Free · open source
The Surface family.
Free, open-source tools that map your AI and application attack surface, from source code to live browser traffic to running agents. Every one runs in your environment.
Shipped
AI Surface
Find and govern the AI surfaces in your application code at PR time. A static source-code analyzer that detects LLM SDK call sites across 12 providers, agent frameworks (LangChain, LangGraph, CrewAI), MCP servers, model gateways, and AI infrastructure, flagging 13 risk indicators. Runs 100% locally, ships as a GitHub Action.
Shipped
APIsec Bolt Code Discovery
Find every API endpoint hiding in your source code before it ships. A GitHub Action that detects frameworks (Spring Boot, FastAPI, Flask, ASP.NET Core, and more), generates an OpenAPI 3.0 spec from your code, and raises a PR, catching undocumented and shadow endpoints in CI, not production.
Shipped
APIsec Bolt Browser Extension
Discover your full API attack surface directly from your browser, no proxies, agents, or setup. Bolt captures live API traffic, filters out the noise, and builds a real-time inventory of endpoints and parameters. Export clean OpenAPI specs in one click.
Shipped
MCP audit
See what your AI agents can actually access before attackers do. Scan Model Context Protocol configurations for exposed secrets, shadow APIs, and undeclared AI models, then generate AI-BOMs for compliance and governance. Maps your agent trust boundaries so you can find misconfigurations and over-permissioned connections.
Coming soon
App Surface
Find the application and API surface in your source code at PR time. A static analyzer that maps endpoints, routes, and parameters straight from code, so undocumented and shadow surface shows up before production.
Coming soon
Agent audit
Audit AI agents for exploitable authorization and access-control gaps across agent identities and tool calls, before they ship.