appsec — independent software & tools
-
Aivist-Verify
A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
-
Velonus
AI-native security copilot for Python developers. Scans for secrets, vulnerabilities, and dependency CVEs — then tells you how to fix them.
-
draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
-
triagekit
Backend-free repo triage in one self-contained HTML file — GitHub Dependabot alerts, code scanning, PRs & issues, scored and tiered. No server, no CDN; your token stays in the browser.
-
pinprick
Pin your GitHub Actions. Prick holes in their supply chain security.
-
pypi-security-best-practices
Secure your Python supply chain with this curated list of best practices for safe package installation, vulnerability scanning, and dependency management.
-
entropy-chaos
Test APIs by generating custom attack scenarios using large language models to uncover logic flaws beyond standard scanners.