Free — No signup required

Free Security Scan
for Your AI Agent

Get an instant security and compliance posture score for your repository. One API call from your AI assistant — no account needed.

How It Works

1

Agent creates a session

Your AI assistant calls our API to create an ephemeral scan session. No signup needed.

POST https://api.brigs.ai/ephemeral/sessions
{ "email": "[email protected]" }
2

You connect your code

Click the connect link to authorize GitHub access. Code is cloned temporarily and deleted after scanning.

3

Agent triggers the scan

The agent adds your repo and starts a scan. Results are ready in 1-3 minutes.

POST https://api.brigs.ai/scans
Authorization: Bearer brigs_eph_...
{ "repoId": "..." }
4

View & share results

Get a shareable public URL with your security posture score and findings summary.

Framework Coverage

Every scan evaluates your code against multiple compliance frameworks simultaneously.

SOC 2
Trust services criteria for SaaS
25 controls
OWASP Agentic
AI agent security framework
11 controls
ISO 27001
Information security management
20 controls
NIST CSF
Cybersecurity framework
18 controls

Frequently Asked Questions

Is the scan really free?

Yes. Ephemeral scan sessions are completely free — 1 repo, 1 scan, results visible for 72 hours. No credit card needed.

What happens to my code?

Your code is cloned to a temporary directory, scanned, and then deleted. We never store source code. Only compliance metadata (scores, control results, finding summaries) is retained.

What information is shown publicly?

The public results page shows only: framework scores, control pass/fail status, and one-line finding summaries. No source code, file paths, line numbers, or technical details are ever exposed.

Can an AI assistant run this autonomously?

Almost. The session creation and scan trigger are fully API-driven. The only human step is clicking the GitHub authorization link (OAuth requires user consent). After that, the agent handles everything.

What happens after 72 hours?

The session expires. Results remain visible with an expired banner, but no new scans can run. Create an account to claim your results and get continuous monitoring.

Which frameworks are supported?

SOC 2 Type II, OWASP Agentic Security, ISO 27001, NIST CSF, and more. Each scan evaluates your code against all applicable frameworks simultaneously.

Ready to Scan?

Ask your AI assistant to create an ephemeral scan session, or create an account for full access.