Skip to content
4 agents live · cloud coming soon

Find, prove, and fix vulnerabilities on every commit.

AI agents learn how your application works, who uses it and what it protects, then audit your code, web apps, and Android apps the way a pentester would. Continuously, with proof and a fix for every finding.

Audit completeSample output

target acme/payments-api @ 4f1c2e9

  1. index1,926 files → code graph · 9 parsers✓
  2. map214 entry points · 41 non-HTTP✓
  3. analysefull call chain per entry point✓
  4. crawlapp.acme.test · 3 roles · real browser✓
  5. attack15 attack classes · 97 WSTG tests✓
  6. verifyreplayed vs control → verified✓
  7. rateCVSS v4.0 ·9 critical·42 high·30 medium
  8. fix3 criticals with fixes waiting for review
Audited by NoHacksha256:07f0…102e
  • 01 White-box · code
  • 02 Grey-box · roles
  • 03 Black-box · runtime
  • 04 Fix · retest

AI agents that find, prove, and fix vulnerabilities on every commit, auditing your code the way an attacker would.

Why now

AI writes most of the code now. Attackers already probe continuously; the audit is still annual. Auditing has to become agentic and continuous, because code creation already is.

One audit

Attackers don’t care whether a bug is a SAST or a DAST finding. Neither does our audit. Code, running app, mobile build, and every pull request. One engine, one report.

The bar

A finding without a proof-of-concept is noise. If we can’t prove it, we don’t ship it.

01

Learns the business before it attacks.

Scanners know payloads. Pentesters know what your application is for. The agents start where a good pentester does.

  • Profiles the application

    What it is, who uses it, how they sign in, and which data is worth stealing, worked out from the code and the running app before the first attack.

  • Maps every role

    Customer, merchant, support, admin. Each role’s view of the app is baselined, so a request that works for the wrong role stands out.

  • Threat-models first

    Context becomes a threat model against OWASP ASVS 5.0, and the threat model becomes attack priorities, the way a pentester scopes an engagement.

  • Tests the business logic

    Refunds, transfers, approvals, tenant boundaries: dedicated agents probe the workflows that payload lists can’t reason about, and skip checks that don’t apply.

Building contextSample output

target app.acme.test + acme/payments-api

app
multi-tenant payments platform
roles
customer · merchant · support · admin
auth
JWT bearer · per-merchant API keys
assets
card tokens · payout accounts · refunds
trust
support can read across tenants

Attack priorities · from the threat model

  1. 01Can merchant A refund merchant B’s order?business logic
  2. 02Can a customer read another tenant’s invoice?authorization
  3. 03Can support change a payout account?privilege

skip CSRF: bearer-only API, no ambient cookies

02

One audit. Every angle.

Each agent attacks from a different side. Findings land in one place, rated the same way, with the same bar for proof.

03

If we can’t prove it, we don’t ship it.

A finding reaches you with the evidence that makes it real (a taint path in code, a replayed request at runtime) and the change that fixes it.

  • Taint path, not pattern match

    Code findings follow the real call chain from input to sink. A sanitizer only counts if it transforms the value that reaches the sink.

  • Replayed before it’s reported

    Every web finding is re-sent alongside a control request in the same session. Verified, rejected, or flagged for a human. Never guessed.

  • Rated with evidence

    CVSS v4.0 on every finding, scored from the vector. On web findings each claimed impact must cite its evidence, and analysts can re-rate or override.

  • Fix attached, retest included

    Each finding carries a specific fix for your code, not generic advice. After you push, a retest tells you fixed, still present, or uncertain.

CriticalTaint verifiedSample finding

SQL injection in order search

endpoint
POST /api/orders/search
weakness
CWE-89
cvss
9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

01 · Taint path · white-boxno sanitizer on path

  1. sourcereq.body.qroutes/orders.ts:42
  2. →OrderService.search(q)services/order.ts:88
  3. →buildFilter(q)services/order.ts:131
  4. sinkdb.raw(`…LIKE '%${q}%'`)db/orders.ts:57

02 · Rating · CVSS v4.09.3 critical

AV:N
route is reachable from the internet
PR:N
no auth middleware on the route chain
VC:H
attacker-controlled SQL reads every order
VI:H
same statement allows writes to orders

03 · Fix · db/orders.ts

- db.raw(`SELECT * FROM orders WHERE name LIKE '%${q}%'`)+ db('orders').whereLike('name', `%${q}%`)
NH-2291-007sha256:76e7…ca71Retest after fix
04

Lives in GitHub and the editor.

Findings arrive in the pull request that introduced them, and in the tools developers and security teams already use.

nohack-labsbotcommented · editedSample · PR #8841

Security Scan Results

3 findings on changed lines of 4f1c2e9 · code, dependencies, secrets

SeverityFindingLocation
CriticalSQL injection in order searchservices/order.ts:131
HighVerified secret: payment API keyconfig/payments.ts:7
Mediumaxios 1.6.0 · CVE-2023-45857package.json:23
NoHack PR · failing: 1 critical, 1 verified secretRequired

GitHub, set up in minutes

A guided flow registers your own GitHub App on github.com, GitHub Enterprise Cloud, or Enterprise Server. Pick repositories and branches, private ones included, and pushes keep continuous audits current.

Every pull request

Code, dependencies, and secrets audited on the exact head commit, reported only where lines changed. One comment, kept current, and a check with line annotations that fails on critical, high, or a verified secret.

How NoHack PR works

MCP server

Your findings as tools in Claude Desktop, Cursor, and VS Code. Developers pull the finding they are fixing into the editor; security teams query posture across every repository without opening a dashboard. Org-scoped tokens, issued and revoked by admins.

> which criticals are open on payments-api?
list_vulnerabilities severity=critical status=open
→ 2 findings · 1 has a fix waiting for review
05

Dark for operations. Light for reports.

The same findings, the same numbers, from the daily triage view to the report your auditor reads.

NoHack dashboard in dark mode: 1,618 findings across 70 scans, 733 critical and high, severity and status breakdowns, a 30-day trend, and a security score of 66 with 92% coverage.
Languages
9
families with semantic parsers
Web tests
97
OWASP WSTG test IDs covered
Mobile rules
98
mapped to OWASP MASVS v2
Ecosystems
16
dependency ecosystems, plus containers
06

Meet Aaron, your security agent.

Ask anything about your security: across every audit, on a single finding, or inside a codebase. Aaron answers from live data, not a summary.

  • One chat across every audit

    Ask about any finding, scan, repository, or secret across code, web, dependency, and secret audits, trends and breakdowns included.

  • On every finding

    Open Aaron beside a finding to understand it, find similar ones, or get a secure patch written for your code.

  • Inside the codebase

    Chat with an indexed repository: Aaron reads files, searches code, lists endpoints, and knows the business context of the app.

  • Summaries for the board

    Executive summaries scoped to an organisation, a scan, or a repository, exported to PDF or Word. Every thread is saved and searchable.

Ask AaronSample conversation
Which criticals are still open on payments-api, and which should we fix first?
  1. ›listVulnerabilities severity=critical status=open repo=payments-api → 3 results
  2. ›getVulnerabilityDetails NH-2291-007 → taint verified · fix attached
  3. ›getTrend range=30d → +2 criticals since last audit

3 criticals are open. Fix NH-2291-007 first: SQL injection on a public route with no auth middleware. The taint path is verified and a fix is attached.

The other two need an authenticated session and touch internal admin routes. Schedule them for this sprint.

Draft a secure patchExecutive summaryCompare with last month
Answered from live org data
07

Know what every audit costs.

Agents spend tokens. You see where every one goes, and you decide the ceiling.

Audit A-3120 · NoHack WebSample

LLM cost

$14.82

of $25.00 budget · 59%

alert at 80%pause at 100% · hard

wall time
38m 12s
agent runs
41
input
18.2M · 71% cached
output
412k

By agent

  • crawl3 runs$1.94
  • threat model1 runs$0.88
  • attack · idor9 runs$4.12
  • attack · sqli7 runs$3.37
  • verify14 runs$2.96
  • rate7 runs$1.55
  • Cost on every audit

    Wall time, agent runs, cached and uncached tokens, and LLM cost against the audit’s budget, with a per-run timeline.

  • Cost by agent

    See which agents spend what across your organisation, and export per-audit cost to Excel for finance.

  • Budgets and limits

    A monthly budget for the organisation, default and maximum limits per audit, and per-audit overrides when you need them.

  • Track, warn, or enforce

    Alerts at 80% and 100%. In hard mode a capped audit pauses with a reason and resumes where it stopped. It is never reported as clean.

08

Pentests, on the same platform.

Run pentest engagements where your continuous audits already live. Same findings, same severity scale, one report.

  • Scoped like an engagement

    Black-, grey-, or white-box; scope, targets, and methodology recorded up front, with status from scheduled to completed.

  • AI white-box engagements

    Pick a repository and a deep, comprehensive audit starts immediately, with the model you choose for each stage.

  • Human-led, same platform

    Track engagements run by your own testers alongside the agents’ work, on the same severity scale.

  • Finalized means final

    Finalizing freezes the findings into a snapshot. After sign-off only the report narrative, severity, and attestation change.

Engagement finalizedSample

Q4 audit: payments platform

Type
White-box
Methodology
AI-led · comprehensive mode
Scope
acme/payments-api
Models
discovery · context · analysis · verification
  1. Scheduled
  2. Active
  3. Completed
  4. Finalized

14

findings frozen

1

snapshot

✓

attestation added

Coming soon · NoHack Marketplace

Need an audit someone else signs?

A vetted security firm runs the engagement on the same platform, inheriting the context it already holds, and issues the signed, compliance-ready report.

Get notified
09

Runs where your code is allowed to go.

Hosted, or in your own cloud with the models you choose. Cloud-agnostic and model-agnostic, built for teams that answer to auditors.

Hosted

Connect GitHub, add a target, upload an APK. Nothing to run.

Self-hosted, any cloud

Kubernetes via Helm, or Docker Compose, on AWS, Azure, GCP, or your own data centre. Code and findings stay in your environment.

Any model

Model-agnostic: OpenAI, Anthropic, Bedrock, Azure OpenAI, Vertex, or a model you host, through any OpenAI-compatible gateway. Pick a model per agent.

Your GitHub, your App

Your own GitHub App on github.com, Enterprise Cloud, or Enterprise Server, so access stays under your organisation’s control.

Access that holds up

Role-based access with custom roles, enforced MFA, an audit log, and isolated tenants.

Reports people sign

DOCX reports from your own templates, SARIF for code scanning, CSV and CycloneDX SBOM exports.

Security at the speed you ship.

Bring a repository, a web app, or an APK. We will walk you through a real audit of it.