← Home
// Security hub
Security Scanning
Run security scans on your code, AI assets, and APIs
// Threat modeling
STRIDE
Web Questionnaire

Answer 5 questions about your system or upload an architecture diagram. Get a full STRIDE analysis with security lead workflow.

Start Analysis →
// AI security
OWASP LLM · MITRE ATLAS
MCP Security Scan

Scan MCP server configurations for prompt injection, excessive permissions, and unverified server origins. Mapped to OWASP LLM Top 10 and MITRE ATLAS.

OWASP LLM
Skill File Scanner

Scan AI agent skill files for prompt injection, obfuscation, and dangerous instructions.

OWASP LLM07 · CWE
Plugin Security Scanner

Scan AI plugin manifests and OpenAPI specs for insecure design, missing auth, and OWASP LLM07 violations.

// Code security
OWASP ASVS · CWE
AI Code Scanner

Scan AI-generated code for security anti-patterns, missing validation, insecure defaults, and CWE violations. Mapped to OWASP ASVS and LLM06.

🔑 CWE-798 · OWASP ASVS
Secrets Detection

Scan your codebase for hardcoded API keys, passwords, private keys, connection strings, and cloud credentials before they reach production.

// Infrastructure security
CIS Benchmarks · NIST SP 800-53
Infrastructure as Code Scanner

Scan Terraform, Kubernetes, Docker, CloudFormation, and Ansible files for security misconfigurations. Missing encryption, overly permissive IAM, exposed resources and more.

Terraform, Kubernetes YAML, Dockerfile, CloudFormation, docker-compose
// API & prompt security
OWASP API Top 10
API Security Scanner

Scan OpenAPI and Swagger specifications for authentication issues, broken authorization, excessive data exposure, and OWASP API Top 10 vulnerabilities.

OWASP LLM01 · LLM08 · MITRE ATLAS
LLM Prompt Security Testing

Test your AI system prompts for prompt injection vulnerabilities, jailbreak susceptibility, sensitive data exposure, missing guardrails, and multi-turn manipulation attacks.

System Prompt *
// Import
Semgrep · Trivy · GitHub GHAS
SARIF Import

Import findings from any SARIF-compatible tool — Semgrep, Trivy, GitHub GHAS, Checkov. Findings appear in your dashboard alongside Arcwall native scans.

// Scheduled Scans
Scheduled Scans

Connect GitHub to set up automatic scheduled scans on your repositories. Runs daily, weekly, or monthly — findings land in your dashboard automatically.

Connect GitHub →