RedFlag runs a deep AI audit across your whole GitHub repo and returns every real vulnerability - ranked by blast radius, each with a one-click fix for Cursor, Claude, or ChatGPT.
From leaked secrets and vulnerable dependencies to the subtle access-control and injection bugs that automated linters miss entirely.
Reasoning models read your code the way an attacker would - following data flow across files, not just pattern-matching a ruleset.
Every finding ships with a concrete exploit scenario and a copy-paste fix prompt for Cursor, Claude, or ChatGPT.
From a repo URL to a ranked report in minutes. Scan many repos at once, or wire RedFlag straight into your CI pipeline.
Your repository is analysed in ephemeral memory and never written to disk - only the findings are kept. Access tokens are encrypted, and you can revoke anytime.
Sign in with GitHub and point RedFlag at any repo - public or private. Nothing to install, no config files, no CI to wire up.
Grounded scanners catch leaked secrets and known-vulnerable dependencies. Then reasoning models read your most security-critical code.
Get a prioritised report of every real issue. Copy a ready-made fix prompt for one finding - or all of them - into your AI assistant.
Free forever for public repos. Personal is free for your first month - private repos and deep scans. Team is unlimited with seats for everyone.
Kick the tyres on your public code.
For individual devs shipping real projects.
Security coverage for your whole engineering team.
All plans include the full report and copy-to-AI fixes. Cancel anytime. Compare plans →
Your first scan is free - or get Personal free for a month for private repos and deep scans. See exactly how exposed your codebase is in minutes.