Free · open source · runs offline

See every way in, before an attacker does.

apisec Surface is a free, open-source discovery tool that inventories every agent, MCP server, RAG pipeline, and API endpoint in your app, in one command. Nothing leaves your machine.

Modern apps have a bigger attack surface than most teams can see: AI agents, model gateways, provider keys, endpoints no one documented. Surface finds all of it and emits it as an AI-BOM, API-BOM, and S-BOM, then gates new high-risk findings right in your CI at PR time, so you catch exposure while it's still a diff, not after it's in production.

AI-BOM · API-BOM · S-BOM

Inventory, emitted at PR time

  • agents
  • MCP servers
  • RAG
  • LLM call sites
  • model gateways
  • provider keys
  • API endpoints
  • infrastructure

Private by design. Nothing leaves your environment, so mapping your own gaps costs you nothing but a command.


Free · open source

The Surface family.

Free, open-source tools that map your AI and application attack surface, from source code to live browser traffic to running agents. Every one runs in your environment.

Shipped

AI Surface

Find and govern the AI surfaces in your application code at PR time. A static source-code analyzer that detects LLM SDK call sites across 12 providers, agent frameworks (LangChain, LangGraph, CrewAI), MCP servers, model gateways, and AI infrastructure, flagging 13 risk indicators. Runs 100% locally, ships as a GitHub Action.

Shipped

APIsec Bolt Code Discovery

Find every API endpoint hiding in your source code before it ships. A GitHub Action that detects frameworks (Spring Boot, FastAPI, Flask, ASP.NET Core, and more), generates an OpenAPI 3.0 spec from your code, and raises a PR, catching undocumented and shadow endpoints in CI, not production.

Shipped

APIsec Bolt Browser Extension

Discover your full API attack surface directly from your browser, no proxies, agents, or setup. Bolt captures live API traffic, filters out the noise, and builds a real-time inventory of endpoints and parameters. Export clean OpenAPI specs in one click.

Apache 2.0Get it →
Shipped

MCP audit

See what your AI agents can actually access before attackers do. Scan Model Context Protocol configurations for exposed secrets, shadow APIs, and undeclared AI models, then generate AI-BOMs for compliance and governance. Maps your agent trust boundaries so you can find misconfigurations and over-permissioned connections.

Coming soon

App Surface

Find the application and API surface in your source code at PR time. A static analyzer that maps endpoints, routes, and parameters straight from code, so undocumented and shadow surface shows up before production.

MITComing soon
Coming soon

Agent audit

Audit AI agents for exploitable authorization and access-control gaps across agent identities and tool calls, before they ship.

MITComing soon
What the map tells you, and doesn't

You mapped it. You still don't know what's exploitable.

Surface can show you 347 endpoints and 2,814 candidate paths. It cannot tell you which of them an attacker can actually reach. That gap between a candidate and a proof is the whole job of the Platform. A map is where the hunt for exploits begins, not where the work ends.


Take it up the chain

A report your CISO will act on.

The AI-BOM, API-BOM, and S-BOM export as a shareable summary: what's running, where the risk concentrates, and what a validation pass would prove. Forward it, drop it in the board deck, or attach it to the budget request.

You found the surface. This is how you make the case for proving it.

Shareable

Export the summary

One page: surface inventory, risk concentration, and the exploitability questions still open. Built to send to whoever signs off.

Map then prove

A map without proof is just another list.

Surface maps, free and static, at PR time. apisec proves, at runtime. Two motions, one arc.