Built for NCA ECC-2:2024 & SAMA CSF

Ship code your regulator already trusts.

Five scanning engines run on every commit and turn into one live compliance score — the same score your dashboard shows and your auditor can verify, with nothing re-typed in between.

Already have an account? Sign in

89%NCA score
2Critical
6High
5Scan engines

Built for Saudi engineering teams shipping under NCA, SAMA, and PDPL requirements

The scan

Five engines, one score, zero guessing about what a regulator will ask.

PDPL data scanner

Reads every file for Saudi National IDs, IBANs, and phone numbers left in code or config — the exact exposure a PDPL audit looks for, before it ships.

National IDIBANPhone

Static analysis

SQL injection, hardcoded secrets, insecure deserialization — caught on the line they were written, mapped straight to the NCA control they violate.

Dependency risk

Every package, every known CVE, tracked individually — not collapsed into a single “vulnerabilities found” number that tells you nothing about what to fix first.

Infrastructure & secrets

Terraform and Kubernetes misconfiguration, hardcoded credentials, and exposed keys — caught before the pipeline runs, not after the breach.

AI-assisted remediation

Every finding ships with a suggested fix. A human reviewer approves, edits, or rejects it before anything reaches your repository.

Compliance, not just security

Two frameworks. One codebase. No spreadsheet in between.

Your NCA and SAMA scores update from the same scan, the same finding set, the same source of truth — so the number your CISO sees and the number your auditor asks about are never two different stories.

NCA ECC-2:2024Essential Cybersecurity Controls
89%
SAMA CSFCyber Security Framework
75%
PDPLPersonal Data Protection Law
CLEAR

How it runs

From repository to auditor‑ready report.

  1. CONNECT

    Point it at a repo

    GitHub, GitLab, or a ZIP upload. No agent to install on your infrastructure.

  2. SCAN

    Five engines run

    Code, dependencies, infrastructure, secrets, and PDPL exposure — in one pass.

  3. GATE

    Block or ship

    Your CI/CD gate enforces the policy you set — critical findings stop the merge.

  4. PROVE IT

    Hand over the score

    A signed, tamper-proof link your auditor can open — no login required.

Your next audit is easier when the evidence has been running since your first commit.

Free for your first repository. No credit card, no sales call to start.