STATIC

Suresofttech Source Code Static Analysis Tool

STATIC from Suresofttech is a static analysis tool that detects coding rule violations, runtime errors, and potential security vulnerabilities without executing the source code. It also provides domain-specific coding rule sets and software quality metrics.

STATIC overview

  • C/C++, C#, Java, Kotlin, PythonSupported languages: Enterprise (EE)

    Standalone (SE): C/C++

  • 1,200+Inspection patterns¹

    Figures are based on Enterprise. The supported scope varies by edition, language, and product version, so the detailed applicable scope must be confirmed against your own environment.

  • IAR · Keil · TASKING · Renesas · TI · Microchip and moreSupported toolchains
  • approx. 30 in EE · approx. 20 in SESoftware quality metrics
Project static analysis status listcompare and manage the analysis status and defect indicators of multiple projects on one screen
Defect review and assignee managementcheck detected rule violations together with their source location and track status and assignee

Why static analysis is needed

A successful compile does not mean there will be no defects at runtime.

  • Defects the compiler cannot catch

    memory leaks, NULL dereferences, and array-bound overruns pass compilation and survive into execution.

  • The later you find it, the more it costs

    finding these through testing requires reproducing the execution conditions that trigger the error, which delays discovery.

  • Rule compliance required by standards

    safety-critical domains such as automotive, defense, and aerospace require compliance with different coding rules depending on the applicable standards and project guidelines.

  • Many defects, no management

    if there is no record of who fixed what and when, detection alone does not improve quality.

What Is Static Analysis?

Static analysis is a technique for detecting errors and potential security vulnerabilities by analyzing the source code itself without executing it. Because it can identify defects that would cause system failures or reduced reliability before the program runs, it is used in most software development today.

Unlike dynamic analysis, which measures execution rates from the results of running the code, static analysis inspects the code itself and can therefore find defects even without test cases. The two approaches complement rather than replace each other.

Static analysis is an activity for finding defects before execution; it does not replace testing (dynamic verification). The actual impact of a detected defect depends on the code context, so a review process is required.

The core value STATIC delivers

STATIC does not stop at detection — it manages defects through remediation and tracking.

  • Runtime error detection without execution

    the STATIC analysis engine uses more than 1,200 inspection patterns and more than 30 kinds of semantic analysis to find memory, arithmetic, and array-bound errors before the code is ever run.

  • Automatic checking against domain rule sets

    STATIC automatically checks coding rules such as MISRA, CERT, and AUTOSAR, CWE-based security weaknesses, and DAPA guideline items.

  • AI-assisted assessment and Q&A

    Smart Suggestion finds and recommends similar suppression history, and STATIC Agent Chat answers questions about tool usage and defects based on the guide documentation.

  • Built for large codebases

    Enterprise analyzes codebases of several million lines, and after the first analysis it shortens the cycle with incremental analysis and APU Grid distributed analysis.²

  • Defect tracking and management

    Enterprise tracks status changes through the defect life cycle and history, and manages quality trends with the rule compliance rate (RCR) and defect density.

² In a measurement example configured with a dedicated APU server, roughly 300 C++ source files were analyzed in under a minute. Actual analysis time varies with code size, rule set, and hardware configuration.

STATIC Enterprise and Standalone

STATIC is offered in two configurations: centrally managed and developer IDE based.

STATIC Enterprise (STATIC EE) manages the defects of multiple developers and projects in a centrally managed web server environment, while STATIC Standalone (STATIC SE) lets you review and fix violations on a single screen in a VS Code based standalone IDE.

Comparison itemSTATIC EnterpriseSTATIC Standalone
One-line definitionOrganization-wide code quality management platformIDE-integrated static analysis tool for developers
Supported languagesC/C++, C#, Java, Kotlin, PythonC/C++
CompositionWeb server (WAS) + analysis agent (APU) + web UIVS Code based IDE, installed locally
Defect managementCentral dashboard, status and assignee management, trend tracking, objective settingLocal filters and status management, review and fix on one screen
Analysis methodServer-side analysis, APU Grid distributed analysis, incremental analysisLocal analysis, automatic extraction of analysis information per development environment
AI featuresSmart Suggestion, STATIC Agent ChatContact us separately
EnvironmentServer and analysis agents operated on the internal networkInstalled on a local PC, dongle license supported

When to choose STATIC Enterprise

  • When defects from multiple developers must be assigned and tracked centrally
  • When project quality trends and objective attainment must be managed
  • When languages other than C/C++, such as Java, C#, Kotlin, and Python, must be analyzed
  • When integration with CI, configuration management, and in-house quality systems is required

When to choose STATIC Standalone

  • When developers need to review and fix violations immediately in the environment where they write code
  • When server access is difficult, such as at a customer site or on an air-gapped network
  • When embedded C/C++ must be analyzed per development PC without server infrastructure

Key features

Coding Rule Checking

STATIC automatically checks the coding rules that must be observed in each domain.

  • Provides coding rule sets such as MISRA C/C++, AUTOSAR C++14, and CERT, CWE-based security weaknesses, and rule sets aligned with DAPA, HKMC, and Ministry of the Interior and Safety guidelines.
  • You can build a rule set from only the rules your project needs, create custom rule sets, and import rule sets from other projects.
  • The rule manual provides a description of each rule together with violating (Bad) and compliant (Good) code examples.

Runtime Error Detection

STATIC detects errors that occur at execution time without running the code.

  • Memory errors

    invalid memory access, memory leaks, NULL dereferences, invalid memory deallocation

  • Arithmetic errors

    errors in complex arithmetic operations, incorrect operations caused by type conversions the user is unaware of

  • Array-bound errors

    errors directly tied to security vulnerabilities, such as buffer overflow and buffer underflow

The STATIC Enterprise analysis engine performs more than 1,200 pattern checks and more than 30 kinds of semantic analysis. C/C++ defects are provided with severity and confidence grades. The scope of defect information differs by language — for example, confidence is not provided for Java, C#, Kotlin, and Python.

Software Quality Metrics

STATIC quantifies the size and complexity of code as metrics.

  • Enterprise provides approximately 30 metrics at the module, file, class, and function levels, with supported items differing by language. These include Cyclomatic Complexity (FUCYC), Modified Cyclomatic Complexity (FUMCYC), maximum nesting depth (FUMNC), Myer's Interval (FUMIV), and MC/DC case count (FUNDM).
  • Standalone provides module-, file-, and function-level metrics for C/C++ plus approximately 20 additional metrics.
  • The six function metrics specified in the Weapon System Software Development and Management Manual are supported.
  • In Enterprise you can divide each metric into stages and set thresholds, so that items exceeding the criteria are flagged with a warning.
  • In Enterprise you can configure specific metric violations to be ignored and export the suppression history as a report.

Defect Management and Objective Tracking

Enterprise tracks defect status from discovery through completed remediation and manages project quality objectives centrally. Standalone provides filter and status management features in the local environment.

  • Defect life cycle and history

    manage defect status stage by stage and track the change history. Each defect is given a unique URL so recurrences of the same defect can be identified.

  • Filters and bulk changes

    search by combining severity, confidence, assignee, file, rule, function, and label, and save frequently used conditions as filters. The status or assignee of selected defects can be changed in bulk.

  • Suppression (ignoring defects)

    manage defects in a Suppressed state with a specified reason such as intended code, false positive, or duplicate.

  • Baseline (Enterprise)

    set a reference point and analyze; defects from earlier analyses are excluded from the managed set so you can focus on defects introduced after the reference point.

  • Objective setting

    set a target for remaining defects by severity along with a period, and track attainment with a burndown chart.

  • Quality indicators

    check the rule compliance rate (RCR), defect density, number of analyzed files, and lines of code per project.

Defect management and objective trackingview defect trends per configuration, the change versus the previous configuration, and actual reduction against the target on one screen

Remediation Support

STATIC provides features that help you understand the cause of a defect and decide how to fix it.

AI features

  • STATIC Agent Chat

    an AI Q&A service that answers questions about tool usage, project information, and defect causes and remediation guidance based on the STATIC guide documentation.

  • Smart Suggestion

    AI finds and recommends past suppression records similar to the current defect. You can compare the original defect code with the recommended suppression record code in a diff view and then accept or reject it, and you can set the reference scope to the current project or to all projects your account can access.

STATIC Agent Chatexplains the cause of a defect, how to fix it, and code examples based on the relevant guide

Remediation history based features

  • Fix Reference

    provides data that helps with remediation, such as code that actually fixed the defect. You can move to the previous or next entry to review them and vote for entries that were helpful.

Analysis Automation and Integration

STATIC integrates into the development pipeline to run static analysis automatically.

Integration targetDescriptionEdition
CI (Jenkins and others)Runs static analysis automatically during the build to enforce analysis from development through deploymentEE·SE
Incremental analysisAnalyzes only the changed portions after the initial full analysis to shorten the cycleEE
APU Grid distributed analysisUses the resources of multiple analysis agents to shorten analysis time on large projectsEE
Open APIFeeds analysis results and quality indicators into in-house systems. An access key is issued from the user profileEE
Configuration management (Git and others)Automatically assigns defects to the responsible developer based on commit informationEE
VPESIntegrates analysis results with the build and test automation toolEE·SE
V-SPICELinks with the process reporting automation toolEE
STATIC SE → EEUploads results analyzed in Standalone to Enterprise for consolidated managementSE→EE

Supported languages

C/C++ combined language tag supported by STATIC C# language tag supported by STATIC Java language tag supported by STATIC Kotlin language tag supported by STATIC Python language tag supported by STATIC

STATIC Enterprise supports C/C++, C#, Java, Kotlin, and Python.

STATIC Standalone supports C/C++.

Coding rules and industry standards

STATIC checks coding rules and domestic domain guidelines as rule sets, and supports the use of static analysis results as verification evidence when responding to safety standards.

CategoryStandard / guidelineSTATIC support scope
International coding rulesMISRA C/C++, AUTOSAR C++14, CERT Secure Coding, JSFCoding rule violation checks. Supported rules and detection scope vary by language, edition, and version
Security weakness classificationCWEChecks for security weaknesses mapped to CWE IDs. Supported items vary by language, edition, and version
Korean automotive guidelinesES95489-23, HKMC verification guidelinesEE: 100% of the ES95489-23 C, C++, and Java rule sets, 60 HKMC grade A/B/SE items. SE: 100% of the ES95489-23 C and C++ rule sets, 48 HKMC grade A/B items
Korean defense guidelinesDAPA Software Reliability Assessment Guidelines (CWE 658/659/660)92 items supported for C/C++. EE additionally supports 65 Java items; further supported scope may vary by product version
Korean security guidelinesMinistry of the Interior and Safety secure coding guideChecks secure coding rules and security weaknesses
Quality rulesNaming and coding style guidelinesChecks naming conventions and coding style
Fields applying safety and life cycle standardsISO 26262, DO-178C, IEC 61508, IEC 62279·EN 50128, IEC 62304, IEC 60880Coding rule checks and static analysis results can be used as verification evidence when responding to the standard. Required deliverables and applicable scope per project must be confirmed separately

Tool qualification materials — tool qualification materials for certification audits are provided. The materials actually supplied, the applicable product versions, and the standard scope must be confirmed on a per-project basis.

Use cases

Automotive parts manufacturer

preventing recurring errors with custom coding rules

Problem
an engine design project (C language) needed custom rules to prevent the recurrence of errors that had actually occurred
Application
analyzed the errors that occurred, developed and applied custom coding rules, and included a rule verification step in the development process
Result
used in the verification process for ISO 26262 compliance

Semiconductor manufacturer

MISRA rules integrated with build automation

Problem
development proceeded without a dedicated static analysis tool, producing variation in code quality
Application
applied MISRA coding rules and integrated with the build automation server so that analysis runs on every build
Result
used in the verification process for IEC 61508 compliance and established a software quality management system

Defense system developer

reliability verification of embedded weapon system software

Problem
the console GUI software of a guided weapon launch control unit had to satisfy software reliability test requirements
Application
detected and fixed defects through runtime error detection and rule checks based on the Software Reliability Assessment Guidelines
Result
met the software reliability test criteria and the acceptance criteria of the ordering company

Frequently asked questions

What is STATIC?

STATIC from Suresofttech (SURESOFTTECH) is a static analysis tool that analyzes source code without executing it to detect coding rule violations and runtime errors. Following coding guidelines, it finds critical errors and potential security holes in the source code, catching defects early in development that the compiler does not report. It supports coding rules such as MISRA and CERT and CWE-based security weakness checks, and its static analysis results can be used as verification evidence when responding to safety standards such as ISO 26262 and IEC 61508. It comes in two forms: STATIC Enterprise, a centrally managed web server environment, and STATIC Standalone, a VS Code based IDE.

What kinds of defects can STATIC detect?

STATIC checks three types of issues. First, it checks coding rule violations such as MISRA, CERT, and AUTOSAR, and security weaknesses mapped to CWE IDs. Second, it detects runtime errors without running the code, including memory errors (invalid access, memory leaks, NULL dereferences, invalid deallocation), arithmetic errors (complex operations, unnoticed type conversions), and array-bound errors (buffer overflow and underflow). Third, it checks violations of software quality metric thresholds such as cyclomatic complexity and nesting depth. C/C++ defects are provided with severity, confidence, and the source code location. Confidence is not provided for Java, C#, Kotlin, and Python, and some other provided items such as function information also differ from C/C++.

What is the difference between STATIC Enterprise and STATIC Standalone?

STATIC Enterprise is a centrally managed web server environment that assigns and tracks the defects of multiple developers and projects from a dashboard and supports five languages: C/C++, C#, Java, Kotlin, and Python. It provides project objective setting and burndown charts, APU Grid distributed analysis, an Open API, and configuration management integration. STATIC Standalone is a VS Code based standalone IDE that supports C/C++ and lets developers review and fix violations on a single screen in the environment where they write code. It supports local installation and dongle licensing, so it can be used at customer sites or on air-gapped networks. Enterprise is recommended when organization-wide quality management is needed, and Standalone when the goal is immediate review and remediation by an individual developer.

Which programming languages and compilers are supported?

STATIC Enterprise supports C/C++, C#, Java, Kotlin, and Python, and STATIC Standalone supports C/C++. Analysis requests reuse your existing build environment: Visual Studio and Makefile for C/C++, Visual Studio solution and project files for C#, and Maven and Gradle for Java and Kotlin. Compiler support is identical in Enterprise and Standalone, with built-in toolchain configurations for IAR, Keil uVision, TASKING (AURIX), Renesas CS+, TI Code Composer Studio, Microchip Studio and MPLAB X IDE, STM32CubeIDE, Xilinx Vitis Unified, MCUXpresso IDE, Code Warrior, GNU, LLVM, and Visual Studio. Compilers not on the list can be configured in Manual Mode; applicability is determined after reviewing the compiler specification and the project environment.

Does it support MISRA C/C++ checking?

Yes, STATIC supports MISRA C and MISRA C++ coding rule checking. It provides MISRA C/C++ rule sets including MISRA C 2004, 2012, 2023, and 2025, as well as AUTOSAR C++14. You can build a rule set from only the rules your project needs, create custom rule sets, and import rule sets from other projects. The rule manual provides a description of each rule together with violating (Bad) and compliant (Good) code examples, so you can make fixes with a clear understanding of the intent behind the rule. The supported MISRA editions and the detection scope per rule vary by edition and product version, so they should be confirmed before adoption. The full list of supported rule sets is available in Coding Rules and Industry Standards.

How can runtime errors be found without executing the code?

STATIC traces the execution paths and data flow of the source code through semantic analysis to identify, at the code level, conditions under which an error could occur at runtime. For example, it tracks the value range of a variable used as an array index to determine whether it could go out of bounds, and it checks whether allocated memory is released on all paths. The Enterprise analysis engine performs more than 1,200 pattern checks and more than 30 kinds of semantic analysis. That said, static analysis is a prediction made before execution, so the actual impact must be reviewed in the context of the code; confidence is provided for C/C++ and is not provided for Java, C#, Kotlin, or Python.

How are false positives managed?

STATIC provides several mechanisms for managing false positives. C/C++ defects are labeled with a confidence grade, and defects can be managed in a Suppressed state with a specified reason such as intended code, false positive, or duplicate. Project members can leave comments on a defect and review it together. Smart Suggestion in Enterprise recommends past suppression records similar to the current defect and lets you compare the original defect with the recommended case before accepting or rejecting it.

We have a lot of legacy code — can we manage only newly written code?

Yes, this is possible with the Baseline feature in Enterprise. Once you set a reference point and run an analysis, defects from earlier analyses are excluded from the managed set so you can focus on defects introduced after the reference point. This avoids a situation where existing defects in legacy code fill the list and bury problems in new code. Baseline can be turned off in the project settings, so once you have capacity you can bring all defects back into the managed set. Used together with the project objective feature, you can set a target for remaining defects by severity along with a period and track reduction progress with a burndown chart — allowing you to prioritize the quality of new code while reducing legacy defects in stages. The related features are described in Defect Management and Objective Tracking.

Can it be used for compliance with safety standards such as ISO 26262 and DO-178C?

Yes, the coding rule checks and static analysis results from STATIC can be used as verification evidence in the process of responding to safety standards. In projects applying safety and life cycle standards such as ISO 26262, DO-178C, IEC 61508, IEC 62279·EN 50128, IEC 62304, and IEC 60880, coding rule compliance and runtime error detection results can be retained as deliverables. STATIC provides the coding rule sets that these standards require, including MISRA C/C++, AUTOSAR C++14, and CERT, and detection results are tracked as defect information including the source location and severity. For C/C++, confidence is provided as well. Tool qualification materials for certification audits are available, and the supported scope per standard is summarized in Coding Rules and Industry Standards.

Can it be installed in an air-gapped (network-separated) environment?

Yes. STATIC Enterprise can be installed with its web server (WAS) and analysis agents (APU) inside your internal network and operated without an external internet connection. STATIC Standalone is installed on a local PC and supports dongle licensing, so it can be used at customer sites and in network-separated environments. Note that AI features such as Smart Suggestion and STATIC Agent Chat require an LLM URL and API key configuration. The LLM configurations and supported models available in an air-gapped environment may vary by edition, version, and license, so they should be confirmed before adoption. The air-gapped installation procedure and licensing options can be explained together with your environment details when you contact us about adoption.

Can projects with several million lines of code be analyzed?

Yes, Enterprise can analyze codebases of several million lines. After the initial full analysis, incremental analysis inspects only the changed portions, and APU Grid distributed analysis uses the resources of multiple analysis agents to shorten analysis time. In a measurement example configured with a dedicated APU server, roughly 300 C++ source files were analyzed in under a minute. Even on large projects you can integrate with CI and run an analysis on every build, and you can check the request history and progress status on the analysis management screen. That said, actual analysis time varies greatly with code size, language, applied rule sets, and agent configuration, so if you share your project size and target analysis cycle when evaluating adoption, we can help identify a suitable server and agent configuration.

How does it integrate with CI/CD and configuration management?

Both Enterprise and Standalone can integrate with continuous integration (CI) environments such as Jenkins, though the details of the integration differ by edition. With CI integration, static analysis runs automatically during the build, so the process can enforce analysis across the entire path from development to deployment. Enterprise automatically assigns detected defects to the responsible developer based on Git commit information, reducing the management overhead of distributing defects. It also provides an access key based Open API, issued from the user profile, for feeding analysis results and quality indicators into your in-house quality management system. Among our own tools, VPES integrates with both editions, and the V-SPICE link is provided in Enterprise. The specific integration configuration must be confirmed against the CI and configuration management tools and versions you use.

How is it different from other static analysis tools?

STATIC is distinguished from general-purpose overseas tools by the fact that it embeds, as rule sets, the verification guidelines required of Korean safety-critical and embedded projects, and by its broad support for embedded compilers. It supports the DAPA Software Reliability Assessment Guidelines with 92 items for C/C++, 100% of the ES95489-23 C and C++ rule sets, and the HKMC verification guidelines with 60 items across grades A/B/SE. Whether a cross compiler can be interpreted often determines whether adoption is feasible at all, and both Enterprise and Standalone ship with built-in build configurations for the IAR, Keil, TASKING, Renesas, TI, Microchip, and NXP toolchain families. Beyond detection, defects are managed through rule compliance rate (RCR) trends, and Smart Suggestion finds and recommends similar cases from past suppression records, reducing the burden of repeated assessments. Compiler enablement, rule set tuning, and guideline interpretation can be discussed in Korean through local technical support. The actual supported scope must be confirmed against your edition and product version.

Product videos

Contact us about adoption

For STATIC, the recommended edition and rule set configuration depend on the languages and standards you apply.

If you include the following information in your inquiry, we can immediately recommend a suitable edition and adoption plan.

Development language and version · compiler/toolchain · standards and guidelines you must comply with · project size (lines of code, number of developers) · whether the network is air-gapped · CI and configuration management integration requirements

For product consultations, demos, or brochure requests, use the Suresofttech product inquiry page.

Corporate website
STATIC product page