Security scanning that fits your codebase — not the other way around

Code, dependencies, secrets and infrastructure config, scanned locally or in CI. Evidence for every finding. One concise pull-request check, not dozens of bot comments.

Scan any repository in one command:

yaksecure scan --upload-results

Open by design

An open scanner and rule format. Write rules in YAML, test them like code, and run the whole engine locally with no account at all.

Local-first

The scanner runs on your machine or your CI. Source never has to leave your infrastructure for you to get results.

Evidence, not noise

Data-flow analysis shows the path from input to sink. Dependency findings say whether the vulnerable code is actually reachable from yours.

Priced per repository

Never per developer, so you can give the whole team read access without a bill for it.

Pricing

Community

£0/mo

1 repositories

Open-source CLI, community rule packs, local SAST/secrets/IaC, unlimited developers.

Team

£99/mo

20 repositories

SAST, SCA, secrets, IaC, PR gating, IDE plugins, SBOMs. Unlimited read-only users.

Growth

£299/mo

100 repositories

Container scanning, DAST allowance, custom rule packs, SSO, customer-managed runners.

Enterprise

Talk to us

Unlimited repositories

Self-managed SCM, SAML/SCIM, regional/air-gapped deployment, compliance evidence, SLA.