Sweep
Powered by Claude Sonnet 4·v1

Stop shipping
AI-generated vulnerabilities.

Sweep automatically scans your repository for hardcoded keys, SQL injection, and the quiet security failures AI coding assistants leave behind.

Scan time
~10s
Checks
120+
Languages
All
Model
Sonnet 4
Built for apps made withCursorv0BoltLovableReplitClaude
Pipeline

Four phases. Ten seconds.

  1. Phase 011

    Submit

    Paste any file, or drop a public GitHub repo or file URL. Any language. No repo access required.

  2. Phase 022

    Pre-scan

    A deterministic regex pass flags obvious secrets instantly — AWS, Stripe, OpenAI, GitHub, Supabase, JWTs.

  3. Phase 033

    Analyse

    Claude Sonnet 4 audits the code for logic flaws, SQL injection, auth mistakes, and exposure risk.

  4. Phase 044

    Report

    You get a risk score, line-level issue list with evidence and fixes, and a ranked remediation plan.

Detection matrix

What Sweep sees.

Hardcoded Secrets

  • OpenAI / Anthropic keys
  • Stripe live keys
  • AWS access keys
  • GitHub tokens
  • Private key blocks

Credentials

  • Database URIs with passwords
  • Hardcoded passwords
  • Exposed service_role keys
  • Leaked JWTs

Injection

  • SQL string concatenation
  • eval() on dynamic input
  • dangerouslySetInnerHTML
  • Unvalidated user input

Configuration

  • CORS wildcard origins
  • Missing rate limits
  • Insecure auth logic
  • Debug mode in production

Exposure

  • NEXT_PUBLIC_ secrets
  • Console logs of tokens
  • Sensitive data in client bundle
  • Verbose error stack traces

Forensics

  • Line-level evidence
  • Fix snippets
  • Severity & category
  • Ranked remediation plan
Pricing

Simple pricing.

No subscriptions. No monthly fees. Pay for what you use.

Scout
Free
Free forever

Get started at no cost.

  • 3 full scan reports included
  • Risk score + issue breakdown
  • Line-level evidence + fixes
  • Paste or GitHub URL input
  • Scan history saved
SINGLE
$3.99
One scan

Perfect for a quick check

  • 1 full scan report
  • Full issue details + fixes
  • Valid for 6 months
  • Instant unlock
BUNDLE
Most popular
$14.99
5 scans — $3.00 per scan

For active builders

  • 5 full scan reports
  • Full issue details + fixes
  • Valid for 6 months
  • Save $5 vs single
ARSENAL
$39.99
20 scans — $2.00 per scan

For teams and agencies

  • 20 full scan reports
  • Full issue details + fixes
  • Valid for 6 months
  • Save $40 vs single
Credits expire 6 months after purchase (we'll email you 30 days before). One-time packs — no subscription to cancel.

Submit your code
for clearance.

Every line reviewed. Every secret flagged. Every fix spelled out.