Repository map
Detect repositories and linked worktrees inside the workspace.
The product
Dokima orchestrates a structured source-code review across your repositories. It owns the context, schedule, quality gates and report. Your chosen AI runner handles each bounded analysis task.
Starts with understanding
A useful security finding depends on more than the line where a problem appears. Dokima first records the shape of the system and the assumptions the code relies on.
Detect repositories and linked worktrees inside the workspace.
Identify components, responsibilities and important paths through the code.
Record exposed interfaces, trust boundaries and security-sensitive flows.
Capture what must remain true for each component to behave safely.
A bounded lifecycle
Dokima separates discovery, challenge, validation and explanation. This keeps the process inspectable and makes it harder for an attractive first answer to become an untested finding.
Map repositories, components, trust boundaries and security assumptions so later work starts with context.
Choose focused review work for each component rather than spending the same effort everywhere.
Apply specialised security lenses and record candidates with evidence tied back to the source.
Peer-review candidates, ask for missing information and separate plausible issues from weak ones.
Check impact, scope and evidence; normalise and deduplicate the findings that remain.
Add a plain-English description, detailed remediation and a report developers can work through.
Schedule later passes, revisit assumptions and review changed code without discarding the project history.
Review the review
Candidate findings can be peer-reviewed, sent back for more information, validated by severity and deduplicated against overlapping work. Dokima records accepted and rejected runs so the schedule only advances on structured output that passes its checks.
The final report separates confidence from severity and keeps verification reasoning beside the issue. Developers can mark accepted risk, mitigation, false positives, duplicates or items needing human review without rewriting the original evidence.
Choose the right depth
Local control
Open the terminal dashboard with dokima, run a single step, complete the next stage or let a full sweep progress through the workspace. The scheduler records its state in .dokima/ and produces a static HTML report you can open locally.
See what Dokima finds
Request a full-product trial for your engineering team. No payment card required.