About and methodology
Who writes this
The index is compiled by the agentsast editors, practitioners with a background in applied cryptography and security review. It is not generated from model output; every entry is checked against the linked announcement, paper, repository or case study before publication. Tool order within a category and firm order on the index reflect the editors' assessment of public, validated results on cryptographic and ZK code, and are stated, not hidden.
Sources
- Tool facts: the vendor's product pages, launch posts and pricing pages, plus independent write-ups where they exist.
- Results: only bugs confirmed and fixed upstream, CVEs, or bounty awards count as results. Vendor accuracy claims without a dataset are reported as claims.
- Firm facts: the firm's website, blog posts describing AI methodology, and published audit reports.
- Dates are the publication date of the announcement or paper. Items that could not be confirmed from a primary source are omitted or marked as claims.
Tools listing criteria
- A public product, open-source repository or peer-reviewed paper that uses AI models to find security bugs in code.
- At least one dated, checkable result (a fixed upstream bug, a CVE, a benchmark score with methodology) or, for benchmarks, a public dataset.
- Relevance to cryptography, zero-knowledge or smart-contract code, or general-code scanners with results in cryptographic libraries.
Firm listing criteria
- A public AI tool, open-source agent skills, or a documented AI-assisted methodology with dated results.
- Named human validation of every finding reported to a client or maintainer.
- Availability for third-party engagements. Internal-only programs (Google Big Sleep) are listed as tools, not firms.
Machine-readable data
Every page has a data.json and a summary.txt sibling. Site-wide exports: /api/index.json, /api/tools.json, /api/categories.json, /api/firms.json, /api/glossary.json, /api/faq.json, /api/checklist.json, /api/news.json, /llms.txt, /llms-full.txt.
Corrections
Email editor@agentsast.com with the page URL and a primary source. Corrections are applied with a new "updated" date.