Auditable security tooling, from the first scan to the prioritised backlog.
Kademos Labs builds focused, auditable software. Kekkai, our open-source CLI, unifies industry-standard scanners and streamlines local triage. Sinterly, our hosted Security ETL engine, turns the findings those scanners produce into a ranked, explainable backlog. Neither replaces the engines you already trust.
Products

Kekkai
Open source · Apache-2.0Local-first security triage for real repositories.
One CLI for Trivy, Semgrep, and Gitleaks — unified reports, interactive triage, and CI-friendly policies.
- Trivy, Semgrep and Gitleaks in one report
- Keyboard-driven triage in the terminal
- CI gates that fail on severity, not noise

Sinterly
Hosted · Code-blind by designThe Security ETL engine.
Ingests findings from the scanners you already run, deduplicates and enriches them, then ranks each one with an explainable five-component priority score — routed to the team that owns the fix.
- SARIF 2.1.0, CSV and OTM ingestion
- Five weighted components, every score auditable
- Jira routing and board-level reporting
What we optimize for
Privacy by default
Kekkai runs scanners wherever you point them, with no SaaS in the loop. Sinterly is code-blind — it works on scanner findings and has no path to your source.
Audit-friendly outputs
Structured JSON, explainable scores, and reports designed for security reviews and compliance evidence.
Secure defaults
Hardened container profiles, tenant isolation enforced in the database, and conservative CI behavior to reduce foot-guns.
