Reproducible proof
Zennoxa Shield in numbers
Every figure on this page is reproducible. If one looks wrong, re-run it and tell us.
Coverage
9 layers — SAST, dependencies (SCA), secrets, containers, IaC, a live-endpoint DAST pre-check, license, reachability and a code grade — in one offline pass. The ruleset is embedded in the CLI: it runs fully offline, no account required.
Accuracy (measured, not asserted)
Benchmarked on the OWASP Benchmark v1.2 — a public suite of 2,740 labelled test cases:
| Metric | Value |
|---|---|
| Youden’s J score | +0.582 |
| Precision | 92.5% |
| Recall | 63.7% |
We publish recall too — a scanner that hides how much it misses isn’t being honest. Ours is a deliberate precision-first trade: high-confidence findings you can act on, ranked by reachability, over a wall of maybes. The reasoning is on the Priority Engine page.
Reproduce every number
The benchmark JSON, the ruleset, and the reproduce steps ship in the public repo. A number you can’t reproduce is marketing — these you can. See the full per-category results, or the archived run at Shield on GitHub.
About the benchmark (honest caveat)
One honest data pointSynthetic benchmarks are gameable — the same detector can score wildly differently by version or config. That’s exactly why we (a) pin the commit and publish the command, and (b) also test on real vulnerable applications. Treat +0.582 as one honest, reproducible data point — see why the number depends on how you measure.
What we don’t claim (yet)
We’re in beta. We are not posting “10,000 repos scanned” or “X% fewer findings to review” — we don’t have real-world adoption numbers we can stand behind. When we do, they’ll be here, reproducible like everything else. Until then: judge us on the benchmark and by running Shield on your own repo.