CLI reference
30 commands across 5 categories. Install with npm i -g @tar_9897/certus-ai
Quick start
$ npm install -g @tar_9897/certus-ai
$ certus init
$ certus login
$ certus scan
# View results in the dashboard
$ certus dashboard
Scanners
All 5 scanners run in parallel via Promise.allSettled. Results are aggregated into a single evidence pack.
Test coverage
Analyzes test runner output for coverage metrics
Jest, Vitest, pytest, Go test
SAST
Static analysis for security vulnerabilities
Semgrep rules, custom patterns
SBOM
Software bill of materials generation and analysis
SPDX, CycloneDX, SLSA provenance
IaC
Infrastructure-as-code compliance checking
Terraform, CloudFormation, Kubernetes
Secrets
Secret and credential detection
Regex patterns, entropy analysis
Core
scanRun all 5 scanners, compute grade, sign evidence pack, optionally sync to APIcertus scan [--format json|table] [--no-sync]
verifyVerify an existing evidence pack signaturecertus verify <pack-id>
initInitialize Certus in the current repositorycertus init
riskCompute risk score for the current repositorycertus risk
fixAuto-fix findings using the fixer registrycertus fix [--dry-run]
Configuration
configView or set configuration valuescertus config [key] [value]
loginAuthenticate with the Certus platformcertus login
statusShow authentication and workspace statuscertus status [--workspace]
pingTest connectivity to the Certus APIcertus ping
Compliance
evidenceGenerate and manage evidence packscertus evidence [--framework soc-2|hipaa|pci]
blueprintRun compliance blueprints against the repositorycertus blueprint [slug]
policyEvaluate and enforce policy rulescertus policy [--strict]
auditGenerate audit-ready reportscertus audit [--format html|json]
attestCreate a signed attestation for a frameworkcertus attest --framework <name>
Analysis
runbackRe-run historical scans for trend analysiscertus runback [--count N]
historyView scan history for the current repositorycertus history [--limit N]
dashboardOpen the web dashboardcertus dashboard
compareCompare two scan resultscertus compare <run1> <run2>
driftDetect compliance drift between runscertus drift
benchmarkBenchmark repository against industry standardscertus benchmark
explainExplain a finding or control mappingcertus explain <finding-id>
costEstimate remediation cost for open findingscertus cost
exportExport evidence in multiple formatscertus export [--format json|pdf|sbom]
Diagnostics
doctorCheck system dependencies and configurationcertus doctor
logsView recent CLI logscertus logs [--tail N]
diagnosticsGenerate a diagnostic bundle for supportcertus diagnostics