An open specification and Python library for generating hardware-attested, tamper-evident records of what an AI agent actually did — for audits and compliance.
#app-security
44 tools curated in this category — including TRACE, CodeIntegrity, VulX
techFind on mySelectas all sites and tools related to app-security. This selection of 44 resources is reviewed and maintained by the community. The most popular include TRACE, CodeIntegrity, VulX. Each tool comes with a review, tags, comparisons and alternatives to help you make the best choice.
A security layer for companies that let AI agents take real actions on their behalf (booking things, editing databases, sending messages) — it steps in at the exact moment an agent is about to act and checks whether that action is actually safe to run, in
Scans AI-generated codebases for exposed keys, vulnerable dependencies, and authorization flaws, with plain-English fixes.
Runs automated agents that continuously check your systems against ISO 27001 and SOC 2 requirements and generate timestamped proof, instead of you scrambling for screenshots the week before an audit.
Uses AI agents to handle the governance-risk-and-compliance busywork — reading your policies, checking your controls, filling out security questionnaires — that would otherwise eat up a compliance team's week.
A compliance platform that pairs automated evidence-gathering software with actual licensed auditors on staff, so the same company that helps you prepare for SOC 2 or ISO 27001 can also perform the audit itself.
Automates the grinding paperwork behind security certifications like SOC 2 or ISO 27001 — connecting to your cloud tools, continuously collecting the evidence an auditor needs, and flagging anything that would fail before the real audit happens.
Cloud security platform that monitors sessions and automatically terminates destructive actions within seconds across AWS, Azure, GCP, and DigitalOcean.
A platform that helps startups pass security audits like SOC 2 by pairing automated compliance software with real human security experts.
A security platform that scans your code, pipelines, and AI coding tools for vulnerabilities across your whole software supply chain, then tries to auto-fix what it finds.
An AI assistant for security teams that reads your product designs and vendor contracts and flags privacy or security risks before they become a problem.
A permission gate that sits in front of your AI coding agent and blocks it from running a dangerous command or deleting a file before it happens — instead of hoping the agent behaves.
A security tool that joins your video calls as a silent watchdog, flagging deepfake voices, AI-generated impersonators and leaked sensitive data in real time.
Free secrets scanner from Gitleaks' original creator: finds leaked API keys and passwords in code with far fewer false positives.
A service that gets a software company ready for its first security certification (like SOC 2) and keeps it that way automatically, instead of a founder spending months chasing screenshots for an auditor.
A security tool that keeps track of every AI agent, app and 'non-human' account quietly operating inside a company's software — and flags the ones nobody's watching before they cause a breach.
Fraud-detection system that scores a payment as risky or safe while it's happening — checking the device, behavior and identity behind it — instead of catching fraud only after the money's already gone.
Language-agnostic AI content moderation platform that filters abusive content, fraud and spam in real time across virtually any language or dialect.
AI content moderation API that detects harmful text, images, video and audio (NSFW, hate speech, violence, CSAM, AI-generated content) at scale.
AI-powered security platform combining automated pentesting, code review and cloud vulnerability scanning to find and fix exploitable issues before attackers do.