Built from research behind 20 coordinated disclosures

Your code has bugs.
We brought a bloodhound.

Sortie combines local source inspection with model review to investigate security flaws. Primary review and finding verification use Codex CLI 0.149.0 and local Docker, with source context sent to your model provider.

local control plane Β· your model provider Β· no Sortie data service

sortie β€” illustrative review flow
➜ ~/app runsortie doctor
βœ“ reviewers: Codex CLI 0.149.0 + local Docker
β—† reviewer tools: immutable source Β· no target execution
➜ ~/app runsortie scan --target api
β—† Fieldglass: mapping required security questions and anchors
β—† explorer: challenging coverage before validation
β—† api: invoking Codex CLI for primary review
review submission: structured evidence
β—† wrapper: validating source-bound arguments from both models
β—† unresolved review evidence: completion withheld
How it works

Five moves. Explicit completion checks.

Point it at a repo, inspect the generated config, and schedule a one-shot scan. Every unattended result still has to pass the Git guard.

  1. πŸ“¦
    01

    Set up for development

    Build from an authorized source checkout. Configure Codex CLI 0.149.0 and local Docker for both reviewer roles; init writes model selectors to JSON config.

  2. πŸ—ΊοΈ
    02

    Map

    Fieldglass parses supported security surfaces into typed facts, mandatory questions, and protected source anchors. Unsupported or incomplete semantics stay visible.

  3. πŸ₯Š
    03

    Challenge coverage

    Before validation, an independent read-only model challenges missing questions and anchors using only the bounded structural facts it receives.

  4. 🧠
    04

    Validate & review

    Fieldglass checks required anchors. Primary review and a distinct finding verifier then use immutable source through container data tools and submit structured evidence. They cannot run target code. Missing or incomplete evidence keeps the run incomplete.

  5. πŸ””
    05

    Accept or fail closed

    Evidence stays in configured repo paths. Missing questions, failed model work, unsupported semantics, or an unsafe Git diff keep the run incomplete.

illustrative development setup
➜ ~/app runsortie init --agent codex --no-schedule
βœ” detected Codex CLI 0.149.0 Β· reviewer route
βœ” config contains selectors, not credentials
βœ” wrote .runsortie/config.json
– schedule not enabled Β· run runsortie scan manually
➜ ~/app runsortie doctor
Reviewer prerequisite: local Docker + pinned image
Under the hood

Follow the whole flight path.

An illustrative path through source inspection, model review, and evidence publication. Each stage has its own completion checks.

πŸͺ‚

Local mission control

api Β· security review

Stage 01runsortie CLI

Set up the current development reviewer route.

A source checkout builds the local CLI with Fieldglass bundled inside it. Primary and finding-verification reviews require Codex CLI 0.149.0 and local Docker. Init records targets and model selectors.

➜runsortie init --agent codex --repo ~/code/api
  • βœ“Scan startup rejects other reviewer adapters and remote Docker endpoints
  • βœ“The host broker uses a private temporary profile and reconciles refreshed file logins
  • βœ“Scheduling is off until you explicitly approve it
Example tracelocal
reviewercodex 0.149.0
dockerlocal
configselectors only

Who owns each handoff

01

RunSortie

supervises

02

Fieldglass

maps + validates

03

Explorer

challenges coverage

04

Primary reviewer

adjudicates

05

Finding verifier

challenges proofs

06

Git guard

accepts

βŒ‚

Stays in your control plane

Config Β· locks Β· checkpoints Β· evidence Β· Fieldglass source

β†—

Leaves only through services you choose

Model prompts Β· optional Git push Β· optional webhook JSON

There is no Sortie scan service in this path. Source context reaches the configured model providers. The host, CLI, Docker daemon, wrapper, and provider connection remain trusted. The reviewer boundary does not establish isolation for Fieldglass or its exploration challenger.

Why it's different

Scanners find patterns.
Sortie finds logic.

A regex has never understood what your code is trying to do. That gap is exactly where the interesting bugs live.

πŸ”¦

Your average SAST scanner

  • βœ•Matches known patterns and tainted sinks
  • βœ•Drowns you in low-signal noise
  • βœ•Blind to intent and business logic
  • βœ•One vendor's model, take it or leave it
  • βœ•Opaque review and data boundaries
πŸͺ‚

Sortie

  • βœ“Maps supported security surfaces into required questions
  • βœ“Evidence and triage notes stay reviewable
  • βœ“Fails closed on missing questions, anchors, or model work
  • βœ“User-selected engine, explorer, reviewer & verifier models
  • βœ“No Sortie service in the data path
🧠

Structure plus reasoning

Fieldglass derives required questions from parser-backed facts. One model challenges coverage before validation; later reviewers independently resolve attacker access, the broken control, gained authority, and consequence.

πŸ”‘

Use existing auth

Config stores model selectors. Reviewer credentials stay in a private host broker profile, with temporary file-login copies and refresh reconciliation. Source snippets and prompts reach the configured provider.

πŸ”Œ

Explicit reviewer boundary

Primary review and finding verification require Codex CLI 0.149.0 and local Docker. Their data-only tools have no external network access or host mounts. Fieldglass's upstream model routes are a separate execution path.

πŸ—οΈ

Runs on your infra

The control plane, config, checkpoints, and evidence live locally. Model prompts, optional Git pushes, and webhook status go only to services you configure.

Primary review and finding verification

Codex CLI 0.149.0Local DockerImmutable source snapshotData-only reviewer toolsCodex CLI 0.149.0Local DockerImmutable source snapshotData-only reviewer tools

These reviewers use container data tools and a trusted host model broker. Fieldglass and its exploration challenger have separate model routes. Review boundary and requirements β†—

Development setup

From source to a
local development setup.

Contributors with access to the RunSortie product repository can build from source. Primary review and finding verification require Codex CLI 0.149.0, a local Docker daemon, and the pinned worker image. Customer packaging and signed delivery are still being prepared.

  • πŸ”‘Reviewer credentials stay in a private host broker profile
  • πŸ”­Bundles the Fieldglass close-inspection engine
  • 🧾Config stores selectors, not credentials
  • ⏱️Shows the exact schedule before you enable it

See the reviewer setup requirements and credential handling and cleanup. File-login reviews use temporary private credential copies; refreshed logins are reconciled after the broker stops.

The frozen v41 evaluation completed 0 of 4 full detection-and-fix lifecycles. The maturity scorecard and customer release gates remain open.

$runsortie init --agent codexcopy ⌘C
illustrative source setup Β· repository access required
➜ ~/app git clone https://github.com/anshumanbh/runsortie.git
➜ ~/app cd runsortie && npm install && npm install -g .
➜ ~/app runsortie init --agent codex --agent-model <primary> \
--verifier-agent codex --verifier-model <challenger> \
--verifier-minimum-severity high --no-schedule
πŸͺ‚ runsortie init
β—† reviewers require Codex CLI 0.149.0 + local Docker
βœ” wrote .runsortie/config.json
βœ” engine: bundled Fieldglass
βœ” no credential written to config
➜ ~/app runsortie doctor
β—† verify prerequisites before a development scan
Planned pricing

Paid pilot. Clear proof. One product.

We’re preparing a small early-access cohort. The planned offer is a paid evaluation of RunSortie β€” not a bug bounty, and not a separate Fieldglass license. Customer delivery remains subject to the open product maturity and signed-release gates.

πŸͺ‚ early access pricing

30 days to prove the workflow,
not just find a bug.

One repo. Your infra. Your model access. Fieldglass included. Unlimited internal users, with no per-seat, per-scan, per-finding, or separate engine charge.

Planned founding offer: $3,000 pilot, fully credited toward an annual subscription starting at $15,000. Terms remain an early-access pricing hypothesis until the cohort opens.

  1. 01

    Start with a paid pilot

    The planned design-partner offer is $3,000 for 30 days against one repo, on your infra and model accounts.

  2. 02

    Measure the whole workflow

    We agree on deployment, coverage, evidence quality, false positives, and review effort β€” not just whether one bug appears.

  3. 03

    Credit it toward annual

    If you continue, the pilot fee is credited in full. Founding subscriptions are expected to start at $15,000 per year for up to five monitored repos.

FAQ

Questions a smart skeptic asks.

The honest answers. If yours isn’t here, an evaluation should answer it faster than we can.

It's the bundled Fieldglass inspection engine, security-review instructions, model review, evidence store, and completion checks. Primary review and finding verification currently require Codex CLI 0.149.0 and local Docker. The trusted wrapper validates submissions and writes accepted evidence to configured paths in your repo.

RunSortie has no hosted scan service. The host model broker sends review prompts, requested source snippets, and finding evidence to your configured provider under your account. Fieldglass and its exploration challenger also use configured model routes. Reviewer data tools run in a container with no external network access or host mounts; this does not make model inference offline. Optional pushes and notifications go to your configured destinations.

Primary review and finding verification support only Codex CLI 0.149.0 with a local Docker daemon through a Unix socket. They must use distinct model routes. Fieldglass's engine and exploration challenger have separate provider and CLI routes; the reviewer container boundary does not establish isolation for that upstream pipeline. Other reviewer adapters, remote Docker endpoints, and keychain-only Codex logins are unsupported.

Configuration stores selectors, not secrets. The trusted host broker writes an environment-supplied OPENAI_API_KEY or copies file-based Codex login credentials into a private temporary profile. They never enter its source snapshot or container tools. Refreshed file logins are reconciled after the broker stops. Normal completion removes the profile. Conflicting updates, crashes, or forced kills can leave private recovery profiles or login locks for operator cleanup.

It adds two evidence-bound challenge points around Fieldglass. Before validation, a separately configured read-only model challenges omitted security questions and anchors using typed structural facts. For every finding at the configured thresholdβ€”high and critical by defaultβ€”the primary and a distinct verifier then independently resolve attacker capability, the violated control, the authority gained, and the consequence from exact lines at the scanned Git revision. Missing, stale, unsupported, incomplete, failed, or disagreeing work leaves the run incomplete. The roles may use the same provider, so cross-vendor review is not claimed.

No. RunSortie proves completion only for the security questions and framework semantics it actually mapped. Supported surfaces, required anchors, model work, and unresolved gaps are recorded; unsupported frameworks or incomplete work make coverage inconclusive rather than silently clean. It is a security-research system, not a whole-program proof engine.

RunSortie produces source-based findings and review evidence. Its reviewer tools can list, read, search, and submit structured data; they cannot execute target code, tests, builds, or reproduction steps. A person confirms findings, scopes impact, and decides what to report.

Customer delivery is not approved. The frozen v41 evaluation completed 0 of 4 baseline-to-introduced-change-to-fix lifecycles: the introduced-change phases were degraded and the fix checks were skipped. Later engineering checks do not replace a fresh lifecycle evaluation. Product maturity, production packaging, signing, and customer delivery gates remain open. Source installation is a development workflow for people with repository access.