
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Find, verify, and analyze leaked credentials

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Octoscan is a static vulnerability scanner for GitHub action workflows.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

safe execution paths for agents - zero trust, zero setup, zero latency.

nodejsscan is a static security code scanner for Node.js applications.

Protect against malicious open source packages 🤖

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.