Engine v2.4 Live · Zero Code Retention

Security reviews for any
GitHub repo, in minutes.

Paste a repository link and get a precise, OWASP-mapped vulnerability report — secrets, injection, broken auth and more — from a focused two-stage AI pipeline.

✓ No credit card·✓ Public & private repos·✓ PDF & Markdown export
src/auth/session.ts
1 Critical Flaw
// Triage Pass: High Risk Injection Detected
const query = `SELECT * FROM users WHERE token = '${userToken}'`;
▲ High entropy unescaped parameter in SQL string
SQL Injection (OWASP A03)
Raw input is concatenated directly into SQL query. Use parameterized queries.
OWASP Top 10
Full Mapping
< 4 min
Median Scan Time
0 KB
Source Code Stored
2 Models
Triage + Deep AI
Architecture

Built for speed, engineered for trust.

AI + SAST

2-Stage AI Triage

A fast static triage pass funnels risky AST branches to a high-reasoning LLM — accurate where it matters, near-zero false positives.

100% Precision

Deterministic Secret Hunt

Regex and entropy scanning catches leaked API keys, tokens, and credentials that language models routinely miss.

Privacy First

Zero Code Retention

Repositories live only in ephemeral temp memory and are purged within the hour. Your source code is never stored or trained on.

Air-Gapped

SSRF-Hardened Cloning

Strict HTTPS cloning from github.com, internal IP ranges rejected, non-redirecting network isolation, and tight size caps.

Security Coverage

What the 2-stage pipeline checks.

SQL / NoSQL / Command Injection
Reflected, Stored & DOM XSS
Broken Auth & Session Handling
Hardcoded Secrets & API Keys
Insecure Deserialization
SSRF & Path Traversal
IDOR & Access-Control Flaws
Vulnerable Dependencies (OSV)
Cryptographic Misuse
CORS & Security-Header Drift
Pricing Plans

Start free. Scale when you ship.

Quotas reset monthly on your billing-cycle anniversary. Billed securely via Razorpay.

Free

$0/month
1 scan per cycle
  • 100 MB repo cap
  • 1 concurrent scan
  • Public repos only
  • Markdown export
  • Standard queue
Select Free

Starter

$5/month
3 scans per cycle
  • 1024 MB repo cap
  • 1 concurrent scan
  • Private & Public repos
  • Markdown export
  • Standard queue
Select Starter
Most Popular

Pro

$20/month
15 scans per cycle
  • 1024 MB repo cap
  • 2 concurrent scans
  • Private & Public repos
  • PDF + Markdown export
  • Priority scan queue
Select Pro

Team

$50/month
30 scans per cycle
  • 1024 MB repo cap
  • 4 concurrent scans
  • Private & Public repos
  • PDF + Markdown export
  • Priority scan queue
Select Team
FAQ

Frequently Asked Questions

Everything you need to know about GuardRepo AI security analysis, privacy, and subscriptions.

Does GuardRepo AI store or retain my source code?

No. GuardRepo AI operates strictly with zero code retention. Repositories are cloned into temporary, isolated memory for AST parsing and LLM triage analysis, then immediately purged upon completion. Your code is never persisted to disk or used for model training.

How does the 2-Stage AI Scanning Pipeline work?

Can I scan private GitHub repositories?

What security standards and vulnerability types are covered?

How does subscription billing and scan quota work?

Ship faster. Audit effortlessly.

Run your first security scan in under a minute — zero setup required.

Get Started Free →