Your code has bugs.
We brought a bloodhound.
Sortie combines local source inspection with model review to investigate security flaws. Primary review and finding verification use Codex CLI 0.149.0 and local Docker, with source context sent to your model provider.
local control plane Β· your model provider Β· no Sortie data service
Receipts, not promises.
Public security research that shaped RunSortie. Every card links to a disclosure, advisory, or bounty reportβnever a marketing placeholder.
Langflow
CVE-2026-10140One tenant's API key served everyone's voice traffic
Home Assistant
CVE-2026-64824Backup restore allowed root code execution
HashiCorp Vault
CVE-2026-14886Cross-namespace deletion of identity entities
n8n
CVE-2026-54305Cross-tenant credential takeover
OpenClaw
GHSA-grc3-2j34-p6gmmessage.action forwarding could send Gateway credentials to model-supplied loopback URLs
Mozilla
HackerOne #3734676Taskcluster OAuth2 authorization codes were reusable and checked against the wrong expiry column
Snapshot aligned with the public research index in August 2026. These are attributed research results, not measurements of the current RunSortie package. Findings awaiting disclosure remain abstract on the source page and are not promoted here.
Five moves. Explicit completion checks.
Point it at a repo, inspect the generated config, and schedule a one-shot scan. Every unattended result still has to pass the Git guard.
- π¦01
Set up for development
Build from an authorized source checkout. Configure Codex CLI 0.149.0 and local Docker for both reviewer roles; init writes model selectors to JSON config.
- πΊοΈ02
Map
Fieldglass parses supported security surfaces into typed facts, mandatory questions, and protected source anchors. Unsupported or incomplete semantics stay visible.
- π₯03
Challenge coverage
Before validation, an independent read-only model challenges missing questions and anchors using only the bounded structural facts it receives.
- π§04
Validate & review
Fieldglass checks required anchors. Primary review and a distinct finding verifier then use immutable source through container data tools and submit structured evidence. They cannot run target code. Missing or incomplete evidence keeps the run incomplete.
- π05
Accept or fail closed
Evidence stays in configured repo paths. Missing questions, failed model work, unsupported semantics, or an unsafe Git diff keep the run incomplete.
Follow the whole flight path.
An illustrative path through source inspection, model review, and evidence publication. Each stage has its own completion checks.
Local mission control
api Β· security review
Set up the current development reviewer route.
A source checkout builds the local CLI with Fieldglass bundled inside it. Primary and finding-verification reviews require Codex CLI 0.149.0 and local Docker. Init records targets and model selectors.
- βScan startup rejects other reviewer adapters and remote Docker endpoints
- βThe host broker uses a private temporary profile and reconciles refreshed file logins
- βScheduling is off until you explicitly approve it
Who owns each handoff
RunSortie
supervises
Fieldglass
maps + validates
Explorer
challenges coverage
Primary reviewer
adjudicates
Finding verifier
challenges proofs
Git guard
accepts
Stays in your control plane
Config Β· locks Β· checkpoints Β· evidence Β· Fieldglass source
Leaves only through services you choose
Model prompts Β· optional Git push Β· optional webhook JSON
There is no Sortie scan service in this path. Source context reaches the configured model providers. The host, CLI, Docker daemon, wrapper, and provider connection remain trusted. The reviewer boundary does not establish isolation for Fieldglass or its exploration challenger.
Scanners find patterns.
Sortie finds logic.
A regex has never understood what your code is trying to do. That gap is exactly where the interesting bugs live.
Your average SAST scanner
- βMatches known patterns and tainted sinks
- βDrowns you in low-signal noise
- βBlind to intent and business logic
- βOne vendor's model, take it or leave it
- βOpaque review and data boundaries
Sortie
- βMaps supported security surfaces into required questions
- βEvidence and triage notes stay reviewable
- βFails closed on missing questions, anchors, or model work
- βUser-selected engine, explorer, reviewer & verifier models
- βNo Sortie service in the data path
Structure plus reasoning
Fieldglass derives required questions from parser-backed facts. One model challenges coverage before validation; later reviewers independently resolve attacker access, the broken control, gained authority, and consequence.
Use existing auth
Config stores model selectors. Reviewer credentials stay in a private host broker profile, with temporary file-login copies and refresh reconciliation. Source snippets and prompts reach the configured provider.
Explicit reviewer boundary
Primary review and finding verification require Codex CLI 0.149.0 and local Docker. Their data-only tools have no external network access or host mounts. Fieldglass's upstream model routes are a separate execution path.
Runs on your infra
The control plane, config, checkpoints, and evidence live locally. Model prompts, optional Git pushes, and webhook status go only to services you configure.
Primary review and finding verification
These reviewers use container data tools and a trusted host model broker. Fieldglass and its exploration challenger have separate model routes. Review boundary and requirements β
From source to a
local development setup.
Contributors with access to the RunSortie product repository can build from source. Primary review and finding verification require Codex CLI 0.149.0, a local Docker daemon, and the pinned worker image. Customer packaging and signed delivery are still being prepared.
- πReviewer credentials stay in a private host broker profile
- πBundles the Fieldglass close-inspection engine
- π§ΎConfig stores selectors, not credentials
- β±οΈShows the exact schedule before you enable it
See the reviewer setup requirements and credential handling and cleanup. File-login reviews use temporary private credential copies; refreshed logins are reconciled after the broker stops.
The frozen v41 evaluation completed 0 of 4 full detection-and-fix lifecycles. The maturity scorecard and customer release gates remain open.
Paid pilot. Clear proof. One product.
Weβre preparing a small early-access cohort. The planned offer is a paid evaluation of RunSortie β not a bug bounty, and not a separate Fieldglass license. Customer delivery remains subject to the open product maturity and signed-release gates.
30 days to prove the workflow,
not just find a bug.
One repo. Your infra. Your model access. Fieldglass included. Unlimited internal users, with no per-seat, per-scan, per-finding, or separate engine charge.
Planned founding offer: $3,000 pilot, fully credited toward an annual subscription starting at $15,000. Terms remain an early-access pricing hypothesis until the cohort opens.
- 01
Start with a paid pilot
The planned design-partner offer is $3,000 for 30 days against one repo, on your infra and model accounts.
- 02
Measure the whole workflow
We agree on deployment, coverage, evidence quality, false positives, and review effort β not just whether one bug appears.
- 03
Credit it toward annual
If you continue, the pilot fee is credited in full. Founding subscriptions are expected to start at $15,000 per year for up to five monitored repos.
Questions a smart skeptic asks.
The honest answers. If yours isnβt here, an evaluation should answer it faster than we can.
It's the bundled Fieldglass inspection engine, security-review instructions, model review, evidence store, and completion checks. Primary review and finding verification currently require Codex CLI 0.149.0 and local Docker. The trusted wrapper validates submissions and writes accepted evidence to configured paths in your repo.
RunSortie has no hosted scan service. The host model broker sends review prompts, requested source snippets, and finding evidence to your configured provider under your account. Fieldglass and its exploration challenger also use configured model routes. Reviewer data tools run in a container with no external network access or host mounts; this does not make model inference offline. Optional pushes and notifications go to your configured destinations.
Primary review and finding verification support only Codex CLI 0.149.0 with a local Docker daemon through a Unix socket. They must use distinct model routes. Fieldglass's engine and exploration challenger have separate provider and CLI routes; the reviewer container boundary does not establish isolation for that upstream pipeline. Other reviewer adapters, remote Docker endpoints, and keychain-only Codex logins are unsupported.
Configuration stores selectors, not secrets. The trusted host broker writes an environment-supplied OPENAI_API_KEY or copies file-based Codex login credentials into a private temporary profile. They never enter its source snapshot or container tools. Refreshed file logins are reconciled after the broker stops. Normal completion removes the profile. Conflicting updates, crashes, or forced kills can leave private recovery profiles or login locks for operator cleanup.
It adds two evidence-bound challenge points around Fieldglass. Before validation, a separately configured read-only model challenges omitted security questions and anchors using typed structural facts. For every finding at the configured thresholdβhigh and critical by defaultβthe primary and a distinct verifier then independently resolve attacker capability, the violated control, the authority gained, and the consequence from exact lines at the scanned Git revision. Missing, stale, unsupported, incomplete, failed, or disagreeing work leaves the run incomplete. The roles may use the same provider, so cross-vendor review is not claimed.
No. RunSortie proves completion only for the security questions and framework semantics it actually mapped. Supported surfaces, required anchors, model work, and unresolved gaps are recorded; unsupported frameworks or incomplete work make coverage inconclusive rather than silently clean. It is a security-research system, not a whole-program proof engine.
RunSortie produces source-based findings and review evidence. Its reviewer tools can list, read, search, and submit structured data; they cannot execute target code, tests, builds, or reproduction steps. A person confirms findings, scopes impact, and decides what to report.
Customer delivery is not approved. The frozen v41 evaluation completed 0 of 4 baseline-to-introduced-change-to-fix lifecycles: the introduced-change phases were degraded and the fix checks were skipped. Later engineering checks do not replace a fresh lifecycle evaluation. Product maturity, production packaging, signing, and customer delivery gates remain open. Source installation is a development workflow for people with repository access.