AI Pentester & Code Security Scanner | Scan your GitHub repo free, Nurbak

PRIVATE AI SECURITY

Your code is too sensitive to send to a third-party AI

Nurbak is an AI pentester with its own model. It finds vulnerabilities like a senior analyst, your code never goes to OpenAI or Anthropic, and we store nothing after the analysis.

For banks, fintech, insurance, healthcare, government and companies with sensitive IP that cannot send their code to OpenAI or Anthropic.

Create account and connect GitHub

We never store your code. We only write when you ask for a fix PR. You pay only if you want the detail or continuous monitoring.

Open source project? Request a free scan →

Own modelEphemeral infraZero retentionSigned audit trailNo third-party AI APIs

Teams that already trust Nurbak

BocadiumTiendliCuidaliZuomy

THE PROBLEM

AI security asks for the one thing you can't give: your code

01

Legal blocks it

You can't send your code to OpenAI or Anthropic. Compliance blocks it and you're left without AI.

02

Noisy SAST

Your scanner throws 500 findings and can't tell which one is actually exploitable.

03

Expensive, one-off pentests

USD 10–30K per engagement, once or twice a year, expiring at the next release.

04

The AI that promises to fix it takes your code

Even the leading tools send your code, or the reasoning, to a third party.

THE SOLUTION

Our model, on ephemeral infra. Nothing is stored.

An AI security agent reasons over your repository, architecture, dependencies, authentication, business logic and multi-file vulnerabilities, prioritizes by real exploitability and hands you the remediation. It runs on our Whitehat model on ephemeral infra: the code is deleted when it finishes, with signed proof that nothing was stored.

HOW IT WORKS

From connecting the repo to a real risk in hours

1

Create your account and connect GitHub.

2

We spin up ephemeral infra with our Whitehat model, just for your analysis.

3

The agent maps the architecture, analyzes the code and correlates findings.

4

You get risks prioritized by exploitability, with remediation, in your Jira.

5

Download the signed audit trail for your auditor.

SEE NURBAK IN ACTION

From connected repo to fix, in one place

Nurbak dashboard with the repo security score and issues by severity

YOUR DASHBOARD

Your security score in minutes

Connect GitHub and see each repo's health from 0 to 100, how many issues there are by severity, which files are affected and the next steps to close them.

Nurbak findings list with severity, file and category

FINDINGS

Every vulnerability, with file and severity

Exposed credentials, dependencies with known CVEs, secrets left in git history, IDOR, mass assignment and more. Ranked by severity and grouped by type and language.

Nurbak finding detail with a plain-language explanation and evidence

DETAIL AND FIX

Explained in plain words, fixed with a PR

Every finding tells you what it means in plain words, what could happen, the technical evidence with CVEs and how to fix it. With one click, Nurbak opens the Pull Request with the change and a security test.

Pull Request opened by Nurbak on GitHub with the security fix and its test

THE PR IN YOUR REPO

The fix arrives as a Pull Request, ready to review

Nurbak opens the PR on a new branch with the smallest change, a summary of what was wrong and a test that fails before the fix and passes after it. It never touches your main branch: you review it and merge it.

SECURITY AND PRIVACY

Ephemeral infra: your code lives only as long as the analysis. Period.

  • Own model (Whitehat): your code never passes through OpenAI, Anthropic or any third-party API.
  • Ephemeral infra: each analysis spins up a fresh instance that is destroyed when it ends.
  • Hash-chain audit trail proving which model analyzed it and that nothing was stored.
  • Zero retention: the code is deleted post-analysis; we only keep the report.
  • Encrypted in transit and in memory; we never write your code to persistent disk.

WHITE / GRAY / BLACK BOX

One agent, three depths

White box generates hypotheses; gray and black box confirm them.

WHITE BOX

White box

Repo + code + configuration

SQLi, XSS, SSRF, secrets, authz/IDOR, business logic and multi-file vulnerabilities.

GRAY BOX

Gray box

Endpoints + test credentials + architecture

Confirms the real exploitability of what white box suspects.

BLACK BOX

Black box

Only the exposed target, no code

Validates from the outside like an attacker and discovers backends and infrastructure.

NOT A SCANNER

A security analyst, not a list of rules

It maps the architecture, forms attack hypotheses, gathers evidence, correlates findings, determines impact, prioritizes and proposes the fix. After the fix, it re-analyzes.

BLOG

Security guides for teams that ship code

See all articles →
Security

What Is an SBOM? Software Bill of Materials Explained

An SBOM is the ingredient list of your software: every library, version and supplier in a machine-readable file. Here is what goes inside one, why regulators now ask for it, CycloneDX vs SPDX, how to generate one with Syft, cdxgen or GitHub, and how to actually use it.

Security

Vulnerability Assessment vs Penetration Testing: Differences and When to Use Each

A vulnerability assessment finds and ranks as many weaknesses as possible. A penetration test proves what an attacker can actually do with them. Here is a clear comparison (goal, depth, exploitation, frequency, automation, cost and output), when to use each, and how continuous code-level assessment fits between pentests.

Security

Secret Scanning Tools: TruffleHog vs Gitleaks vs GitGuardian vs GitHub

A fair comparison of the main secret scanning tools: what TruffleHog, Gitleaks, GitGuardian and GitHub secret scanning actually do, which are open source, which verify live secrets, how they handle git history, and how to rotate and purge a leaked key the right way.

ENTERPRISE

Ready for your infrastructure and your compliance

Own model, ephemeral infra and signed evidence for your auditor.

RBAC + SSO

SAML/OIDC and role-based access control.

Audit logs + model provenance

Which model analyzed what and when, with signed evidence.

Ephemeral infra + zero retention

The instance dies with the analysis. Signed proof that nothing was kept.

Integrations

SIEM, Jira, GitHub/GitLab and Slack/Teams.

Compliance reporting

Turns findings into evidence for PCI, HIPAA or SOC 2.

Own model

Whitehat, our own model. No third-party APIs.

NURBAKOPEN SOURCE

Maintain an open source project?

Request a free scan of your public repo with the same model. Create your account, send the repo and we review it and run the scan.

Request an open source scan

PRICING

The scan is free. You pay for the detail.

See your score for free. When you want file, line and fix, plus automatic daily scans, pick a plan. Everything included.

FREE

Scan

USD 0per repo

To know where you stand.

  • Score and count by severity
  • Affected categories
  • Badge for the README (OSS)
  • 1 scan per repo per week
Scan now
EVERYTHING INCLUDED

1 repo

USD 79per month

Everything included for one project.

  • Automatic daily scan
  • Every finding with file, line and fix
  • AI fix delivered as a Pull Request
  • Alerts, history and signed audit trail
Get started
BEST VALUEUp to 5 repos
USD 199per month

Everything included for your team. USD 40 per repo.

  • Automatic daily scan of every repo
  • Every finding with file, line and fix
  • AI fix delivered as a Pull Request
  • Alerts, history and signed audit trail
Get started

More than 5 repos or on your own infrastructure

Enterprise with SSO, SIEM, compliance reporting and on-premise deployment.

Talk to sales

We charge per repo, not per developer: add teammates without changing the bill. Reference: a manual pentest costs USD 10–30K. Open source: the public report and the badge are always free. Enterprise with SSO, SIEM and compliance reporting: get in touch.