Your product finds vulnerable code. Does it find malicious code?

CVE scanners ask one question: is this known to be vulnerable? Almost nothing asks the other: was it written to do harm? atomdrift does, from the artifact itself — source, binaries, firmware, containers, packages — at scan time, on your infrastructure. isotope¹³ makes it shippable: OEM rights, rules the hour they clear QA, and the people who wrote it on the other end of the email.

67%
zero-day malware caught
0%
false positives

Measured 2026-09-22 against VirusTotal, Socket, ClamAV and 4 others on 3 live samples, median 19 hours old. Next best engine: 33%. A fresh cohort every day. Every sample published in the lab.

atomdrift.org/compare →

A detection engine for the product you already ship.

Not a dashboard. Not another vendor between you and your customer. A component, with the license and the support to put it in production.

SAST and SCA platforms

Your customers now ask whether you catch malicious packages. Add the answer without hiring a malware team. It runs inside your CI integration, so no customer code leaves their environment, and every verdict carries the capabilities that drove it. A false positive becomes a ticket you can answer.

Hardened images and rebuilt libraries

Provenance proves who built it, not that upstream was clean. Scan every release at ingest and diff it against the last one. xz-utils was a 5.4.5 to 5.6.0 diff. Deterministic verdicts, pinned rule and model versions, batch throughput on your own hardware.

Distributions and registries

Every tarball you ingest was written by a stranger. Gate the build on a verdict, on-prem, under an OSI license you can ship. Fixes go upstream. There is no private fork to depend on.

Firmware and binary analysis

No source, no problem. Capability extraction across ELF, PE, Mach-O and packed binaries, string recovery that survives XOR and Go layouts, and a classifier per file type. Embed it as Rust libraries.

A verdict at scan time, wherever your code is.

Deterministic and reproducible.

Same bytes, same rules, same model: same verdict. Pin tool, rule and model versions so a scan from last quarter can be reproduced today.

Explainable to the byte.

A hostile verdict names the rule, file, byte offset, source line and behavior that caused it. You ship verdicts to your customers; you need to defend them.

Runs where you choose.

In-process or air-gapped on your infrastructure, with no egress. Or Beamline, our hosted API, when one HTTP call is easier. Same engine, same verdicts, move between them at will.

Maintained daily, with someone on the hook.

New samples, threat feeds and published research become roughly 1,000 rule updates a day, every one validated before it ships. Support from the engineers who wrote it.

Two products. Nothing more.

Enriched Subscription

Rules the hour they clear QA, the Beamline hosted API, and support from the engineers who build the tools. Business $499/mo. OEM $2,499/mo to ship the hourly rules inside your product. Your rate stays fixed while you subscribe.

Learn more →

Services Contract

We embed Scan, Isomer or Cleave into your product, or assess the supply chain you already run. Fixed scope, quoted up front. The report says what is wrong and how to fix it.

Learn more →

Open source, permanently.

Revenue from these two products pays the engineers building Scan, Isomer and Cleave. The software stays free whatever happens to the company. That is the point: you are embedding a project, not renting a feature.

See our projects →
  • Scan, Isomer and Cleave stay open source
  • If isotope¹³ closes, everything ships under a permissive license
  • OSI-approved licenses only; community work is never relicensed
  • Fixes go upstream; no private forks
  • Open formats; your data stays yours

One email. No deck.

Tell us what you are running and what you want it to catch.