Documentation | Nurbak

Nurbak documentation

An AI pentester for your source code. Connect a GitHub repo, get a security score and concrete findings, and fix them with a Pull Request.

Nurbak reads your repository and looks for vulnerabilities the way a pentester would: it combines its own self-hosted AI model, Whitehat, with deterministic checks for dependencies, risky code patterns and leaked secrets. Your code is analyzed on ephemeral infrastructure, is never sent to third-party AIs during the scan, and is deleted when the scan ends.

Getting started

1. Create your account

Sign up at watch.nurbak.com.

2. Connect GitHub

Nurbak connects to GitHub through the Nurbak GitHub App. When you install it, GitHub lets you choose which repositories the app can see: all of them or only the ones you select.

Only GitHub is supported today. GitLab and Bitbucket are not.

3. Pick a repository

Choose the repo you want to scan. Public and private repositories both work. Archived repositories are hidden from the list.

The scan starts right away and the report appears in your panel when it finishes.

What gets scanned

Each scan runs two kinds of analysis over the same copy of your code. Files are prioritized by risk, so the most sensitive parts of the code are reviewed first.

GitHub repo (via Nurbak GitHub App) | v Ephemeral GPU infrastructure +-- Whitehat (Nurbak's self-hosted AI model) +-- Deterministic checks | v Report: score + findings (your code is deleted)
CheckWhat it looks for
Whitehat AI reviewVulnerabilities that need context to spot, the kind a pentester finds by reading the code. Runs on Nurbak's own model.
Dependency auditKnown vulnerabilities in your dependencies, checked against OSV.dev. Only the package name and version leave our infrastructure, never your code.
Code rulesPattern-based detection of risky constructs and insecure CI configuration.
Secrets in codeAPI keys, tokens and credentials that match known secret patterns in the current code.
Secrets in git historySecrets committed in the last 50 commits, even if they were later removed from the code.
Critical code without testsSensitive code paths that have no tests covering them.

Reading the report

Security score

The report opens with a score from 0 to 100, where 100 is best. Every finding lowers it, weighted by severity. The score maps to a grade:

ScoreGrade
90 to 100A
80 to 89B
70 to 79C
60 to 69D
0 to 59F

Any critical finding caps the score at 49 (grade F), and five or more high findings cap it at 74, so a serious issue is never hidden behind many passing checks.

Findings

Each finding includes:

Fix Pull Requests

From any finding you can ask Nurbak to fix it. Nurbak generates the change (and a regression test where it applies) and opens a Pull Request on your repository. The PR is written in English and signed by Nurbak, so you review and merge it like any other contribution.

  1. Open the finding and click the button to create the fix PR.
  2. Confirm. Generating a fix is opt-in: the confirmation tells you which file is sent to generate the fix and which AI model handles it. The rest of your code does not leave, and the request is recorded in your audit trail.
  3. The panel updates by itself while the fix is generated. When it is ready you get a link to the PR.

Not every finding gets a PR. Dependency findings need a version bump and git history findings need the secret to be rotated, so for those Nurbak gives you the steps instead of a Pull Request.

Plans and limits

PlanPriceWhat you get
FreeUSD 0Security score, the 3 most important findings in full and 1 free fix Pull Request.
1 repoUSD 79/monthFull report, fix Pull Requests and daily re-scans for 1 repository.
Up to 5 reposUSD 199/monthEverything above for up to 5 repositories.
EnterpriseCustomMore than 5 repositories. Contact us.

See the pricing page for the current details.

Privacy and audit trail

Audit trail

Every scan comes with a downloadable JSON log of every AI interaction: what was sent, to which model and when. You can hand it to your security team or an auditor as proof of where your code went. If you opt in to a fix Pull Request, that request appears in the same log.

More detail on the security page.

Disconnecting GitHub

Go to your profile page in the panel and disconnect GitHub. That uninstalls the Nurbak GitHub App access, so Nurbak can no longer read your repositories or open Pull Requests.

FAQ

Does Nurbak store my code?

No. The code is used during the scan and deleted when it ends. What we keep is the result: the score and the findings (severity, CWE, file, line, description and recommendation), plus your account data.

Can Nurbak change my code without asking?

No. The write permission is used only to open a fix Pull Request when you request it. Nothing is merged for you: you review the PR and decide.

Does it work with private repositories?

Yes. Public and private GitHub repositories are supported. Archived repositories are hidden.

Do you support GitLab or Bitbucket?

Not yet. Nurbak works with GitHub only.

How often is my repo scanned?

Paid plans re-scan the repository every day, so new issues show up without you doing anything.

Why doesn't a dependency finding have a fix PR?

Because the fix is to upgrade the package to a version without the vulnerability, and secrets found in git history need to be rotated. The report tells you what to do in both cases.

Requirements

  • A GitHub account that can install the Nurbak GitHub App on the repository
  • A repository that is not archived, public or private
  • A free Nurbak account at watch.nurbak.com

Find the vulnerabilities in your code before an attacker does

Connect GitHub and Nurbak analyzes your repo with its own AI: exploitable vulnerabilities with file and line, and the fix ready as a Pull Request.

Your code never goes to OpenAI or Anthropic. No credit card.