Real-world validation
Cybseco on public code, at scale
The accuracy benchmark asks whether a finding is right. This page asks a different question: does the engine run correctly on real code it has never seen, written by people who were not thinking about us. Everything below is a volume or a rate.
What these figures are, and what they are not
These numbers come from public repositories analysed automatically. Nobody has read every line of those projects to establish what vulnerabilities they actually contain, so no exhaustive ground truth exists for them and no precision, recall or F1 can honestly be computed from them. You will find none here. What they do show is reliability under variety: how many real projects the engine completed, in how many languages and technologies, how often the architecture graph built, and whether re-analysing the same commit gives the same answer. Our accuracy figures are measured somewhere else entirely, on a corpus we labelled by hand, and they are published separately so the two can never be averaged.
Loading the latest aggregate.
See Cybseco reason about a real-world system
Watch the interactive demo, then request a guided trial for your team.