SecAudit Agent

An AI agent that audits your web app for security problems and hands you the exact fix.

Enter a site you own. The agent explores it in a real browser, runs safe read-only checks, looks up known vulnerabilities, and writes a fix for every finding using NVIDIA Nemotron on Nebius.

How it works

  1. 1Verify ownership
  2. 2Explore
  3. 3Check
  4. 4Look up CVEs
  5. 5Write fixes
  6. 6Report

Every step streams to the page as it happens, so you can watch the agent work. A typical scan takes under two minutes.

What it does

  • Explores your app like a real browser

    Loads the site in headless Chromium, so JavaScript-heavy apps work, and maps pages, forms, API calls, headers and cookies. It follows same-site links one level deep, up to 15 pages.

  • Runs safe, non-destructive checks

    Security headers (CSP, HSTS, clickjacking, nosniff), cookie flags, TLS certificate and HTTPS redirect, mixed content, CORS misconfiguration, and software version disclosure.

  • Looks up known vulnerabilities

    For every software version your site reveals, Tavily searches vulnerability databases (NVD, GitHub Advisories, OSV, Snyk) and Nemotron keeps only the CVEs whose affected range includes that exact version. A CVE is only reported if it appears in the sources, and severity comes from the published CVSS score.

  • Writes the fix for every finding

    NVIDIA Nemotron explains each issue in plain language and writes concrete steps, code and config snippets for the stack it detected (nginx, Express, Django…), and a command to verify the fix.

  • Produces a report you can act on

    Findings with CVSS-based severity, reproduction steps, redacted evidence, business impact and references, as a web page, PDF or Markdown.

  • Checks you're allowed to scan

    You prove you control a site with a DNS TXT record, a token file, or a meta tag before it can be scanned. Every scan attempt is logged with time, target, consent and IP address.

What it does not do

  • Scan sites you haven't verified

    Unverified targets are refused. Verification lasts 7 days.

  • Attack, overload or change anything

    It never runs denial-of-service, fuzzing, password guessing or exploitation. It only sends read-only requests (GET, HEAD, OPTIONS), rate-limited to 2 per second, a handful per scan.

  • Reach private networks

    Hosts that resolve to private, loopback or reserved addresses are blocked for the target, the scanner's own requests, and every request the browser makes.

  • Keep your data

    Response bodies, cookie values and credentials are never stored, and evidence is redacted. Only a software name and version are sent to Tavily, never your URL.

  • Test behind a login

    It scans what an anonymous visitor can reach. Logged-in pages and access control between users aren't tested.

  • Replace a penetration test

    It finds common, detectable issues. A clean result means these checks passed, not that the application is secure.

Tech stack

AI reasoning
NVIDIA Nemotron 3 Super (120B-A12B) on Nebius Token Factory, via its OpenAI-compatible API
Vulnerability intel
Tavily Search API, limited to NVD, GitHub Advisories, OSV, Snyk and CVE.org
Browser engine
Playwright 1.63 driving headless Chromium
Backend
Python 3.12 · FastAPI · Server-Sent Events · httpx · dnspython · Pydantic 2
Reports
Jinja2 HTML (auto-escaped) · PDF printed by Chromium · Markdown
Frontend
Next.js 16 (static export) · React 19 · Tailwind CSS 4
Hosting
nginx · systemd · Ubuntu 24.04 · Let's Encrypt TLS