One platform · two command centersSee the platform

Find it. Prove it. Fix it.

One platform for authorized offensive research and the AI in your codebase — every finding backed by tamper-evident evidence. Break in with proof. Lock down with proof.

2 command centers
one platform
100%
actions audited
OWASP LLM
top-10 mapped
scopesafe — acme-corp workspace
Workspace
Programs
Findings12
Evidence
Reports
r. okafor
pro
scope classify api.acme.com
matched *.acme.com
IN SCOPE
FindingSeverityScopeStatus
IDOR on /v1/ordersHighin-scopetriaged
Stored XSS — profileHighin-scopedraft
Auth bypass (SSO)Critin-scopesubmitted
Rate-limit gapLowin-scopereview
chaina1f97c2ee4b0
tamper-evident · verified
Tamper-evident audit OWASP LLM Top 10 Encrypted at rest
One platform · two command centers

The proof layer for security work.

Break in or lock down — ScopeSafe backs both with the same tamper-evident spine. Pick the command center for the work in front of you.

ScopeSafe ResearchFor researchers & pentest teams

Authorized offensive research, scope to payout.

A command center for bug-bounty and pentest work. A scope guard blocks out-of-bounds targets, every action lands on a hash-chained audit trail, evidence is sealed in an encrypted vault, and reports export submission-ready — tracked through to payout.

  • Scope guard, on by default
  • Tamper-evident evidence & reports
  • Import H1 · Intigriti · export Jira · GitHub
Explore Research
ScopeSafe AIFor AppSec & security engineering

Know every AI in your codebase. Prove it's safe to ship.

The open-source aibom scanner builds an AI Bill of Materials — every agent, model, tool, and MCP server — with findings mapped to the OWASP LLM Top 10. Track new / recurring / resolved across scans, and gate risky PRs in CI before they merge.

  • AI-BOM: agents, models, tools, MCP
  • OWASP LLM Top 10 findings
  • Fail the build on new critical risk
Explore AI Security

Same tamper-evident audit, encrypted storage, and roles across both. Start with either — one account covers the platform.

Imports scope from · exports findings to
HackerOneIntigritiGitHubJiraSlackMicrosoft TeamsCSV ImportBugcrowd
ScopeSafe Research

Everything from scope to submission, in one place.

A local-first command center for authorized research — not an autonomous tool. You stay in control; it keeps you in scope and on the record.

Scope guard, on by default

Every target is classified against the program's rules before you touch it. Out-of-scope work is blocked, with a clear reason — so you stay authorized, always.

api.acme.comIN SCOPE
blog.partner.ioBLOCKED

Tamper-evident audit trail

Every consequential action is appended to a SHA-256 hash-chained log. Break a link and verification fails — your evidence holds up.

Encrypted evidence vault

Files are sealed with AES-256-GCM before they ever hit storage. Plaintext never leaves your process.

CVSS & validation

Score severity with a guided calculator and run a readiness checklist before you submit.

Duplicate detection

Catch overlap with prior findings before a triager does — and before you waste a write-up.

Reports that submit

Compose a clean report, export to GitHub or Jira, and track each submission to payout.

ScopeSafe Research · how it works

Five steps, every one on the record.

Connect a program

Import scope from HackerOne, Intigriti, or a CSV. Assets and rules land structured and ready for the scope guard.

console
$ import --platform hackerone
✓ 24 assets · 11 in-scope rules
ScopeSafe AI · powered by the open-source aibom

Know every AI in your codebase. Prove it's safe to ship.

The aibom scanner builds an AI Bill of Materials from your code — no execution, zero dependencies — then flags the risky parts and gates them in CI.

aibom — CI
$ pip install scopesafe-aibom && aibom . --upload
 
uploaded scan · project 'payments-service'
findings: 1 new, 4 recurring, 2 resolved
gate: fail — AGENT-001: agent has destructive tools without human approval

Agents & models

LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex and direct SDKs — including graph idioms and cross-file wiring.

MCP servers & tools

Every MCP server your repo wires in, with scope classification and capability tags: filesystem, exec, network, delete.

OWASP-mapped posture

Excessive agency, over-scoped servers, destructive tools without approval, hardcoded keys — mapped to the OWASP LLM Top 10.

PR gating

The platform diffs each scan against history — new, recurring, resolved — and fails the build on new critical findings.

Trust model

Built to hold up under scrutiny.

A pentest report or an AI Bill of Materials is only as valuable as it is defensible. Authorization, integrity, and confidentiality are the default across both command centers — not an afterthought.

Authorized & gated by design

A scope guard blocks out-of-bounds research; a CI gate blocks risky AI changes. Control surfaces, never autonomous tools.

Tamper-evident

Per-workspace SHA-256 hash-chained audit trail. Alter one entry and verification breaks.

Encrypted at rest

Evidence sealed with AES-256-GCM in your process; only ciphertext is ever written.

Keys you control

Argon2id-derived keys and independent vault/database subkeys keep a DB breach off your vault.

Pricing

Start free. Scale when it pays off.

MonthlyAnnual · 2 months free

Free

Everything to run authorized research, solo.

$0forever
Start free
Up to 3 programs, 50 findings
Scope guard + audit trail
CVSS, validation & dupes
Report compose + tracker
AI security: 1 project (aibom scans)
Encrypted evidence vault
Integrations & AI assist
Popular

Pro

For serious hunters who live in their pipeline.

$24/mo
billed annually
Start Pro
Unlimited programs & findings
Encrypted evidence vault
Slack, Teams, GitHub, Jira
Program import (H1, Intigriti)
AI security: 10 projects + PR gate
AI assist
Everything in Free

Team

Shared workspaces, roles, and review.

$83/mo
billed annually
Start Team
Teams, roles & RBAC
Reviewer workflow
Shared programs & findings
AI security: unlimited projects
Priority support
Audit-trail export
Everything in Pro

Enterprise

SSO, custom data residency & retention, and a dedicated success contact.

Talk to us

Security work you can put your name on.

Start free in minutes — run authorized research or scan your codebase for AI risk, with every finding backed by tamper-evident evidence.