v1.0.0  ·  Community edition free  ·  Windows 10/11

Stop drowning in
disconnected security alerts.

SecureGraph AI is a GUI-first desktop security platform. It runs SAST, taint analysis, SCA, secrets scanning, IaC, container, DAST, API threat modeling, AI/MCP security, and cryptographic-inventory (CBOM) checks — then correlates every finding onto one Security Graph, so you see what's actually reachable and exploitable instead of a long undifferentiated list.

Download for Windows (v1.0.0) Read the Docs →
GUI-first, CLI for CI/CD Local-only AI option Free Community edition
10
security engines, one workflow
1
Security Graph correlating every finding
10
report types, incl. SARIF & SBOM/CBOM
Free
Community edition, non-expiring
// the core idea

Scanning finds issues. Observation tells you which ones matter.

Every scanner produces a pile of findings. The hard part isn't running more scanners — it's knowing which findings are duplicates, which are connected, and which are actually reachable in your real application.

Scan — evidence gathering

An active check you run on demand or in CI. It executes one or more engines against your codebase or artifact and produces raw findings for that run — your evidence that a library, endpoint, config file, or image has a known weakness.

Observation — the durable picture

What SecureGraph AI builds from your scans over time: the Security Graph, Correlation, Attack Paths, and a risk score that tracks how your posture changes scan over scan — not a one-off snapshot that goes stale the moment you close the report.


// what it scans

Ten engines, one Findings view

Every engine's output rolls into one cross-cutting Findings view and into the Security Graph for correlation — you don't review ten separate tools' reports by hand.

Developer Workflow

SAST — Static Analysis

Code-level flaws — injection, unsafe deserialization, hardcoded logic bugs, and more — via rule-based pattern matching.

Developer Workflow

Taint Analysis (advanced SAST)

Data-flow tracing from untrusted input to a dangerous operation across function and file boundaries — catches what plain pattern-matching misses. Fully built in, no external tool required.

Developer Workflow

SCA — Dependencies

Known-vulnerable open-source dependencies, checked by version against CVE data.

Developer Workflow

Secrets Scanning

Hardcoded credentials, API keys, and tokens committed to the repo — several providers support live validation.

Developer Workflow

Infrastructure as Code

Misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and similar IaC.

Developer Workflow

Container Security

Base-image vulnerabilities and registry drift for your container images.

Security & Risk

DAST — Dynamic Testing

Runtime, black-box testing against a live, consent-gated target — typically reviewer-initiated, not an everyday pre-commit check.

Security & Risk

Threat Model (API Security)

API surface mapping and threat modeling for your services.

Security & Risk

AI & MCP Security

Security posture of AI/LLM integrations and the MCP (Model Context Protocol) servers your code talks to.

Security & Risk

CBOM — Cryptographic Inventory

Every cryptographic asset in use — algorithms, key sizes, padding modes — and whether it's weak, deprecated, or strong.

Stated honestly: most engines above drive a separate command-line tool (Semgrep, OpenGrep, OSV-Scanner, Gitleaks, Checkov, Trivy, OWASP ZAP) that has to be installed on your machine — SecureGraph AI does not silently bundle these. Taint Analysis is the one exception; it's fully built in. Settings → Scanner Tool Locations shows exactly which path was found for each tool, with an auto-detect button. If a tool isn't installed yet, that engine reports an error instead of findings — the engines you do have installed still run normally.

// the living threat model

One Security Graph, built from your real scans

Once you have scans across multiple engines, three views build on top of them — and keep updating as you scan again.

10 engines → raw findings deduplicated & enriched with CWE/CVE where available
raw findings → Security Graph a navigable graph of components, data flows & findings
Security Graph → Correlation groups shared-root-cause & duplicate findings into one issue
Correlation → Attack Paths chains correlated findings into candidate exploit paths

Security Graph

A navigable graph of your application's components, data flows, and findings, with neighbor-relationship exploration.

Correlation

Groups findings that share a root cause or are duplicates reported by different engines, so you review one grouped issue instead of five near-identical ones.

Attack Paths

Chains correlated findings into candidate exploit paths, so you see which combinations of individually low/medium findings actually add up to something exploitable.


// for every audience

A dashboard for whoever's looking

The same underlying graph and findings, shown at the altitude each audience actually needs.

DashboardAudienceWhat it shows
ExecutiveLeadershipOverall posture, trend, top risks in plain language
SecuritySecurity teamAggregate findings, coverage, and risk across the portfolio
DeveloperEngineersPer-repo findings, scan history, and remediation status
AI GovernanceSecurity & complianceAI/LLM integration posture, MCP server risk, AI Context Firewall activity

// pricing, stated plainly

One free edition today

SecureGraph AI Desktop Community is the current edition: every scanner, every export, every finding, and every base report is available whether or not you register. Free email registration additionally unlocks the governance-level dashboards below — no expiry, no credit card.

Community

Free
  • ✓All 10 scanning engines, unregistered
  • ✓Security Graph, Correlation & Attack Paths
  • ✓All findings, exports & base reports (SARIF, SBOM/CBOM, CSV, HTML)
  • ✓CLI for CI/CD automation
  • ✓Free registration unlocks: Executive Dashboard, Portfolio Rollups, Governance Dashboard, AI Governance Dashboard, Policy views

Pro & Enterprise

Planned, not yet available
  • ✓Server-managed licensing, trials, and multi-seat administration
  • ✓SIEM integration & org-wide policy enforcement

// stated honestly, not oversold

What to expect

// get started
SecureGraph AI icon

Bring every finding onto one graph

Free Community edition. No credit card. Registration is optional and only unlocks governance dashboards.

Signed with VaultMorph's code-signing certificate. Verify the SHA-256 checksum listed in the release notes before you install.