GDPR · NIS2 · EU AI Act · DORA · PCI DSS · SOC 2 · ISO 27001
bryxe — illustrative scan output
$ bryxe scan ./my-app --deep
Layer 1 · static patterns (20+ languages)
CRITICAL SQL injection via $queryRawUnsafe (api.ts:42)
CRITICAL Python pickle.loads on user data (worker.py:17)
CRITICAL Stripe live key in source (lib/pay.go:8)
Layer 2 · offensive AI audit
HIGH SSRF → IMDS chain on /api/preview
HIGH IDOR → admin escalation via mass-assign role
HIGH JWT alg confusion — no algorithms whitelist
Layer 3 · CVE database (850,000+)
HIGH log4j-core@2.14.1: CVE-2021-44228 (Log4Shell)
Layer 4 · EU compliance
MISSING GDPR Art. 17: erasure endpoint
MISSING NIS2 21(2)(j): MFA required
Done in 47s · 52 findings · GDPR 41% · NIS2 38%

The AI code
security scanner
for your next
big release.

Bryxe Shield helps you find exposed secrets, risky code patterns and vulnerable dependencies in AI-generated code. Review your Next.js, Supabase and Stripe integrations, prioritize findings, and verify the fixes before you ship.

Cursor · ChatGPT · Claude · v0 · Lovable · Copilot

Detect. Fix. Re-scan.

Concrete patterns Bryxe detects and the minimal patch it generates. Every fix is a real diff you can preview before applying.

criticalSQL injection via string concatenation
Rule SQL-TEMPLATE · OWASP A03:2021
Detected
app.post('/login', async (req, res) => {
  const { email, password } = req.body;
  const user = await db.query(
    `SELECT * FROM users
     WHERE email = '${email}'
     AND password = '${password}'`
  );
});
Patch
app.post('/login', async (req, res) => {
  const { email, password } = req.body;
  const user = await db.query(
    'SELECT * FROM users WHERE email = $1',
    [email]
  );
  const valid = await bcrypt.compare(
    password, user.password_hash
  );
});

User input interpolated into a SQL template literal. Bryxe detects the pattern and rewrites the query with parameter binding plus bcrypt password compare.

Try it now — no signup required

Paste your code. See vulnerabilities.

Try a code snippet to explore supported security checks in your browser. This preview uses static rules. Use a repository scan for broader context, then review and test the findings in your application.

Live Scanner
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
Issues Found

Paste code or load example
to start scanning

Real-time CLI Protection

Stops AI Hallucinations Dead.

Bryxe integrates directly into your workflow to catch slopsquatting, hallucinated dependencies, and missing auth checks before they even reach your git history.

bryxe-agent ~ /dev/vibe-project
Simulated demo — actual CLI agent coming soon
Threat Atlas

Know your risk areas.
Focus your next fix.

Explore the security patterns Bryxe helps you investigate. Coverage depends on the language, code context and enabled analysis. Use findings to guide review and application tests.

55+
patterns

Injection

Review injection patterns including concatenated SQL, unsafe template strings, eval on model output, deserialization and command execution.

  • SQL · NoSQL
  • Command
  • XSS variants
  • Deserialization
  • Template / SSTI
  • Path traversal
25+
patterns

Access Control

Check for missing authorization: auth on GET but not PATCH, missing ownership predicates and role checks in the wrong layer.

  • IDOR
  • Mass assignment
  • tRPC public mutations
  • Client-side auth
  • Server actions w/o auth
  • Horizontal escalation
40+
patterns

Secrets

Live API keys committed to repos, NEXT_PUBLIC_ leaks, service_role in client bundles, weak/default JWT secrets ('supersecretkey').

  • AWS · Stripe · OpenAI
  • Anthropic · Google
  • GitHub · GitLab · npm
  • Slack · SendGrid · Resend
  • PlanetScale · Supabase
  • Weak/default values
10+
patterns

AI / LLM

Emerging class — prompt injection via user input, missing max_tokens (LLMjacking), API key in browser, agent tools wrapping exec/eval.

  • Prompt injection
  • No max_tokens (cost DoS)
  • Key in client bundle
  • Missing rate limit
  • Agent tool → RCE
  • eval(model output)
8+
patterns

SSRF

fetch/axios/got/ky/needle/superagent with user-controlled URLs, file:// / gopher:// smuggling, cloud-metadata IPs, DNS rebinding, stored webhook URLs.

  • fetch / axios / got
  • file / gopher / dict
  • 169.254.169.254
  • DNS rebinding
  • Stored webhook URLs
  • Redirect-chain bypass
50+
patterns

Vibe Stack

Review common integration risks in code built with Cursor, v0, Lovable and other assistants, from database access to payment webhooks.

  • Supabase RLS · service_role
  • Stripe webhook · price-from-body
  • Next.js server actions
  • Drizzle / Prisma footguns
  • Clerk / Auth.js gaps
  • Vercel AI SDK / OpenAI
Separate dependency checkerAST taint analysis across JS / TSCompliance readiness mapping20+ languages
Code security · Clear findings · Verified fixes

From code to a clearer release decision

Bring code review, exposed-secret checks and compliance readiness into your release workflow. Understand what was checked, prioritize the findings, and keep evidence of the fixes.

Layer 1 · Static Pattern Engine

Review supported source files for exposed credentials, injection patterns, risky Server Actions, Supabase access-control mistakes and Stripe webhook issues. Investigate findings in the context of your application.

Code patternsSecretsNext.jsSupabaseStripe

Layer 2 · Dataflow & AI Review

Trace supported JavaScript and TypeScript input-to-sink paths with AST analysis. AI review adds context for selected files when enabled by your plan and scan configuration. Validate each finding before applying a fix.

AST taintAttack chainsIDORSSRFPrompt-inj

Dependency Review

Use the dependency checker to look up supported npm package versions against OSV advisories and flag package names for manual review. Verify resolved versions in your lockfile; a clean result does not prove a package is safe.

npmOSV advisoriesPackage identityVersion review

Compliance Readiness

Map supported technical findings to readiness work across GDPR, NIS2, the EU AI Act and other frameworks. Use the results alongside organizational controls, legal review and your auditor's requirements.

GDPRNIS2AI ActDORASOC 2

AI Auto-Fix

Generate suggested patches for supported findings. Review the diff, test the change and use the GitHub workflow where configured. Re-scan to check the result before merging.

Diff previewBatch fixGitHub PR

Your Own Rules + External Engines

Add custom detection rules for patterns specific to your application. External scanner integrations require separate configuration; check which engines ran when interpreting a report.

Custom rulesConfigured integrationsScan scope

Evidence You Can Review

Share scan findings, reports and badges with the people reviewing your release. Scores describe the checks performed; they are not security certification or proof of compliance.

Scan reportsSecurity badgeReview evidence

How it works

Four steps from a security question to a reviewed fix. Scan time depends on project size and the analysis enabled.

01

Upload

Drop a .zip, paste a GitHub URL (public or private), or scan a live URL. 20+ languages supported: JS/TS, Python, Go, Rust, Java, C/C++, PHP, Ruby, .NET, Swift, Kotlin, Shell, plus IaC.

02

Scan

Run supported code and secret checks. Review the scan scope to see which analysis layers ran, including AST analysis and AI review when enabled.

03

Fix

Review findings and apply suggested fixes. Preview diffs, apply one-by-one or batch-fix all critical issues into a GitHub PR.

04

Verify

Test the changes, re-scan and share the findings with your team. Use technical evidence to support a broader security and compliance review.

Built for code shipped from

CursorChatGPTClaudev0LovableBoltCopilotReplit
Detection
500+ checks
OWASP Top 10 · CWE Top 25 · vibe-stack pack
Languages
20+ languages
JS · TS · Python · Go · Rust · Java · C/C++ · PHP · Ruby · .NET · Swift · Kotlin · Shell · SQL · IaC
Dependencies
Package review
Dedicated npm checker · OSV advisories · version review
Compliance
7 frameworks
GDPR · NIS2 · AI Act · DORA · PCI · SOC 2 · ISO 27001
Pricing

Pay once. Or get continuous support.

One-time scans for one-time problems. Monthly subscription only if you want continuous monitoring and alerts.

One-time
Vibe Check
$0

Built an MVP with Cursor? Check if it's safe.

  • Scan up to 10 files
  • Check for hardcoded secrets
  • Find missing API auth
  • Vibe Coding Security Score
Start Free Scan
Launch Audit
$49

Full AST analysis before you hit 'Deploy'.

  • Unlimited files & deep AST scan
  • Find all SSRF & SQLi flaws
  • Cursor / Claude hallucination check
  • Actionable human-readable report
  • PDF export for stakeholders
Audit My App
AI Auto-Fix (Coming Q1 2027)Most popular
$149

Cursor broke it. Our AI fixes it.

  • Everything in Launch Audit
  • 1-click PRs to fix vulnerabilities
  • Zod validation auto-generation
  • NextAuth / Supabase RLS fixes
  • Embeddable 'Safe to Use' badge
Fix My Code
Enterprise Ready (Coming Q1 2027)
$349

Your MVP just got a B2B client. Need SOC2?

  • Everything in Auto-Fix
  • SOC 2 & GDPR readiness check
  • Architecture flaw detection
  • Data privacy compliance report
  • Export bundle for your auditor
Get Enterprise Ready
Ongoing support
Ongoing Shield
$79/ month

Continuous protection on every git push.

  • Auto-scan on every push / PR
  • Auto-fix critical issues via PR
  • New CVE alerts in Slack / Discord
  • Monthly compliance drift report
  • Cancel anytime
Start 14-day Trial
Enterprise
Custom

For teams of 10+ developers.

  • Everything in Ongoing Shield
  • SAML / Okta SSO + RBAC
  • Dedicated workspace + custom rules
  • API access · CI/CD integration
  • 99.9% SLA · priority support
Talk to Sales

All one-time purchases include 30-day money-back guarantee. Subscriptions cancel anytime.

Questions before you ship

Clear answers. Better security decisions.

What Bryxe checks, where manual review matters, and how to turn findings into fixes.

What is Bryxe Shield?

Bryxe Shield is a security scanner for AI-generated code and modern SaaS projects. It checks supported source files for risky patterns and exposed secrets, checks supported dependencies for known vulnerabilities, and helps developers prioritize findings. It is built for teams working with tools such as Cursor, Claude Code, ChatGPT, Lovable and GitHub Copilot.

How do I check whether AI-generated code is safe to deploy?

Scan the code, review high-impact findings, and test the application with separate user accounts. Check authorization on server endpoints, database access policies, secret handling, payment verification and dependencies. Then test fixes and repeat the scan. A clean scan is useful evidence, but cannot prove that an application is secure.

Can Bryxe scan projects built with Cursor, Claude Code or Lovable?

Yes. Bryxe analyzes the code you provide, regardless of which assistant helped write it. Supported checks include patterns used in Next.js, Supabase and Stripe projects. Coverage depends on the language, file type and scan mode; a repository scan can inspect more context than a pasted snippet.

What is the difference between a code scan and a live website scan?

A code scan examines supplied source files and supported dependency manifests. A live website scan examines the publicly accessible response and assets it can retrieve. It cannot see private backend code or establish whether your live database policies are correct. Use source review and runtime testing together.

Does Bryxe check Supabase RLS and Stripe webhooks?

Bryxe includes checks for risky Supabase and Stripe code patterns, including exposed privileged keys and missing webhook verification patterns. Source findings are a starting point: test RLS using actual database roles and verify webhook signatures and duplicate-event handling in a test environment.

Is a compliance readiness report a certification?

No. Mapping technical findings to GDPR, NIS2, the EU AI Act, DORA, PCI DSS, SOC 2 or ISO 27001 can support readiness work. These regulations, standards and assurance frameworks have different scopes. Code scanning does not establish legal compliance, replace an audit, or issue a certification.

Do I need to give Bryxe access to my private repository?

Choose the scan input appropriate for your project: the public tools accept selected snippets or manifests, while the application supports repository and ZIP workflows. Review the Security and Privacy pages before supplying proprietary code. Replace live credentials with placeholders in examples; detection of a leaked credential should be followed by rotation with its provider.

What should I do first after a security scan?

First contain exposed credentials and reachable authorization or payment flaws. Confirm each finding in context, assign an owner, make the smallest safe fix and add a regression check. Re-scan the changed code and retain the result alongside the tested commit. A severity score helps triage; exposure and business impact determine urgency.

Can a scanner replace a penetration test or security review?

No. Automated checks are repeatable and useful during development, but can miss business-logic issues, production configuration and attacks that require runtime context. Use them alongside code review, authorization tests and a risk-appropriate independent security assessment.

Can I try Bryxe for free?

Yes. Start with the free scan or a focused tool for AI code, dependency checks or environment-variable exposure. Scan limits and additional capabilities depend on the current plan. The pricing section lists the available options before you choose a paid audit.

Explore the security guides, read our data handling details, or contact Bryxe.

Scan your code now

First scan is free. ZIP, GitHub URL, or paste a snippet. See exactly what your AI shipped — and how to fix it.

Source code processed in memory · deleted after the scan completes.