Docs / FUNDAMENTALS
FUNDAMENTALS
Architecture at a Glance
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex is composed of 14 specialized engines that cooperate around a single shared truth source. This page is the bird's-eye view: how the engines connect, what flows between them, and when each runs.
The Pipeline
Every Korthex run starts at the Scanner and fans out to the analytical engines. The Baseline Registry sits underneath as the shared truth source - every other engine consults it. Input Source code · Binaries · Configuration · Runtime processes ↓ Stage 1 Scanner AST · Binary · Runtime · TLS · Git · Config ↓ Stage 2 Context Engine Dataflow · Taint analysis · Cross-file clustering · FP filtering ↓ Stage 3 - analytical fan-out Inventory CBOM · SBOM Impact Audience reports Dataflow Graph queries Policy CI gate · SARIF Planner Migration plan Neural Network On-device hints Runtime Agent Live observation Exploit PoC evidence ↓ Shared truth source - consulted by every stage above Baseline Registry 11 500+ algorithm rules · classification · min-key-bits · deadlines Side-band engines Accuracy Engine - precision/recall/F1 measurement against ground-truth corpora. Mesh-Relay - outbound event forwarding for fleet-scale Enterprise deployments. Auto Migration (V2) - consumes Planner output, executes context-aware code rewrites with diff-review.
Engine Roles
| Engine | Asks | Answers | Produces |
|---|---|---|---|
| Scanner | What crypto is used and where? | Per-file findings. | Findings JSON / .krx |
| Context Engine | Which findings actually matter? | Reduced false positives, clusters, cross-file groupings. | Enriched findings |
| Baseline Registry | Is this algorithm strong enough? | recommended / acceptable / deprecated / disallowed. | Lookup table |
| Inventory | What cryptography do we have, in total? | Comprehensive crypto-asset list. | .kxi + CycloneDX + SPDX |
| Impact | What's the business impact? | Per-audience risk reports. | JSON / PDF per audience |
| Dataflow | How does this key flow through the system? | Graph of crypto relationships. | .kxg.* (6 variants) |
| Policy | Does this scan pass our rules? | BLOCK / WARN / ALLOW verdicts. | SARIF / JUnit / JSON + exit code |
| Planner | How do we fix it? | Sequenced migration plan with hours + deadlines. | .krx (plan) + PDF |
| Neural Network | How confident is this detection? | On-device ML hints for ambiguous patterns. | Predictions consumed by other engines |
| Runtime Agent | What does the code do at runtime? | Live observations from a running process. | .krxr |
| Exploit | Is this finding actually exploitable? | Proof-of-concept evidence per finding. | SARIF / JSON |
| Auto Migration (V2) | Can we just fix it? | Context-aware automatic rewrites. | Working-tree diff |
| Accuracy | Is the scanner getting better? | Precision / recall / F1 measurement. | Measurement JSON |
| Mesh-Relay | How do multiple installations coordinate? | Forwarded scan events. | Wire events (signed) |
When Each Engine Runs
| Phase | Engines active |
|---|---|
| Scan | Scanner -> Context Engine -> Neural Network Engine (hints) -> Baseline Registry (lookups throughout). |
| Post-scan analytics | Inventory, Impact, Dataflow, Policy, Planner, Exploit. Each runs independently against the scan output. |
| Migration | Planner produces the plan; (V1) Migrate simulate previews; (V2) Auto Migration executes; Accuracy measures success. |
| Operations | Runtime Agent (on-demand against live processes). Mesh-Relay (continuous, when enabled). |
| Maintenance | Accuracy Engine (regression testing). Baseline-Registry refresh (monthly update bundles). |
Key Architectural Decisions
Offline-first. Every engine runs locally. No source code or scan data leaves the machine unless you opt in to telemetry, the Dashboard, or Mesh-Relay. Single truth source. The Baseline Registry is the only place algorithm classification lives. Severity, ELS, compliance verdicts, and migration recommendations all derive from it - so they stay consistent. Stable file formats. Every Korthex artifact has a defined extension, format, and compatibility policy. See File Format Reference . CI-native. Every analytical engine that produces output produces SARIF as an option, so findings flow into the platform you already use. Fail-closed where it matters. Exploit Engine is gated by default; Mesh-Relay requires a TLS pin file or refuses to start; license issues stop the engine rather than continuing degraded. On-device ML. The Neural Network Engine never sends inputs over the network - only optional model-version checks with explicit consent.