SecurePR runs Checkov, Semgrep, TruffleHog, and Grype on every pull request — then posts a BLOCK / REVIEW / PASS verdict as a PR comment. DORA, FCA, FINMA, and SWIFT compliance mapping included.
Add SecurePR to any GitHub repo without changing your workflow.
Go to the onboarding page, enter your GitHub org and email, pick a plan. You get a key instantly.
Download securepr.yml and drop it in .github/workflows/. Add your key as a repo secret.
SecurePR scans the branch, runs AI triage, and posts a BLOCK / REVIEW / PASS comment automatically.
Four scanners, AI triage, and compliance mapping — all from a single GitHub Action.
IaC misconfiguration scanning across Terraform, CloudFormation, Kubernetes, and Helm.
Secret detection in code history and diffs. AWS keys, tokens, passwords — verified before flagging.
Code pattern scanning for security anti-patterns in Python, Go, JavaScript, and more.
CVE scanning against the NVD. Finds vulnerabilities in your dependencies and container images.
GPT-4o summarises every finding in plain English. Developers understand the risk immediately.
Every finding is classified by STRIDE category — Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege.
Findings mapped to DORA Article 19, FCA SYSC 8, FINMA RS 2023/1, and SWIFT CSCF v2024.
Only new findings are surfaced on each PR. Existing issues don't create noise on every commit.
Every pull request gets a structured verdict. Your team knows exactly what to do.
aws_s3_bucket_public_access_block resource before re-review.
| Metric | Count |
|---|---|
| Total findings | 8 |
| Critical / High | 5 |
| Medium | 3 |
| DORA reportable | 2 |
| Capability | Checkov (DIY) | Snyk | SecurePR |
|---|---|---|---|
| Automatic PR comment | — | ✓ | ✓ |
| BLOCK / REVIEW / PASS verdict | — | — | ✓ |
| AI plain-English summary | — | — | ✓ |
| STRIDE threat classification | — | — | ✓ |
| DORA Article 19 mapping | — | — | ✓ |
| FCA / FINMA / SWIFT mapping | — | — | ✓ |
| Secret scanning (Go binary) | — | ✓ | ✓ |
| Baseline noise filtering | — | ✓ | ✓ |
| Starting price | Free (DIY setup) | $25/mo | Free tier |
Every finding is mapped to the frameworks your auditors care about.
EU Digital Operational Resilience Act. Article 19 incident reporting obligations flagged per finding.
UK Financial Conduct Authority systems and controls requirements mapped at finding level.
Swiss Financial Market Supervisory Authority operational risk circular requirements.
Customer Security Controls Framework mandatory and advisory controls coverage.
No credit card required on the Starter plan. Cancel Team or Pro anytime.
Free tier. No credit card. Takes 2 minutes to set up.
No spam. Unsubscribe anytime.