DEV Community

Cover image for Verify Everything, Trust Nothing: an open-source security platform where even the AI has to show its work
Huỳnh Lê Nhất Nghĩa
Huỳnh Lê Nhất Nghĩa

Posted on

Verify Everything, Trust Nothing: an open-source security platform where even the AI has to show its work

Most security tooling asks you to trust it. The SCA scanner guesses that a CVE applies. The SAST tool floods your PR with maybes. The shiny new "AI security assistant" confidently tells you something is exploitable — and you have no idea how it decided that.

I kept hitting the same wall: a pile of findings, no custody, no proof, and an AI I couldn't audit. So the thing I got excited about building (and now get to share) takes the opposite stance, right there in the tagline:

Verify Everything. Trust Nothing.

Meet Synapse — an open-source (Apache-2.0), Go control plane that runs the whole security-assessment lifecycle behind one gate and treats every result as evidence you can re-check, not an alert you have to believe.

👉 Want to just click around first? There's a live playground — no install, no signup: synapse-playground.pages.dev


The problem: security tools that can't show their work

Three things broke my trust in the usual stack:

  1. False positives with no reachability. A CVE in a dependency you import but never actually call still lights up red. Triage eats your week.
  2. No chain of custody. A scan result is a line in a report. Who produced it? From what input? Can you prove it wasn't edited before the auditor saw it? Usually: no.
  3. LLMs in the critical path. The moment a model's free-text opinion can confirm a vulnerability or write your final report, you've traded a deterministic process for a vibe.

Synapse is basically a long answer to "what if none of that were allowed?"

What Synapse actually is

One platform, every angle — supply chain, code, cloud, offensive, and runtime defense:

  • 📦 SCA with a detection-independent engine: it owns its SBOM parsers (npm, PyPI, Maven, Gradle, Go, Cargo, RubyGems, and more) and its advisory matching, ingesting OSV, GHSA, CSAF and OVAL — so detection isn't hostage to any single vendor.
  • 🎯 Reachability that's sound by construction. A deterministic call graph (Go, plus JVM and JS/TS tiers) decides whether a vulnerable symbol is actually reachable from your code. It only ever raises urgency when it can prove a reference — it never silently marks something safe on a guess.
  • 🔎 First-party SAST + taint, secret scanning, and IaC misconfiguration (Terraform, CloudFormation, ARM, Kubernetes), plus third-party SARIF ingest.
  • 🧾 Risk-based prioritization ordered by exploitability — CISA KEV → EPSS → CVSS, never raw CVSS.
  • 🛰️ Blue-team runtime defense: an eBPF-backed agent fleet where a runtime detection is attributable, hash-chained evidence joined to the same asset, finding and attack path the static pillars reason about — plus governed response actions and purple-team coverage.
  • 🔴 Offensive side too: recon in a hardened sandbox, an attack-path graph, and governed exploitation under the same admission + evidence rules.

The three ideas that make it different

1. Deterministic-first — no model in the report path

Scanning, matching and reporting are pure, reproducible Go. Reports are templated from stored data. The output you hand an auditor was computed, not generated.

2. Evidence, not alerts — hash-chained custody

Every artifact is hash-chained into a tamper-evident custody record (RFC-3161 anchored). A broken chain blocks the report. You can prove what was found, from what input, and that nobody edited it in between.

3. The Judgment primitive — the AI has to prove it

This is my favorite part. Every AI/analysis claim goes through propose → verify → confirm. The agent is propose-only: it can suggest a reachability result, a SAST finding, a risk narrative — but a gated claim is promoted only when a distinct verifier seals a verdict over the evidence. The model that made the claim can never confirm its own claim, and it never sits in the report path. AI helps; it doesn't get to lie.

And underneath all of it: safe by construction — argv-only tool execution inside a Linux sandbox, server-side scope + authorization enforced before any tool runs, secrets that never leave the server, RBAC + tenant isolation (Postgres RLS) through a single authorization chokepoint.

It fits your pipeline

synapse-cli is a single static binary that gates a build and emits SARIF for code scanning, with CycloneDX/SPDX + PURL, OpenVEX, and KEV/EPSS all native:

# Gate a repo in CI — fail the build on high-severity, reachable findings
synapse-cli scan ./path/to/project --fail-on high --sarif > results.sarif
Enter fullscreen mode Exit fullscreen mode

Standards in, standards out. No lock-in.


Try it in 60 seconds (no install)

The fastest way to get the feel for it is the browser playground — poke at a scan, see findings tied to evidence, watch the reachability call it:

👉 synapse-playground.pages.dev

No signup, nothing to install. Bring a repo in your head and see how the "evidence, not alerts" model reads.

Like it? Two small things would mean a lot

Synapse is open source (Apache-2.0) and built in the open:

  • ⭐ Star the repo so more folks find it: github.com/KKloudTarus/synapse-ce
  • 🛠️ Contribute — it's clean-architecture Go (1.26), the issues are labeled, and there's genuinely interesting work across SCA matchers, reachability tiers, SAST rules, and the blue-team fleet. PRs and discussion very welcome.
  • 🐛 Found a false positive or a missed CVE? That's the most useful bug report there is for a tool like this — open an issue.

If the idea of a security platform that has to prove every finding — and keeps even its own AI honest — sounds like your kind of thing, come kick the tires.

Verify everything. Trust nothing. 🔐

Synapse is for authorized security testing only — every engagement enforces an explicit scope and authorization window, server-side, before any tool runs.

Top comments (0)