Find it. Prove it. Fix it.
One platform for authorized offensive research and the AI in your codebase — every finding backed by tamper-evident evidence. Break in with proof. Lock down with proof.
The proof layer for security work.
Break in or lock down — ScopeSafe backs both with the same tamper-evident spine. Pick the command center for the work in front of you.
Authorized offensive research, scope to payout.
A command center for bug-bounty and pentest work. A scope guard blocks out-of-bounds targets, every action lands on a hash-chained audit trail, evidence is sealed in an encrypted vault, and reports export submission-ready — tracked through to payout.
- Scope guard, on by default
- Tamper-evident evidence & reports
- Import H1 · Intigriti · export Jira · GitHub
Know every AI in your codebase. Prove it's safe to ship.
The open-source aibom scanner builds an AI Bill of Materials — every agent, model, tool, and MCP server — with findings mapped to the OWASP LLM Top 10. Track new / recurring / resolved across scans, and gate risky PRs in CI before they merge.
- AI-BOM: agents, models, tools, MCP
- OWASP LLM Top 10 findings
- Fail the build on new critical risk
Same tamper-evident audit, encrypted storage, and roles across both. Start with either — one account covers the platform.
Everything from scope to submission, in one place.
A local-first command center for authorized research — not an autonomous tool. You stay in control; it keeps you in scope and on the record.
Scope guard, on by default
Every target is classified against the program's rules before you touch it. Out-of-scope work is blocked, with a clear reason — so you stay authorized, always.
Tamper-evident audit trail
Every consequential action is appended to a SHA-256 hash-chained log. Break a link and verification fails — your evidence holds up.
Encrypted evidence vault
Files are sealed with AES-256-GCM before they ever hit storage. Plaintext never leaves your process.
CVSS & validation
Score severity with a guided calculator and run a readiness checklist before you submit.
Duplicate detection
Catch overlap with prior findings before a triager does — and before you waste a write-up.
Reports that submit
Compose a clean report, export to GitHub or Jira, and track each submission to payout.
Five steps, every one on the record.
Connect a program
Import scope from HackerOne, Intigriti, or a CSV. Assets and rules land structured and ready for the scope guard.
Know every AI in your codebase. Prove it's safe to ship.
The aibom scanner builds an AI Bill of Materials from your code — no execution, zero dependencies — then flags the risky parts and gates them in CI.
Agents & models
LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex and direct SDKs — including graph idioms and cross-file wiring.
MCP servers & tools
Every MCP server your repo wires in, with scope classification and capability tags: filesystem, exec, network, delete.
OWASP-mapped posture
Excessive agency, over-scoped servers, destructive tools without approval, hardcoded keys — mapped to the OWASP LLM Top 10.
PR gating
The platform diffs each scan against history — new, recurring, resolved — and fails the build on new critical findings.
Built to hold up under scrutiny.
A pentest report or an AI Bill of Materials is only as valuable as it is defensible. Authorization, integrity, and confidentiality are the default across both command centers — not an afterthought.
Authorized & gated by design
A scope guard blocks out-of-bounds research; a CI gate blocks risky AI changes. Control surfaces, never autonomous tools.
Tamper-evident
Per-workspace SHA-256 hash-chained audit trail. Alter one entry and verification breaks.
Encrypted at rest
Evidence sealed with AES-256-GCM in your process; only ciphertext is ever written.
Keys you control
Argon2id-derived keys and independent vault/database subkeys keep a DB breach off your vault.
Start free. Scale when it pays off.
Free
Everything to run authorized research, solo.
Pro
For serious hunters who live in their pipeline.
Team
Shared workspaces, roles, and review.
Enterprise
SSO, custom data residency & retention, and a dedicated success contact.
Security work you can put your name on.
Start free in minutes — run authorized research or scan your codebase for AI risk, with every finding backed by tamper-evident evidence.