How CoreDhristi protects your code and your business once an agent goes live
An honest answer, not a marketing promise: no marketplace has fully solved code security, not Adobe, not Autodesk, not us. Here is exactly what CoreDhristi does, why it works that way, and where the real limits are.
CoreDhristi's model has a developer's code running on the company that hires it, on that company's own infrastructure. That's a deliberate choice: your data never has to leave your servers to use an agent. It also means the code physically reaches that server, and no platform can honestly promise that code reaching someone else's machine can never be copied. What CoreDhristi can promise is a real, layered set of deterrents and traceability for developer protection, built the way any serious software vendor approaches anti-piracy, plus total honesty about what those protections do and don't guarantee.
What protects your code
License fingerprinting
Every install carries a disclosed, unique identifier tied to its license. If a copy ever turns up outside its licensed deployment, it traces straight back to the account it was issued to.
Code obfuscation
JavaScript/TypeScript agent code is automatically scrambled before delivery, raising the bar for anyone trying to read or strip it down. Support for more languages is being added over time.
A real Terms clause, not just a norm
Every company that licenses an agent agrees to CoreDhristi's Terms of Service, which explicitly prohibits redistribution or use beyond the licensed deployment. A breach can mean account suspension, license revocation, and legal action.
7-layer security review
Every listed agent runs through the same automated layers below, including automated penetration testing, before it can be hired, so what you run on your own infrastructure has already been checked for secrets, vulnerabilities, and unsafe behaviour.
The 7-layer review, on every listing
Fully automated AI security testing runs on every listing before an admin reviews and approves it - no skipping the automated scans, no exceptions. Layers 1 to 5 gate approval today; layers 6 and 7 run and are recorded on the listing, and do not block it yet.
Secret scanning
Betterleaks reads the full repository history for hardcoded API keys, tokens, and passwords, so no credential ships hidden inside an agent.
Static analysis
Semgrep and CodeQL inspect the source for injection vectors, unsafe calls, and the kind of security flaws that never show up at runtime.
Dependency and supply chain
OSV-Scanner checks every package the agent depends on against known-vulnerability databases, across JavaScript, Python and more, so a clean agent cannot be undermined by a compromised library.
QA and functionality
The agent is installed and built in an isolated container, and its own test suite is run, to confirm it actually works before anyone can hire it.
Attack simulation
Promptfoo runs simulated attacks across dozens of vulnerability categories, probing how the agent behaves under adversarial input, entirely automated.
Workflow and MCP verification
Agentic Radar traces what an n8n or framework-based automation actually does, and MCP Inspector connects to an MCP server and lists the tools it really exposes. Each runs on the listing types it applies to.
Data claims and SBOM
Presidio cross-checks how the code handles personal data against what the developer declared, and Syft publishes a full software bill of materials for what you are about to run.
What we will not claim
We won't tell you an agent's code is impossible to copy once it's running on your own server. Nobody can promise that honestly, not for software that has to run on infrastructure it doesn't control. Adobe and Autodesk spend far more on anti-piracy than a marketplace at our stage ever will, and their products still get copied. Anti-tamper protection is, industry-wide, a moving target: not a lock that closes once, but something that keeps improving as the tools available to everyone, including attackers, get better.
What we do claim: every install is traceable, every license carries real Terms with real consequences, obfuscation raises the real cost of copying, and we keep investing in raising that bar. It's not a one-time feature we shipped and forgot about. We don't publish a public engineering roadmap, so email support@coredhristi.com directly if you want specifics on what's coming next, before you list or license an agent.