Secrets in the diff
API keys pasted into sample code, .env files committed by mistake — gitleaks-grade issues your AI happily reproduces.
Private alpha — early feedback in flight
Indie-friendly security audits, built for the post-Cursor era. EU-hosted. CRA-aligned. From €19/month.
The problem
Cursor and Copilot ship code in seconds. Subtle security issues come along for the ride. Your linter won't catch these. Your IDE won't either.
API keys pasted into sample code, .env files committed by mistake — gitleaks-grade issues your AI happily reproduces.
String interpolation in queries, missing input validation, prototype pollution patterns silently copied from training data.
Package versions suggested by autocomplete that match a CVE published last week — flagged by Trivy, ignored everywhere else.
CORS wide open, missing auth checks on admin routes, generic JWT secrets baked into config — the boilerplate that 'works on my machine'.
How it works
Scan, attest, fix. No new lint to learn, no second dashboard to babysit.
Trivy, Semgrep, gitleaks orchestrated for you — locally via the open-source CLI or remotely on every pull request. One workflow file, no glue code.
Findings deduplicated by signature, ranked by severity, posted as a single PR review comment that updates as you push. Resolved issues auto-close.
Each finding gets an LLM-written explanation in your code's context, plus a suggested fix you can copy or apply with one click.
Three steps
No migration. No call. No card required.
30 seconds. Minimal permissions: read code, read PRs, write commit statuses. You pick the repos.
We open the PR for you with the workflow pre-configured, or you add it yourself in a minute.
The scan runs, the review lands in PR comments. No action needed — security becomes part of your usual flow.
Pricing
Free forever for hobby projects. Solo at €19/month for serious indie work. Studio and Team when you grow.
Forever free for hobby projects
For Léa: serious indie SaaS work
For multi-project indies
Why trust Attestely
Primary data center in France (Supabase EU). Edge workers on Cloudflare's EU network. No US data transfer in the default configuration.
Built around GDPR from day one. CRA-aligned. Cookieless analytics (Plausible). No tracking pixels, no ad networks.
The scanner CLI is open-source on GitHub. Run it locally for free, audit the code, fork it. The backend pipeline remains proprietary.
We send snippets to the LLM provider (Anthropic) with the no-training data policy. Raw blobs deleted after 30 days.
Sign up free in under a minute. The first scan runs the moment you open a PR.