Perfai Security
An automated security guard for apps built with AI coding tools like Cursor or Claude Code — it finds real, exploitable bugs and opens a pull request that fixes them.
🔗 Visit Perfai SecurityDescription
When you build an app quickly with an AI coding assistant, it's easy to ship something that works but has security holes nobody checked for — the kind of mistake a rushed team makes without a dedicated security engineer on staff. Perfai is built to catch exactly that: it studies your running app, actually tries to break into it the way a real attacker would, and instead of just handing you a scary report, it opens a pull request with the fix already written.
Perfai Security is an agentic application-security platform purpose-built for apps shipped from AI coding tools — Cursor, Bolt, v0, Replit, Windsurf, Claude Code, and GitHub Copilot. It automatically maps your app's attack surface, then runs tailored tests across more than 70 AI-native threat categories (broken access control, IDOR, business-logic abuse, SSRF, prompt injection, RAG poisoning, and the standard OWASP Top 10), validating that each finding is a real, exploitable issue before reporting it rather than flooding you with false positives. Fixes ship as ready-to-review GitHub pull requests, and monitoring runs continuously rather than on a scheduled scan cadence. Pricing is credit-based: free at 900 credits/month, Pro at $99/month for 1,800 credits, Growth at $499/month for 5,400 credits, and a custom Enterprise tier that includes self-hosted deployment.
💬 Our review
The short version: if your team ships fast with AI coding assistants and doesn't have a security engineer reviewing every PR, Perfai plugs a real gap — automated, continuously-running penetration testing that produces an actual fix instead of just a finding.
The strongest part of the pitch is exploit validation: a lot of security scanners generate long lists of theoretical vulnerabilities that eat a day of triage before you learn most of them don't matter; Perfai claims to only report issues it actually proved are exploitable, which — if it holds up in practice — is the difference between a tool your team trusts and one that gets ignored after the third false alarm. The category itself (AI-native threat testing: prompt injection, RAG poisoning) is newer and less battle-tested than traditional DAST/SAST tooling, so treat it as a strong complement to, not a full replacement for, a real security review before anything handling sensitive data goes to production. At $99/month for 1,800 credits, Pro is priced for small teams and solo founders rather than casual side projects; the free tier is generous enough to trial it seriously. Best fit: teams shipping fast from Cursor/Claude Code/v0 with no in-house AppSec function. Less useful if you already have a mature security pipeline with SAST/DAST/pentest coverage — you'd be paying to duplicate.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Gratuit : 900 crédits/mois. Pro : 99 $/mois (1 800 crédits). Growth : 499 $/mois (5 400 crédits). Enterprise : sur devis, option self-hosted.
Pros
Validation d'exploit réelle avant de remonter une faille (moins de faux positifs)
Corrige directement via pull request, pas juste un rapport
70+ catégories de menaces spécifiques aux apps générées par IA (prompt injection, RAG poisoning)
Surveillance continue, pas de scan planifié à lancer manuellement
Cons
Catégorie « sécurité IA-native » encore jeune, moins éprouvée que le SAST/DAST classique
Ne remplace pas un vrai audit sécurité pour du code sensible
Redondant si l'équipe a déjà un pipeline sécurité mature
Tarification par crédits, pas un tarif simple à l'usage