The product

A security review process your team can keep running.

Dokima orchestrates a structured source-code review across your repositories. It owns the context, schedule, quality gates and report. Your chosen AI runner handles each bounded analysis task.

Starts with understanding

The review learns how your software is put together.

A useful security finding depends on more than the line where a problem appears. Dokima first records the shape of the system and the assumptions the code relies on.

01

Repository map

Detect repositories and linked worktrees inside the workspace.

02

Component model

Identify components, responsibilities and important paths through the code.

03

Attack surface

Record exposed interfaces, trust boundaries and security-sensitive flows.

04

Security assumptions

Capture what must remain true for each component to behave safely.

A bounded lifecycle

Each stage has one job.

Dokima separates discovery, challenge, validation and explanation. This keeps the process inspectable and makes it harder for an attractive first answer to become an untested finding.

  1. 01

    Understand

    Map repositories, components, trust boundaries and security assumptions so later work starts with context.

  2. 02

    Plan

    Choose focused review work for each component rather than spending the same effort everywhere.

  3. 03

    Hunt

    Apply specialised security lenses and record candidates with evidence tied back to the source.

  4. 04

    Challenge

    Peer-review candidates, ask for missing information and separate plausible issues from weak ones.

  5. 05

    Validate

    Check impact, scope and evidence; normalise and deduplicate the findings that remain.

  6. 06

    Explain

    Add a plain-English description, detailed remediation and a report developers can work through.

  7. 07

    Continue

    Schedule later passes, revisit assumptions and review changed code without discarding the project history.

Review the review

Findings are challenged before they are presented.

Candidate findings can be peer-reviewed, sent back for more information, validated by severity and deduplicated against overlapping work. Dokima records accepted and rejected runs so the schedule only advances on structured output that passes its checks.

The final report separates confidence from severity and keeps verification reasoning beside the issue. Developers can mark accepted risk, mitigation, false positives, duplicates or items needing human review without rewriting the original evidence.

Choose the right depth

Run the part of the review you need.

Architecture review

Understand the system and revisit its assumptions.

Vulnerability hunting

Plan and run focused searches for new security issues.

Finding review

Clean up, validate, expand and report existing findings.

Full sweep

Run the complete lifecycle across due work.

Local control

CLI when you need it. Dashboard when you want the whole picture.

Open the terminal dashboard with dokima, run a single step, complete the next stage or let a full sweep progress through the workspace. The scheduler records its state in .dokima/ and produces a static HTML report you can open locally.

See how setup works

See what Dokima finds

Put an AI security reviewer to work on your codebase.

Request a full-product trial for your engineering team. No payment card required.