Technical trust

Security claims should come with boundaries.

Speculynx separates deterministic contract facts, account access, and human decisions. This page states what the product does—and what it does not prove.

Local-first analysis

Static OpenAPI analysis runs locally. The source file is not uploaded for license or entitlement verification.

Deterministic output

Versioned terminal and JSON contracts expose findings, verdicts, diagnostics, and coverage.

Bounded synchronization

Optional dashboard synchronization sends a versioned, sanitized result—not the OpenAPI source.

Exact entitlements

Pro and Agent Security access remain separate. The Suite grants exactly three Agent capabilities.

Signed billing events

Authenticated checkout intent and signed Stripe webhook completion drive billing records and grants.

Credential lifecycle

Agent credentials can be issued, rotated, and revoked. The raw secret is shown once and not stored in recoverable form.

Analysis boundary

Static evidence is one layer of the security decision.

Speculynx does not prove live IAM, runtime reachability, prompt-injection resistance, absence of vulnerabilities, or safe agent execution. Validate those properties with runtime evidence and human review.

A finding is a signal to verify. A PASS is scoped to the evaluated contract model and coverage; it is not a production safety guarantee.

Report a vulnerability

Inspect the contract before the agent acts.

Start with a local OpenAPI review, then choose the Agent Security workflow that matches your decision.

Analyze your API