Pre-flight scan
Local secret detection (AWS, GitHub, OpenAI, Stripe, Slack, JWT, private keys, .env) — runs in your browser before any payload is sent.
Dependency CVE lookup
Parses package.json, requirements.txt, Cargo.toml, go.mod and Gemfile.lock; queries the public OSV.dev database for known vulnerabilities.
SARIF export
Download any scan as SARIF 2.1.0 for GitHub Code Scanning, VS Code SARIF Viewer, and most security dashboards.
Honest copy
Removed unverified marketing claims, fake customer logos, and pricing for tiers we don't ship yet.