An AI pentester for your source code. Connect a GitHub repo, get a security score and concrete findings, and fix them with a Pull Request.
Nurbak reads your repository and looks for vulnerabilities the way a pentester would: it combines its own self-hosted AI model, Whitehat, with deterministic checks for dependencies, risky code patterns and leaked secrets. Your code is analyzed on ephemeral infrastructure, is never sent to third-party AIs during the scan, and is deleted when the scan ends.
Sign up at watch.nurbak.com.
Nurbak connects to GitHub through the Nurbak GitHub App. When you install it, GitHub lets you choose which repositories the app can see: all of them or only the ones you select.
Only GitHub is supported today. GitLab and Bitbucket are not.
Choose the repo you want to scan. Public and private repositories both work. Archived repositories are hidden from the list.
The scan starts right away and the report appears in your panel when it finishes.
Each scan runs two kinds of analysis over the same copy of your code. Files are prioritized by risk, so the most sensitive parts of the code are reviewed first.
| Check | What it looks for |
|---|---|
| Whitehat AI review | Vulnerabilities that need context to spot, the kind a pentester finds by reading the code. Runs on Nurbak's own model. |
| Dependency audit | Known vulnerabilities in your dependencies, checked against OSV.dev. Only the package name and version leave our infrastructure, never your code. |
| Code rules | Pattern-based detection of risky constructs and insecure CI configuration. |
| Secrets in code | API keys, tokens and credentials that match known secret patterns in the current code. |
| Secrets in git history | Secrets committed in the last 50 commits, even if they were later removed from the code. |
| Critical code without tests | Sensitive code paths that have no tests covering them. |
The report opens with a score from 0 to 100, where 100 is best. Every finding lowers it, weighted by severity. The score maps to a grade:
| Score | Grade |
|---|---|
| 90 to 100 | A |
| 80 to 89 | B |
| 70 to 79 | C |
| 60 to 69 | D |
| 0 to 59 | F |
Any critical finding caps the score at 49 (grade F), and five or more high findings cap it at 74, so a serious issue is never hidden behind many passing checks.
Each finding includes:
From any finding you can ask Nurbak to fix it. Nurbak generates the change (and a regression test where it applies) and opens a Pull Request on your repository. The PR is written in English and signed by Nurbak, so you review and merge it like any other contribution.
Not every finding gets a PR. Dependency findings need a version bump and git history findings need the secret to be rotated, so for those Nurbak gives you the steps instead of a Pull Request.
| Plan | Price | What you get |
|---|---|---|
| Free | USD 0 | Security score, the 3 most important findings in full and 1 free fix Pull Request. |
| 1 repo | USD 79/month | Full report, fix Pull Requests and daily re-scans for 1 repository. |
| Up to 5 repos | USD 199/month | Everything above for up to 5 repositories. |
| Enterprise | Custom | More than 5 repositories. Contact us. |
See the pricing page for the current details.
Every scan comes with a downloadable JSON log of every AI interaction: what was sent, to which model and when. You can hand it to your security team or an auditor as proof of where your code went. If you opt in to a fix Pull Request, that request appears in the same log.
More detail on the security page.
Go to your profile page in the panel and disconnect GitHub. That uninstalls the Nurbak GitHub App access, so Nurbak can no longer read your repositories or open Pull Requests.
No. The code is used during the scan and deleted when it ends. What we keep is the result: the score and the findings (severity, CWE, file, line, description and recommendation), plus your account data.
No. The write permission is used only to open a fix Pull Request when you request it. Nothing is merged for you: you review the PR and decide.
Yes. Public and private GitHub repositories are supported. Archived repositories are hidden.
Not yet. Nurbak works with GitHub only.
Paid plans re-scan the repository every day, so new issues show up without you doing anything.
Because the fix is to upgrade the package to a version without the vulnerability, and secrets found in git history need to be rotated. The report tells you what to do in both cases.
Connect GitHub and Nurbak analyzes your repo with its own AI: exploitable vulnerabilities with file and line, and the fix ready as a Pull Request.
Your code never goes to OpenAI or Anthropic. No credit card.