Research

Choosing a model

A guide helping you find the model that's right for you.

Quick Recommendation

Choose Minisøk when you want vulnerability identification only. It reports findings, but it does not provide solutions or return solution code.

Choose Vakttårn when you want vulnerability identification and suggested solutions in the same scan. It can return code when a solution is available.

Model Fit

For fast report-only scans, choose Minisøk. It focuses on identification without generating solutions.

For CI or audit output that another team will review, choose Minisøk. It keeps the output narrow and easy to review.

For interactive review with suggested code changes, choose Vakttårn. It finds vulnerabilities and proposes solutions.

For JSONL pipelines that may auto-apply code changes, choose Vakttårn. It can include solution code for supported findings.

If you are unsure which model to start with, choose Vakttårn unless you explicitly do not want solutions.

Vaktex Vulnerability Detection

ModelIdentificationSolutions
Vakttårn69.16%76.82%
Minisøk59.26%-
GPT-5.546.30%34.63%
Snyk44.44%-

OWASP Java

ModelIdentificationSolutions
Vakttårn80.44%63.70%
GPT-5.580.00%74.59%
Minisøk72.15%-
Snyk70.44%-

How to Read the Benchmarks

Identification measures whether a model finds the vulnerable code. Solutions measure whether a model returns useful code. A dash means that model does not provide a solution result in that workflow.

The Vaktex Vulnerability Detection benchmark is a private corpus of vulnerable and secure code with more than 1,000 files across 20 different languages. That breadth gives a more accurate impression of how a model will perform in the real world than a narrow single-language test set. Against the industry-standard scanner baseline listed here, Vakttårn finds far more vulnerabilities and is the only listed model with a strong solution score. Minisøk also clears the scanner baseline by a wide margin while staying focused on identification only.

The OWASP Java benchmark is a public benchmark on a well documented language, which makes the spread tighter. That is what makes the result impressive: Vakttårn still leads identification. GPT-5.5 leads solutions on this benchmark, but it is also more than 100x the size of the Vaktex models. Vakttårn staying this close while remaining much smaller makes it the stronger one-pass choice when you want both findings and solutions.

Workflow Guidance

Use Minisøk when the scan is part of discovery, audit, compliance review, or human-led triage. It keeps the output focused on what was found.

Use Vakttårn when the next step is code change. Its suggestions still need review and tests, but it gives developers and coding agents a concrete starting point.

For auto-apply workflows, use Vakttårn and review the resulting diff before merging. Minisøk is not appropriate for auto-apply because it does not produce solutions.

Improve team velocity with
better security and privacy.