Skip to main content
Scan tiers are composable flags. Each tier adds capability while keeping everything below it.
complior scan
Coverage60–70%
Time2–5 seconds
DependenciesNone (zero install)
What runsL1–L4 checks + Rust-native secret detection (37 patterns)
Works completely offline. No internet, no accounts, no API keys.

Deep scan tools

Tools auto-downloaded on first --deep run:
ToolLicenseWhat it does
SemgrepLGPL-2.1Multi-language AST rules (20–30 YAML rules)
BanditApache 2.0Python security analysis (pickle, eval, exec)
ModelScanApache 2.0Model file backdoor detection (.pt/.pkl/.safetensors)
All cached in ~/.complior/tools/. No manual setup needed.