<!--
STATIC product overview web page copy (contents.md) [EN]
- Publication-ready copy, tables, and figures written in web page section order
- [Section n | Component] comments: screen composition notes for that block (for design reference)
- Source of facts: the official STATIC manual first, the product brochure as a secondary source
- Images: selected from static/images (the official manual image set)
-->

<!-- [Section 1 | Hero: H1 + definition + metric strip + key visuals] -->

# STATIC | Suresofttech Source Code Static Analysis Tool

STATIC from Suresofttech is a static analysis tool that detects coding rule violations, runtime errors, and potential security vulnerabilities without executing the source code. It also provides domain-specific coding rule sets and software quality metrics.

<!-- Use the definition above verbatim as the meta description -->

<!-- Metric strip: 4-column cards. Set the "value" of each item large and the "label" small -->

- **Supported languages** — Enterprise (EE): C/C++, C#, Java, Kotlin, Python; Standalone (SE): C/C++
- **Inspection patterns¹** — 1,200+
- **Supported toolchains** — IAR · Keil · TASKING · Renesas · TI · Microchip and more
- **Software quality metrics** — approx. 30 in EE · approx. 20 in SE

¹ Figures are based on Enterprise. The supported scope varies by edition, language, and product version, so the detailed applicable scope must be confirmed against your own environment.

<!-- Key visual gallery: two tabs or slides, "Project quality status" and "Defect review and assignee management" -->

![Example of the STATIC Enterprise project list screen. For each of the VehicleControl, BatteryManager, DiagnosticsService, and GatewayECU projects, the language, manager, remaining/suppressed/new/closed defect counts, creation time, and latest analysis time are displayed, so the code quality status of multiple projects can be compared at a glance.](images/projects-list.png)
*Project static analysis status list — compare and manage the analysis status and defect indicators of multiple projects on one screen*

![Example of the STATIC Enterprise defect list screen. Severity, confidence, assignee, file, rule, function, status, and label filters are placed at the top, and predefined filters such as assigned defects, new defects, and closed defects are shown on the left. Each defect card shows the INT31_C rule ID, the MainFrm.cpp file and line number, the OnCreate function, the integer conversion violation, and the status and assignee change controls.](images/defect-list.png)
*Defect review and assignee management — check detected rule violations together with their source location and track status and assignee*

---

<!-- [Section 2 | 4 problem cards + concept block] -->

## Why static analysis is needed

**A successful compile does not mean there will be no defects at runtime.**

- **Defects the compiler cannot catch** — memory leaks, NULL dereferences, and array-bound overruns pass compilation and survive into execution.
- **The later you find it, the more it costs** — finding these through testing requires reproducing the execution conditions that trigger the error, which delays discovery.
- **Rule compliance required by standards** — safety-critical domains such as automotive, defense, and aerospace require compliance with different coding rules depending on the applicable standards and project guidelines.
- **Many defects, no management** — if there is no record of who fixed what and when, detection alone does not improve quality.

### What Is Static Analysis?

Static analysis is a technique for detecting errors and potential security vulnerabilities by analyzing the source code itself without executing it. Because it can identify defects that would cause system failures or reduced reliability before the program runs, it is used in most software development today.

Unlike dynamic analysis, which measures execution rates from the results of running the code, static analysis inspects the code itself and can therefore find defects even without test cases. The two approaches complement rather than replace each other.

> Static analysis is an activity for finding defects before execution; it does not replace testing (dynamic verification). The actual impact of a detected defect depends on the code context, so a review process is required.

---

<!-- [Section 3 | 5 figure-emphasis cards] -->

## The core value STATIC delivers

**STATIC does not stop at detection — it manages defects through remediation and tracking.**

- **Runtime error detection without execution** — the STATIC analysis engine uses more than 1,200 inspection patterns and more than 30 kinds of semantic analysis to find memory, arithmetic, and array-bound errors before the code is ever run.
- **Automatic checking against domain rule sets** — STATIC automatically checks coding rules such as MISRA, CERT, and AUTOSAR, CWE-based security weaknesses, and DAPA guideline items.
- **AI-assisted assessment and Q&A** — Smart Suggestion finds and recommends similar suppression history, and STATIC Agent Chat answers questions about tool usage and defects based on the guide documentation.
- **Built for large codebases** — Enterprise analyzes codebases of several million lines, and after the first analysis it shortens the cycle with incremental analysis and APU Grid distributed analysis.²
- **Defect tracking and management** — Enterprise tracks status changes through the defect life cycle and history, and manages quality trends with the rule compliance rate (RCR) and defect density.

² In a measurement example configured with a dedicated APU server, roughly 300 C++ source files were analyzed in under a minute. Actual analysis time varies with code size, rule set, and hardware configuration.

---

<!-- [Section 4 | Edition comparison: 2-column cards + comparison table + selection criteria] -->

## STATIC Enterprise and Standalone

**STATIC is offered in two configurations: centrally managed and developer IDE based.**

STATIC Enterprise (STATIC EE) manages the defects of multiple developers and projects in a centrally managed web server environment, while STATIC Standalone (STATIC SE) lets you review and fix violations on a single screen in a VS Code based standalone IDE.

| Comparison item | STATIC Enterprise | STATIC Standalone |
|---|---|---|
| One-line definition | Organization-wide code quality management platform | IDE-integrated static analysis tool for developers |
| Supported languages | C/C++, C#, Java, Kotlin, Python | C/C++ |
| Composition | Web server (WAS) + analysis agent (APU) + web UI | VS Code based IDE, installed locally |
| Defect management | Central dashboard, status and assignee management, trend tracking, objective setting | Local filters and status management, review and fix on one screen |
| Analysis method | Server-side analysis, APU Grid distributed analysis, incremental analysis | Local analysis, automatic extraction of analysis information per development environment |
| AI features | Smart Suggestion, STATIC Agent Chat | Contact us separately |
| Environment | Server and analysis agents operated on the internal network | Installed on a local PC, dongle license supported |

**When to choose STATIC Enterprise**

- When defects from multiple developers must be assigned and tracked centrally
- When project quality trends and objective attainment must be managed
- When languages other than C/C++, such as Java, C#, Kotlin, and Python, must be analyzed
- When integration with CI, configuration management, and in-house quality systems is required

**When to choose STATIC Standalone**

- When developers need to review and fix violations immediately in the environment where they write code
- When server access is difficult, such as at a customer site or on an air-gapped network
- When embedded C/C++ must be analyzed per development PC without server infrastructure

---

<!-- [Section 5 | 5 feature blocks (each: lead copy + points + screenshot)] -->

## Key features

### Coding Rule Checking

**STATIC automatically checks the coding rules that must be observed in each domain.**

- Provides coding rule sets such as MISRA C/C++, AUTOSAR C++14, and CERT, CWE-based security weaknesses, and rule sets aligned with DAPA, HKMC, and Ministry of the Interior and Safety guidelines.
- You can build a rule set from only the rules your project needs, create custom rule sets, and import rule sets from other projects.
- The rule manual provides a description of each rule together with violating (Bad) and compliant (Good) code examples.

### Runtime Error Detection

**STATIC detects errors that occur at execution time without running the code.**

- **Memory errors** — invalid memory access, memory leaks, NULL dereferences, invalid memory deallocation
- **Arithmetic errors** — errors in complex arithmetic operations, incorrect operations caused by type conversions the user is unaware of
- **Array-bound errors** — errors directly tied to security vulnerabilities, such as buffer overflow and buffer underflow

The STATIC Enterprise analysis engine performs more than 1,200 pattern checks and more than 30 kinds of semantic analysis. C/C++ defects are provided with severity and confidence grades. The scope of defect information differs by language — for example, confidence is not provided for Java, C#, Kotlin, and Python.

### Software Quality Metrics

**STATIC quantifies the size and complexity of code as metrics.**

- Enterprise provides approximately 30 metrics at the module, file, class, and function levels, with supported items differing by language. These include Cyclomatic Complexity (FUCYC), Modified Cyclomatic Complexity (FUMCYC), maximum nesting depth (FUMNC), Myer's Interval (FUMIV), and MC/DC case count (FUNDM).
- Standalone provides module-, file-, and function-level metrics for C/C++ plus approximately 20 additional metrics.
- The six function metrics specified in the Weapon System Software Development and Management Manual are supported.
- In Enterprise you can divide each metric into stages and set thresholds, so that items exceeding the criteria are flagged with a warning.
- In Enterprise you can configure specific metric violations to be ignored and export the suppression history as a report.

### Defect Management and Objective Tracking

**Enterprise tracks defect status from discovery through completed remediation and manages project quality objectives centrally. Standalone provides filter and status management features in the local environment.**

- **Defect life cycle and history** — manage defect status stage by stage and track the change history. Each defect is given a unique URL so recurrences of the same defect can be identified.
- **Filters and bulk changes** — search by combining severity, confidence, assignee, file, rule, function, and label, and save frequently used conditions as filters. The status or assignee of selected defects can be changed in bulk.
- **Suppression (ignoring defects)** — manage defects in a Suppressed state with a specified reason such as intended code, false positive, or duplicate.
- **Baseline (Enterprise)** — set a reference point and analyze; defects from earlier analyses are excluded from the managed set so you can focus on defects introduced after the reference point.
- **Objective setting** — set a target for remaining defects by severity along with a period, and track attainment with a burndown chart.
- **Quality indicators** — check the rule compliance rate (RCR), defect density, number of analyzed files, and lines of code per project.

![Example image reconstructing the defect management and objective tracking features of STATIC Enterprise. The Defects area shows how remaining, suppressed, new, and closed defects changed across six configuration analyses, with the delta values indicating the difference between the latest and previous configuration. The Objective area shows a target of 1,000, remaining of 2,880, and required closures of 1,880 together with the ideal and actual trends. The figures on screen are sample data used to explain the feature.](images/defect-management-objective.png)
*Defect management and objective tracking — view defect trends per configuration, the change versus the previous configuration, and actual reduction against the target on one screen*

### Remediation Support

**STATIC provides features that help you understand the cause of a defect and decide how to fix it.**

**AI features**

- **STATIC Agent Chat** — an AI Q&A service that answers questions about tool usage, project information, and defect causes and remediation guidance based on the STATIC guide documentation.
- **Smart Suggestion** — AI finds and recommends past suppression records similar to the current defect. You can compare the original defect code with the recommended suppression record code in a diff view and then accept or reject it, and you can set the reference scope to the current project or to all projects your account can access.

![The STATIC Agent Chat screen. When the user asks how to fix a defect, the AI finds and reads the relevant guide and presents the cause of the defect that occurs when converting a signed value to an unsigned type, how to validate the range, the related rules, and a code fix example.](images/agent-chat.png)
*STATIC Agent Chat — explains the cause of a defect, how to fix it, and code examples based on the relevant guide*

**Remediation history based features**

- **Fix Reference** — provides data that helps with remediation, such as code that actually fixed the defect. You can move to the previous or next entry to review them and vote for entries that were helpful.

### Analysis Automation and Integration

**STATIC integrates into the development pipeline to run static analysis automatically.**

| Integration target | Description | Edition |
|---|---|---|
| CI (Jenkins and others) | Runs static analysis automatically during the build to enforce analysis from development through deployment | EE·SE |
| Incremental analysis | Analyzes only the changed portions after the initial full analysis to shorten the cycle | EE |
| APU Grid distributed analysis | Uses the resources of multiple analysis agents to shorten analysis time on large projects | EE |
| Open API | Feeds analysis results and quality indicators into in-house systems. An access key is issued from the user profile | EE |
| Configuration management (Git and others) | Automatically assigns defects to the responsible developer based on commit information | EE |
| VPES | Integrates analysis results with the build and test automation tool | EE·SE |
| V-SPICE | Links with the process reporting automation tool | EE |
| STATIC SE → EE | Uploads results analyzed in Standalone to Enterprise for consolidated management | SE→EE |

---

<!-- [Section 6 | Supported language tags]
     ★ Make the entire tag containing the language name a link.
     ★ Lay them out in one row on desktop and in 2–3 columns on mobile.
     ★ Use the in-house tag SVGs in a consistent format instead of external language logos.
     ★ Do not hide the tag images as decorative; provide alt text that includes the language name. -->

## Supported languages

STATIC Enterprise supports C/C++, C#, Java, Kotlin, and Python.

STATIC Standalone supports C/C++.

<div class="language-logo-tabs" aria-label="Languages supported by STATIC" style="display:flex; flex-wrap:wrap; gap:20px; align-items:center; margin-bottom:16px;">
  <a class="language-logo-tab" href="../languages/languages_contents.md#c--c" aria-label="C/C++ support information" style="display:inline-flex; width:128px; height:56px; flex:0 0 128px;"><img src="images/language-c-cplusplus.svg?v=20260826" width="128" height="56" style="display:block; width:128px; height:56px; object-fit:contain;" alt="C/C++ combined language tag supported by STATIC"></a>
  <a class="language-logo-tab" href="../languages/languages_contents.md#c" aria-label="C# support information" style="display:inline-flex; width:128px; height:56px; flex:0 0 128px;"><img src="images/language-csharp.svg?v=20260826" width="128" height="56" style="display:block; width:128px; height:56px; object-fit:contain;" alt="C# language tag supported by STATIC"></a>
  <a class="language-logo-tab" href="../languages/languages_contents.md#java" aria-label="Java support information" style="display:inline-flex; width:128px; height:56px; flex:0 0 128px;"><img src="images/language-java.svg?v=20260826" width="128" height="56" style="display:block; width:128px; height:56px; object-fit:contain;" alt="Java language tag supported by STATIC"></a>
  <a class="language-logo-tab" href="../languages/languages_contents.md#kotlin" aria-label="Kotlin support information" style="display:inline-flex; width:128px; height:56px; flex:0 0 128px;"><img src="images/language-kotlin.svg?v=20260826" width="128" height="56" style="display:block; width:128px; height:56px; object-fit:contain;" alt="Kotlin language tag supported by STATIC"></a>
  <a class="language-logo-tab" href="../languages/languages_contents.md#python" aria-label="Python support information" style="display:inline-flex; width:128px; height:56px; flex:0 0 128px;"><img src="images/language-python.svg?v=20260826" width="128" height="56" style="display:block; width:128px; height:56px; object-fit:contain;" alt="Python language tag supported by STATIC"></a>
</div>

[See the supported versions and development environments for STATIC languages in detail →](../languages/languages_contents.md)

---

<!-- [Section 7 | Table separating coding rules, industry standards, and tool qualification] -->

## Coding rules and industry standards

**STATIC checks coding rules and domestic domain guidelines as rule sets, and supports the use of static analysis results as verification evidence when responding to safety standards.**

| Category | Standard / guideline | STATIC support scope |
|---|---|---|
| International coding rules | MISRA C/C++, AUTOSAR C++14, CERT Secure Coding, JSF | Coding rule violation checks. Supported rules and detection scope vary by language, edition, and version |
| Security weakness classification | CWE | Checks for security weaknesses mapped to CWE IDs. Supported items vary by language, edition, and version |
| Korean automotive guidelines | ES95489-23, HKMC verification guidelines | EE: 100% of the ES95489-23 C, C++, and Java rule sets, 60 HKMC grade A/B/SE items. SE: 100% of the ES95489-23 C and C++ rule sets, 48 HKMC grade A/B items |
| Korean defense guidelines | DAPA Software Reliability Assessment Guidelines (CWE 658/659/660) | 92 items supported for C/C++. EE additionally supports 65 Java items; further supported scope may vary by product version |
| Korean security guidelines | Ministry of the Interior and Safety secure coding guide | Checks secure coding rules and security weaknesses |
| Quality rules | Naming and coding style guidelines | Checks naming conventions and coding style |
| Fields applying safety and life cycle standards | ISO 26262, DO-178C, IEC 61508, IEC 62279·EN 50128, IEC 62304, IEC 60880 | Coding rule checks and static analysis results can be used as verification evidence when responding to the standard. Required deliverables and applicable scope per project must be confirmed separately |

**Tool qualification materials** — tool qualification materials for certification audits are provided. The materials actually supplied, the applicable product versions, and the standard scope must be confirmed on a per-project basis.

---

<!-- [Section 8 | 3 case cards (problem / application / result)] -->

## Use cases

### Automotive parts manufacturer — preventing recurring errors with custom coding rules

- **Problem** — an engine design project (C language) needed custom rules to prevent the recurrence of errors that had actually occurred
- **Application** — analyzed the errors that occurred, developed and applied custom coding rules, and included a rule verification step in the development process
- **Result** — used in the verification process for ISO 26262 compliance

### Semiconductor manufacturer — MISRA rules integrated with build automation

- **Problem** — development proceeded without a dedicated static analysis tool, producing variation in code quality
- **Application** — applied MISRA coding rules and integrated with the build automation server so that analysis runs on every build
- **Result** — used in the verification process for IEC 61508 compliance and established a software quality management system

### Defense system developer — reliability verification of embedded weapon system software

- **Problem** — the console GUI software of a guided weapon launch control unit had to satisfy software reliability test requirements
- **Application** — detected and fixed defects through runtime error detection and rule checks based on the Software Reliability Assessment Guidelines
- **Result** — met the software reliability test criteria and the acceptance criteria of the ordering company

---


<!-- [Section 9 | FAQ accordion, 13 items] -->

## Frequently asked questions

### What is STATIC?

STATIC from Suresofttech (SURESOFTTECH) is a static analysis tool that analyzes source code without executing it to detect coding rule violations and runtime errors. Following coding guidelines, it finds critical errors and potential security holes in the source code, catching defects early in development that the compiler does not report. It supports coding rules such as MISRA and CERT and CWE-based security weakness checks, and its static analysis results can be used as verification evidence when responding to safety standards such as ISO 26262 and IEC 61508. It comes in two forms: STATIC Enterprise, a centrally managed web server environment, and STATIC Standalone, a VS Code based IDE.

### What kinds of defects can STATIC detect?

STATIC checks three types of issues. First, it checks coding rule violations such as MISRA, CERT, and AUTOSAR, and security weaknesses mapped to CWE IDs. Second, it detects runtime errors without running the code, including memory errors (invalid access, memory leaks, NULL dereferences, invalid deallocation), arithmetic errors (complex operations, unnoticed type conversions), and array-bound errors (buffer overflow and underflow). Third, it checks violations of software quality metric thresholds such as cyclomatic complexity and nesting depth. C/C++ defects are provided with severity, confidence, and the source code location. Confidence is not provided for Java, C#, Kotlin, and Python, and some other provided items such as function information also differ from C/C++.

### What is the difference between STATIC Enterprise and STATIC Standalone?

STATIC Enterprise is a centrally managed web server environment that assigns and tracks the defects of multiple developers and projects from a dashboard and supports five languages: C/C++, C#, Java, Kotlin, and Python. It provides project objective setting and burndown charts, APU Grid distributed analysis, an Open API, and configuration management integration. STATIC Standalone is a VS Code based standalone IDE that supports C/C++ and lets developers review and fix violations on a single screen in the environment where they write code. It supports local installation and dongle licensing, so it can be used at customer sites or on air-gapped networks. Enterprise is recommended when organization-wide quality management is needed, and Standalone when the goal is immediate review and remediation by an individual developer.

### Which programming languages and compilers are supported?

STATIC Enterprise supports C/C++, C#, Java, Kotlin, and Python, and STATIC Standalone supports C/C++. Analysis requests reuse your existing build environment: Visual Studio and Makefile for C/C++, Visual Studio solution and project files for C#, and Maven and Gradle for Java and Kotlin. Compiler support is identical in Enterprise and Standalone, with built-in toolchain configurations for IAR, Keil uVision, TASKING (AURIX), Renesas CS+, TI Code Composer Studio, Microchip Studio and MPLAB X IDE, STM32CubeIDE, Xilinx Vitis Unified, MCUXpresso IDE, Code Warrior, GNU, LLVM, and Visual Studio. Compilers not on the list can be configured in Manual Mode; applicability is determined after reviewing the compiler specification and the project environment.

### Does it support MISRA C/C++ checking?

Yes, STATIC supports MISRA C and MISRA C++ coding rule checking. It provides MISRA C/C++ rule sets including MISRA C 2004, 2012, 2023, and 2025, as well as AUTOSAR C++14. You can build a rule set from only the rules your project needs, create custom rule sets, and import rule sets from other projects. The rule manual provides a description of each rule together with violating (Bad) and compliant (Good) code examples, so you can make fixes with a clear understanding of the intent behind the rule. The supported MISRA editions and the detection scope per rule vary by edition and product version, so they should be confirmed before adoption. The full list of supported rule sets is available in [Coding Rules and Industry Standards](#coding-rules-and-industry-standards).

### How can runtime errors be found without executing the code?

STATIC traces the execution paths and data flow of the source code through semantic analysis to identify, at the code level, conditions under which an error could occur at runtime. For example, it tracks the value range of a variable used as an array index to determine whether it could go out of bounds, and it checks whether allocated memory is released on all paths. The Enterprise analysis engine performs more than 1,200 pattern checks and more than 30 kinds of semantic analysis. That said, static analysis is a prediction made before execution, so the actual impact must be reviewed in the context of the code; confidence is provided for C/C++ and is not provided for Java, C#, Kotlin, or Python.

### How are false positives managed?

STATIC provides several mechanisms for managing false positives. C/C++ defects are labeled with a confidence grade, and defects can be managed in a Suppressed state with a specified reason such as intended code, false positive, or duplicate. Project members can leave comments on a defect and review it together. Smart Suggestion in Enterprise recommends past suppression records similar to the current defect and lets you compare the original defect with the recommended case before accepting or rejecting it.

### We have a lot of legacy code — can we manage only newly written code?

Yes, this is possible with the Baseline feature in Enterprise. Once you set a reference point and run an analysis, defects from earlier analyses are excluded from the managed set so you can focus on defects introduced after the reference point. This avoids a situation where existing defects in legacy code fill the list and bury problems in new code. Baseline can be turned off in the project settings, so once you have capacity you can bring all defects back into the managed set. Used together with the project objective feature, you can set a target for remaining defects by severity along with a period and track reduction progress with a burndown chart — allowing you to prioritize the quality of new code while reducing legacy defects in stages. The related features are described in [Defect Management and Objective Tracking](#defect-management-and-objective-tracking).

### Can it be used for compliance with safety standards such as ISO 26262 and DO-178C?

Yes, the coding rule checks and static analysis results from STATIC can be used as verification evidence in the process of responding to safety standards. In projects applying safety and life cycle standards such as ISO 26262, DO-178C, IEC 61508, IEC 62279·EN 50128, IEC 62304, and IEC 60880, coding rule compliance and runtime error detection results can be retained as deliverables. STATIC provides the coding rule sets that these standards require, including MISRA C/C++, AUTOSAR C++14, and CERT, and detection results are tracked as defect information including the source location and severity. For C/C++, confidence is provided as well. Tool qualification materials for certification audits are available, and the supported scope per standard is summarized in [Coding Rules and Industry Standards](#coding-rules-and-industry-standards).

### Can it be installed in an air-gapped (network-separated) environment?

Yes. STATIC Enterprise can be installed with its web server (WAS) and analysis agents (APU) inside your internal network and operated without an external internet connection. STATIC Standalone is installed on a local PC and supports dongle licensing, so it can be used at customer sites and in network-separated environments. Note that AI features such as Smart Suggestion and STATIC Agent Chat require an LLM URL and API key configuration. The LLM configurations and supported models available in an air-gapped environment may vary by edition, version, and license, so they should be confirmed before adoption. The air-gapped installation procedure and licensing options can be explained together with your environment details when you contact us about adoption.

### Can projects with several million lines of code be analyzed?

Yes, Enterprise can analyze codebases of several million lines. After the initial full analysis, incremental analysis inspects only the changed portions, and APU Grid distributed analysis uses the resources of multiple analysis agents to shorten analysis time. In a measurement example configured with a dedicated APU server, roughly 300 C++ source files were analyzed in under a minute. Even on large projects you can integrate with CI and run an analysis on every build, and you can check the request history and progress status on the analysis management screen. That said, actual analysis time varies greatly with code size, language, applied rule sets, and agent configuration, so if you share your project size and target analysis cycle when evaluating adoption, we can help identify a suitable server and agent configuration.

### How does it integrate with CI/CD and configuration management?

Both Enterprise and Standalone can integrate with continuous integration (CI) environments such as Jenkins, though the details of the integration differ by edition. With CI integration, static analysis runs automatically during the build, so the process can enforce analysis across the entire path from development to deployment. Enterprise automatically assigns detected defects to the responsible developer based on Git commit information, reducing the management overhead of distributing defects. It also provides an access key based Open API, issued from the user profile, for feeding analysis results and quality indicators into your in-house quality management system. Among our own tools, VPES integrates with both editions, and the V-SPICE link is provided in Enterprise. The specific integration configuration must be confirmed against the CI and configuration management tools and versions you use.


### How is it different from other static analysis tools?

STATIC is distinguished from general-purpose overseas tools by the fact that it embeds, as rule sets, the verification guidelines required of Korean safety-critical and embedded projects, and by its broad support for embedded compilers. It supports the DAPA Software Reliability Assessment Guidelines with 92 items for C/C++, 100% of the ES95489-23 C and C++ rule sets, and the HKMC verification guidelines with 60 items across grades A/B/SE. Whether a cross compiler can be interpreted often determines whether adoption is feasible at all, and both Enterprise and Standalone ship with built-in build configurations for the IAR, Keil, TASKING, Renesas, TI, Microchip, and NXP toolchain families. Beyond detection, defects are managed through rule compliance rate (RCR) trends, and Smart Suggestion finds and recommends similar cases from past suppression records, reducing the burden of repeated assessments. Compiler enablement, rule set tuning, and guideline interpretation can be discussed in Korean through local technical support. The actual supported scope must be confirmed against your edition and product version.

---

<!-- [Section 10 | 4 video cards (thumbnail + summary)] -->

## Product videos

> **Video** — [Detecting and applying MISRA C++ 2023 rules](https://youtu.be/5CXUeYU51cM)
> Key content of the MISRA C++ 2023 rules and how to detect and apply them with STATIC — Suresofttech seminar (in Korean)

> **Video** — [Introducing new features in STATIC 4.8 | AI & Cyber Security With Automation Tools](https://youtu.be/y88Co7L0kuU)
> An introduction to new features in STATIC 4.8, including AI features and cyber security rule checking — Suresofttech seminar (in Korean)

> **Video** — [Improving verification productivity by automating coding rule checks and defect life cycle management](https://youtu.be/BY89uaIDgX8)
> Automating static analysis with STATIC from coding rule checks through defect life cycle management, and how it improves verification productivity — Suresofttech seminar (in Korean)

> **Video** — [STATIC | Using detection information | How to fix code](https://youtu.be/dB_QcIcESa4)
> How to use the detection information in STATIC to identify the cause of a defect and fix the code — Suresofttech seminar (in Korean)

---

<!-- [Section 11 | CTA banner + contact information] -->

## Contact us about adoption

**For STATIC, the recommended edition and rule set configuration depend on the languages and standards you apply.**

If you include the following information in your inquiry, we can immediately recommend a suitable edition and adoption plan.

Development language and version · compiler/toolchain · standards and guidelines you must comply with · project size (lines of code, number of developers) · whether the network is air-gapped · CI and configuration management integration requirements

For product consultations, demos, or brochure requests, use the [Suresofttech product inquiry page](https://www.suresofttech.com/customer/inquiry.php).

**[Request a Demo](https://www.suresofttech.com/customer/inquiry.php)**

Corporate website: [STATIC product page](https://www.suresofttech.com/product/code_verification.php?ptype=view&prdcode=2606240002&page=1&catcode=10120000)

Technical support: [Suresofttech inquiry page](https://www.suresofttech.com/customer/inquiry.php) · help@suresofttech.com · +82-31-606-2000

---
