Local-first analysis
Static OpenAPI analysis runs locally. The source file is not uploaded for license or entitlement verification.
Technical trust
Speculynx separates deterministic contract facts, account access, and human decisions. This page states what the product does—and what it does not prove.
These statements preserve the existing technical trust contract while moving the page from static HTML to native Next.js.
Static OpenAPI analysis runs locally. The source file is not uploaded for license or entitlement verification.
Versioned terminal and JSON contracts expose findings, verdicts, diagnostics, and coverage.
Optional dashboard synchronization sends a versioned, sanitized result—not the OpenAPI source.
Pro and Agent Security access remain separate. The Suite grants exactly three Agent capabilities.
Authenticated checkout intent and signed Stripe webhook completion drive billing records and grants.
Agent credentials can be issued, rotated, and revoked. The raw secret is shown once and not stored in recoverable form.
Speculynx does not prove live IAM, runtime reachability, prompt-injection resistance, absence of vulnerabilities, or safe agent execution. Validate those properties with runtime evidence and human review.
A finding is a signal to verify.
A PASS is scoped to the evaluated contract model and coverage; it is not a production safety guarantee.
Start with a local OpenAPI review, then choose the Agent Security workflow that matches your decision.
Analyze your API