Introduction¶
Trilocore is a smart-contract security platform. The Contract IDE, the
Architecture Explorer and the Auditing IDE are the three workbench
surfaces. They share one foundation: the fork environments the work runs on and
the analysis engine that reads the bytecode. Janus AI is in development and not
yet available. All three surfaces live in one application at
app.trilocore.ai, and all are driven by one public API at api.trilocore.ai.
The work is done against a fork — a private copy of a real chain, pinned to a block. You can send transactions, rewrite storage, and replay a sequence as many times as you like; nothing you do touches the live chain.
-
Quickstart¶
Open a fork of mainnet and send your first transaction against it, from the command line, in three requests.
-
Core concepts¶
Sessions, forks, executions, findings and severity, workspaces and projects, and the attestations that make a report checkable.
-
Contract IDE¶
Git-native workspaces, Solidity and Vyper compilation, merge requests, annotations and GitHub publishing.
-
Architecture Explorer¶
Who can change what: the protocol's authority map, read from the actual authority slots on a fork rather than from the documentation.
-
Auditing IDE¶
The security-review surface: Composer, MorphVM, and the rest of the panel set, all against a fork you control.
-
API¶
Base URL, authentication, idempotency, errors and rate limits — then the per-endpoint reference.
-
Audit reports¶
Published reports, each with its severity breakdown and verdict.
What you can do¶
| Goal | Where it happens | Start here |
|---|---|---|
| Reproduce a suspected bug against real mainnet state | Auditing IDE — Composer, on a forked session | Quickstart |
| Sweep a contract's bytecode for known-bad patterns | Auditing IDE — Passive and Findings | Auditing IDE |
| See who can change what in a protocol | Architecture Explorer | Architecture Explorer |
| Write and compile a contract, then review it | Contract IDE | Contract IDE |
| Publish a workspace to GitHub with its full history | Contract IDE | Contract IDE |
| Record findings against a project and issue a report | Workspaces and audits | Core concepts |
| Let a third party verify a report you issued | Public attestation verification | Core concepts |
| Automate any of the above | The api.trilocore.ai resource API |
API overview |
How the surfaces relate¶
A workspace is the tenancy boundary: it owns projects, a contract inventory, audits, findings and reports. The workbench surfaces file their work into it, which is what makes an audit reconstructable months later — an execution in the Auditing IDE and a merge request in the Contract IDE end up in the same activity trail, and an architecture can be attached to the same workspace and project when you create it.
Everything the application does, it does through the same public API. There is no private surface behind the app: the endpoints in the reference are the ones the product itself calls.
Not in the current release
AI-assisted analysis is in development and is not part of the current release. Nothing in these pages depends on it. Where a page describes something that is planned rather than shipped, it says so explicitly.