Built for software built with AI

Ship at AI speed.Audit with confidence.

VibeCodeShield sends security-focused AI agents through your codebase, connects the context, and turns hidden risk into clear, verifiable findings.

GitHub read-onlyNo code executionSelected repositories only
acme-labs/northstar-api
EXAMPLE AUDIT
01export async function exportInvoice(req) {
02 const invoiceId = req.params.id;
03 const invoice = await db.invoice.findUnique({
04 where: { id: invoiceId }
05 });
06 return reply.send(invoice);
07}

Missing ownership check

CRITICAL

Invoice access is scoped by ID, not by the requesting account. Any authenticated user may export another account's invoice.

High confidenceBroken access controlline 4

18

Files reviewed

7

Findings

8m 42s

Audit time

One engine. Configurable providers.OpenAIOpenRouterAnthropicAuditable findings
Product

Security review that keeps up with the way you build.

From first connection to ongoing posture, every component is designed to make security review continuous, understandable, and affordable.

Reason across the repository

Agents trace authorization, data flow, configuration, and business logic across files—not just isolated patterns.

Persistent audit history

Projects, audit provenance, normalized findings, and review state remain available across completed reviews.

Audit on your rhythm

Run an audit on demand or enable a push-triggered review for the branch configured on a project.

Configurable AI providers

Use included VibeCodeShield AI or connect your own OpenAI, OpenRouter, or Anthropic key and spend 90% fewer credits.

Read-only by design

GitHub access is limited to reading selected repositories. V1 never writes changes or executes customer code.

Findings you can act on

Every issue includes severity, evidence, location, remediation guidance, and full audit provenance.

How it works

From repository to actionable findings.

V1 performs static review only. It never installs your dependencies or runs your application, tests, migrations, or repository scripts.

01

Connect a selected repository

Install our GitHub App with minimum read-only access. You choose exactly which repositories are in scope.

02

Build safe, ephemeral context

A temporary workspace inventories code, configuration, manifests, and architecture without executing customer code.

03

Run a security-focused agent

Select an enabled provider, model, and reasoning level. The platform records immutable audit provenance.

04

Validate and track findings

Review evidence, severity, confidence, and remediation guidance alongside project-level trends.

Security architecture

Your source is context, never inventory.

Repository contents are checked out into an ephemeral, constrained workspace. We persist findings and approved derived context—not a hidden copy of your repository.

Selected repos only
Read-only access
Ephemeral checkout
No code execution
Plans

Start small. Audit seriously.

One balance, with the exact charge shown before every audit. A Quick Scan currently uses 1 credit with DeepSeek Flash, 2 with DeepSeek Pro, or 0.1 with your own AI key. Agent Audit starts at 5 credits, or 0.5 with BYOK.

Free

For evaluating VibeCodeShield on one project with a safe monthly allowance.

€0/ month

Available now

  • 1 flexible audit credit / month
  • BYOK audits cost 90% fewer credits
  • 1 project
  • 1 audit at a time
  • Quick Scan
  • Connect your own AI key

Go

For solo builders securing a small portfolio with included AI and BYOK.

€24.99/ month

Available now

  • 25 flexible audit credits / month
  • BYOK audits cost 90% fewer credits
  • 5 projects
  • 1 audit at a time
  • Manual audits
  • Quick Scan + Agent Audit
  • Connect your own AI key
Best for teams

Pro

For teams that want security review to follow every release.

€49.99/ month

Available now

  • 50 flexible audit credits / month
  • BYOK audits cost 90% fewer credits
  • 25 projects
  • 2 parallel audits
  • Push-triggered audits
  • Quick Scan + Agent Audit
  • Connect your own AI key

Roadmap

Full Coverage

Scale

For growing teams with more repositories and throughput.

€99.99/ month

Available now

  • 100 flexible audit credits / month
  • BYOK audits cost 90% fewer credits
  • 50 projects
  • 2 parallel audits
  • Push-triggered audits
  • Quick Scan + Agent Audit
  • Connect your own AI key

Roadmap

Full Coverage · Security Simulation

Quick Scan is available on every plan. Agent Audit is available on eligible paid plans. Full Coverage and Security Simulation remain roadmap modes; availability and credit weights will be confirmed before release.

Make security part of the vibe.

We're opening VibeCodeShield to a small group of builders. Bring a real project, help shape the audit experience, and get launch pricing.

Open VibeCodeShield

Sign in with an authorized GitHub identity or an invited account.