverage of a well-shaped extract — without putting confidential data in model context, and without a data-exfiltration path through the agent. The model helps us write the tool. The tool never reports the records back to the model.

security/learn

$ learn --live

The classroom version is live: we sell session courses so people learn safe coding practices. Unlock on CodeStrux Learn with USDC.

open learn

~/start

$ ./start.sh

Need a pentest, or this loop on a system you cannot expose to a vendor model? Tell us what you are building. See services for the rest of the stack, or how to pay when you are ready to settle.

contact WhatsApp ls services/