# Zennoxa Shield Full-content version of this file (capability numbers, published benchmark results, every documented rule, glossary, research studies): https://zennoxa.com/llms-full.txt > Zennoxa Shield is a developer-first code security scanner. One scan runs multiple layers over your repository — static analysis (SAST), secret detection, dependency checks, container image scanning, Infrastructure-as-Code (IaC) checks, and a live-endpoint DAST pre-check (security headers, TLS, exposure — not full crawling) — then ranks every finding by real-world risk using reachability analysis and a priority score, so teams fix what actually matters first. Connect GitHub, GitLab, or Bitbucket. Free during beta. ## What it does - Multi-layer scanning in a single run: SAST, secrets, dependencies, containers, IaC, plus a reachability ranking pass, a code-quality grade, a CycloneDX/SPDX SBOM, and a live-endpoint DAST pre-check (headers, TLS — not full crawling) - Reachability analysis: flags whether vulnerable code is actually reachable - Risk-based priority scoring: ranks findings by real-world risk, not just raw severity - Code quality grade for each scan - AI-assisted explanations and suggested fixes: a local LLM writes a plain-language explanation and a suggested code fix for each finding, which you review before applying - Works with GitHub, GitLab, and Bitbucket (public or private repositories) - Available as a web dashboard and a command-line interface (CLI) ## Who it is for - Developers and small teams without a dedicated security team - Startups, software houses, and small-to-medium businesses (SMEs) ## Key pages - [Product overview](https://zennoxa.com/): what Zennoxa Shield is and how it works - [User guide](https://zennoxa.com/guide): step-by-step setup, scanning, and CLI usage (available in Thai and English) - [Application Security Glossary](https://zennoxa.com/glossary): 60 plain-English AppSec definitions (SAST, SCA, reachability, EPSS/CVSS/KEV, IaC, secrets, taint analysis) with FAQ + DefinedTerm schema - [Documentation](https://zennoxa.com/docs): reference docs for the dashboard, CLI, and API ## Facts - Pricing: free during beta; there is no signup paywall at this time. - The scanning engine is rule-based, not AI-generated: findings are produced by Shield's own rules across the layers listed above. AI is used only to assist — writing explanations and suggested fixes that a human reviews before applying — never to invent findings. - Shield does not resell or expose a third-party CVE vulnerability database; findings are produced by Shield's own rules. - Positioning: a developer-experience-led alternative for teams that want prioritized, actionable results instead of a wall of undifferentiated findings.