[LG] LogicGuard v0.9-private-beta
SYSTEM STATUS: OPERATIONAL — ACTIVE AST PARSER

Business logic vulnerabilities caught before the pull request merges.

LogicGuard inspects execution graphs across multi-file pull requests to eliminate authorization bypasses, multi-tenant boundary leaks, and IDOR flaws that static linters miss.

Deploy GitHub Action View Sample Security Spec Zero code retention • Nitro enclaves
org/billing-service / PR #214
BLOCKED BY LOGICGUARD
Inspector: logicguard-enclave-worker-04 Scan Duration: 142ms AST Invariants Evaluated: 18,420 nodes
Branch: feat/billing-agg → main
apps/billing-service/src/routes/invoice.controller.ts
Rule: LG-CWE-639-TENANT-ISOLATION
18 export async function getInvoiceRecord(req: Request, res: Response) {
19 // Extract unauthenticated payload parameter
20 const { invoiceId } = req.params;
21
22 - // ❌ CWE-639 / BOLA: Direct lookup without tenant predicate allows cross-tenant exfiltration
23 -   const invoice = await prisma.invoice.findUnique({ where: { id: invoiceId } });
22 + // ✅ LOGICGUARD REPAIR: Scoped query bound to verified JWT tenant context
23 +   const { tenantId } = req.auth; // Enforces strict multi-tenant boundary
24 +   const invoice = await prisma.invoice.findFirstOrThrow({
25 +     where: { id: invoiceId, tenantId: tenantId }
26 +   });
27
28 return res.json(invoice);
29 }
[CWE-639 / BOLA DETECTED] Severity: High (CVSS 8.6)

Generated regression test: tests/security/tenant_isolation_test.py

Automated Fix PR #215 drafted with scoped query patch.

Technical Foundation

Engineered for execution graphs, not regex matching.

Traditional linters evaluate single lines in isolation. LogicGuard builds inter-procedural AST call graphs to trace authorization context across the entire repository.

Multi-File Taint & Flow Analysis

Tracks untrusted request parameters across controllers, service boundaries, and ORM calls rather than isolated single-line regex matches.

Inter-procedural AST • Follows async boundaries & middleware state

Deterministic Test Synthesis

Never fires unvalidated alerts. LogicGuard synthesizes an isolated unit test reproducing the bypass before flagging the PR.

0.0% False Positives • Test executes in ephemeral sandboxes

Automated Remediation PRs

Emits precise, AST-validated pull requests directly into GitHub/GitLab, keeping review velocity high while locking down invariants.

Auto-PR Generation • Context-aware scoped query patches
Detection Engine

Why traditional SAST fails on business logic.

Traditional code scanners look for known vulnerable function signatures (eval(), exec()). Business logic flaws are syntactically valid code that violates semantic security invariants.

Security Invariant / Capability Legacy Linters & SAST LogicGuard AST Engine
Broken Object Level Auth (BOLA / IDOR)
CWE-639 • Accessing resource IDs without tenant checks
Misses cross-file context Blocked via AST Taint Graph
Multi-Tenant Boundary Leaks
CWE-285 • Cross-organization data aggregation or joining
Blind to SQL / ORM scopes Enforces composite tenant predicates
Verification via Test Synthesis
Synthesizing runnable unit tests proving exploitability
Unsupported (heuristic alerts) Generates pytest / Vitest reproducer
Automated Fix Generation
Producing branch-ready pull requests with correct types
Generic regex suggestions Drafts ready-to-merge Fix PR
False Positive Rate
Signal-to-noise ratio in developer pull requests
High (35% – 60% alert fatigue) 0.0% (Gated by synthesized test pass)
Declarative Security As Code

Define security invariants in your repository.

Write rules once in .logicguard/invariants.yaml. LogicGuard compiles them into AST traversal rules that execute across every pull request.

Tracks ORM queries, GraphQL resolvers, and REST endpoints
Enforces session identity invariants on all persistent sinks
Blocks merging automatically when unit test reproducer fires
.logicguard/invariants.yaml
Spec Version: 2026.1
# LogicGuard Invariant Specification v2026.1
version: "2026.1"
enforcement_policy:
  fail_mode: BLOCK_PULL_REQUEST
  synthesize_exploit_test: true
  auto_draft_remediation_pr: true

invariants:
  - id: "INV-TENANT-ISOLATION"
    cwe: "CWE-639"
    description: "ORM queries must bind req.auth.tenantId on multi-tenant entities."
    targets:
      - "prisma.*.findUnique"
      - "prisma.*.findMany"
      - "typeorm.*.findOne"
    taint_rules:
      untrusted_source: "req.params.*"
      required_predicate: "where.tenantId == req.auth.tenantId"
    test_synthesis:
      framework: "pytest"
      mock_tenants: 2
ZERO CODE RETENTION ENCLAVES

Zero Code Retention Policy.

Repositories are processed ephemerally in isolated secure enclaves. Your proprietary source code is never used for training foundation models.

AWS Nitro Enclaves

Ephemeral, memory-only execution environments with cryptographic attestation and zero persistent disk storage.

Zero Model Training

Customer AST trees and source diffs are purged upon scan completion. No weights are modified using private customer code.

Self-Hosted Runners

Deploy the LogicGuard AST daemon inside your own VPC or air-gapped Kubernetes cluster with zero external egress.

SOC 2 Type II Aligned

Enterprise audit-ready controls with mutual TLS 1.3, ephemeral key pairs, and role-based access control.

Quick Integration

Add to your GitHub Actions pipeline in 3 lines.

Runs natively inside your PR check suite. Evaluates the full execution graph before developer review starts.

$ gh extension install logicguard/cli