SecAudit Agent
An AI agent that audits your web app for security problems and hands you the exact fix.
Enter a site you own. The agent explores it in a real browser, runs safe read-only checks, looks up known vulnerabilities, and writes a fix for every finding using NVIDIA Nemotron on Nebius.
How it works
- 1Verify ownership
- 2Explore
- 3Check
- 4Look up CVEs
- 5Write fixes
- 6Report
Every step streams to the page as it happens, so you can watch the agent work. A typical scan takes under two minutes.
What it does
- Explores your app like a real browser
Loads the site in headless Chromium, so JavaScript-heavy apps work, and maps pages, forms, API calls, headers and cookies. It follows same-site links one level deep, up to 15 pages.
- Runs safe, non-destructive checks
Security headers (CSP, HSTS, clickjacking, nosniff), cookie flags, TLS certificate and HTTPS redirect, mixed content, CORS misconfiguration, and software version disclosure.
- Looks up known vulnerabilities
For every software version your site reveals, Tavily searches vulnerability databases (NVD, GitHub Advisories, OSV, Snyk) and Nemotron keeps only the CVEs whose affected range includes that exact version. A CVE is only reported if it appears in the sources, and severity comes from the published CVSS score.
- Writes the fix for every finding
NVIDIA Nemotron explains each issue in plain language and writes concrete steps, code and config snippets for the stack it detected (nginx, Express, Django…), and a command to verify the fix.
- Produces a report you can act on
Findings with CVSS-based severity, reproduction steps, redacted evidence, business impact and references, as a web page, PDF or Markdown.
- Checks you're allowed to scan
You prove you control a site with a DNS TXT record, a token file, or a meta tag before it can be scanned. Every scan attempt is logged with time, target, consent and IP address.
What it does not do
- Scan sites you haven't verified
Unverified targets are refused. Verification lasts 7 days.
- Attack, overload or change anything
It never runs denial-of-service, fuzzing, password guessing or exploitation. It only sends read-only requests (GET, HEAD, OPTIONS), rate-limited to 2 per second, a handful per scan.
- Reach private networks
Hosts that resolve to private, loopback or reserved addresses are blocked for the target, the scanner's own requests, and every request the browser makes.
- Keep your data
Response bodies, cookie values and credentials are never stored, and evidence is redacted. Only a software name and version are sent to Tavily, never your URL.
- Test behind a login
It scans what an anonymous visitor can reach. Logged-in pages and access control between users aren't tested.
- Replace a penetration test
It finds common, detectable issues. A clean result means these checks passed, not that the application is secure.
Tech stack
- AI reasoning
- NVIDIA Nemotron 3 Super (120B-A12B) on Nebius Token Factory, via its OpenAI-compatible API
- Vulnerability intel
- Tavily Search API, limited to NVD, GitHub Advisories, OSV, Snyk and CVE.org
- Browser engine
- Playwright 1.63 driving headless Chromium
- Backend
- Python 3.12 · FastAPI · Server-Sent Events · httpx · dnspython · Pydantic 2
- Reports
- Jinja2 HTML (auto-escaped) · PDF printed by Chromium · Markdown
- Frontend
- Next.js 16 (static export) · React 19 · Tailwind CSS 4
- Hosting
- nginx · systemd · Ubuntu 24.04 · Let's Encrypt TLS