Research
Vakttårn
A vulnerability-identification and solution model for scans that need resolution.
Overview
Vakttårn is the Vaktex model for end-to-end vulnerability work: find the issue, classify it, and return a suggested solution. It is the default choice when the output should be actionable inside a codebase rather than limited to a report.
Use Vakttårn when you want scan results that can feed interactive review, JSONL pipelines, or auto-apply workflows. Compared with Minisøk, Vakttårn does the extra work of producing solutions.
Benchmarks
Vaktex Vulnerability Detection
| Model | Identification | Solutions |
|---|---|---|
| Vakttårn | 69.16% | 76.82% |
| Minisøk | 59.26% | - |
| GPT-5.5 | 46.30% | 34.63% |
| Snyk | 44.44% | - |
OWASP Java
| Model | Identification | Solutions |
|---|---|---|
| Vakttårn | 80.44% | 63.70% |
| GPT-5.5 | 80.00% | 74.59% |
| Minisøk | 72.15% | - |
| Snyk | 70.44% | - |
How to Read the Benchmarks
Identification measures whether a model finds the vulnerable code. Solutions measure whether a model returns useful code. A dash means that model does not provide a solution result in that workflow.
The Vaktex Vulnerability Detection benchmark is a private corpus of vulnerable and secure code with more than 1,000 files across 20 different languages. That breadth gives a more accurate impression of how a model will perform in the real world than a narrow single-language test set. Against the industry-standard scanner baseline listed here, Vakttårn finds far more vulnerabilities and is the only listed model with a strong solution score.
The OWASP Java benchmark is a public benchmark on a well documented language, which makes the spread tighter. That is what makes the result impressive: Vakttårn still leads identification. GPT-5.5 leads solutions on this benchmark, but it is also more than 100x the size of the Vaktex models. Vakttårn staying this close while remaining much smaller makes it the stronger one-pass choice when you want both findings and solutions.
Capabilities
- Identifies likely vulnerabilities in application code
- Generates suggested solutions for supported findings
- Returns solution code in JSONL output when available
- Supports interactive review and non-interactive pipelines where solutions need to be inspected or applied
Limitations
Vakttårn suggestions should be reviewed like any security-sensitive code change. Generated solutions may need adaptation for project conventions, surrounding architecture, or tests that were not visible during the scan.
Solution scores vary by benchmark. On OWASP Java, Vakttårn leads identification in the listed results, while GPT-5.5 has the highest solution score. On the Vaktex Vulnerability Detection benchmark, Vakttårn leads both identification and solutions among the listed models.
Recommended Use
Choose Vakttårn when you want findings and solutions in one pass.
Choose Minisøk when you only need vulnerability identification and do not want generated solutions.