๐ŸŒ US-Proxy
class="inter_8f1c4a24-module__nx7jFG__variable jetbrains_mono_4282af4f-module__TNdyLG__variable font-sans antialiased">
superagent_

Y Combinatorbacked by Y Combinator

Security forAI-native developers

trust what you merge, control what your agents do, and show your users it's safe. free for open source.

customers

ubicloudevry healthdotenvxfirecrawlcapchasenangomastrapaperclip

products

trust the change

checks on every pull request, before merge. vulnerabilities, supply-chain risk, who's behind the code, and whether the cla is signed โ€” findings on the exact line, fixes as pull requests.

pr scans

vulnerability checks on every pull request.

  • โ–ธinline review comments
  • โ–ธgithub check runs
  • โ–ธpatches as prs

docsโ–ธ

contributor trust

know who is behind the code before it merges.

  • โ–ธrisk scores per contributor
  • โ–ธsupply-chain flags
  • โ–ธprivate by default

docsโ–ธ

agreements

cla templates, versions, and signing workflows.

  • โ–ธcla templates
  • โ–ธsigning bot
  • โ–ธversion control

docsโ–ธ

control it where it runs

deterministic rules for what agents do, trust scores for everything they consume โ€” and sensitive activity stays on the endpoint.

runtime guardrails

deterministic rules that decide what your agent may do.

  • โ–ธbuilt-in detections
  • โ–ธcustom security rules
  • โ–ธmonitor or enforce

docsโ–ธ

context guardrails

trust scoring for everything your agent consumes.

  • โ–ธevery source scored
  • โ–ธfour-dimension scoring
  • โ–ธfast enough for runtime

docsโ–ธ

break it before it ships

self-serve red teaming against what you actually run. black-box against the public surface, gray-box with repo context. every finding ships with repro steps and the payload that worked.

red team

adversarial tests on your app, repo, agents, and models.

  • โ–ธreal adversary playbooks
  • โ–ธevery surface
  • โ–ธproof, not vibes

docsโ–ธ

how it works

you already work in your coding agent and github. so that's where superagent works too โ€” no new workflows or tools to learn.

three steps, no new habits

01 create your account โ€” connect repos, manage keys, invite your team

02 connect to github โ€” keeps your repos secure

03 add the mcp server โ€” red-team your code and agents from your coding agent

covered from first prompt to production

changelog

customer quotes

โ€œi wish i could just let our agents run free and solve all our problems. but at what cost? superagent helps us sleep better at night.โ€

โ€œit chained vulnerabilities together the way a real attacker builds a kill chain and found exploit paths. a week later, a threat intelligence scanner flagged the same vulnerability. by then it was already fixed.โ€

โ€œyou guys are the best.โ€

โ€” devin foley, co-founder & cto, paperclip

[ all customer stories ]

get started

free for open source.

the whole suite, on any public repo. private repos are paid โ€” contact us and we'll set you up.