Scan a repository inside the enclave

codex-security clones the repository you name and scans it with an agent, entirely inside the confidential VM. Everything on this page travels through the sealed channel that verification opened, so the repository URL, the log, the findings and your API token are readable only to the enclave whose measurements you pinned.

Verify the endpoint first

This console will not send a repository URL, a token, or anything else until the endpoint has proved, to this browser, that it is the Intel TDX enclave running the pinned image. Scans then ride inside the channel that proof established.

Read the trust pagehttps://codex-security-scanner-dev.confidential.ai