SaaSecure is a desktop scanner that finds OWASP Top 10 vulnerabilities across your codebase in seconds - offline, private, and blazing fast thanks to a Rust engine.
$ saasecure scan . ✔ Scanned 1,284 files in 2.1s - everything stayed local CRITICAL SQL Injection src/db/user.js:42 HIGH OS Command Injection src/jobs/run.js:88 MEDIUM Weak cipher (DES/ECB) src/crypto.ts:15 ➜ 3 issues found · 0 sent to the cloud ▋
Everything runs on your machine. No accounts to scan, no source uploaded, no telemetry.
Your source never leaves the machine - no cloud, no uploads, no accounts. Perfect for proprietary and regulated codebases.
A tree-sitter engine written in Rust parses thousands of files a second, so a full scan finishes before your coffee cools.
Rules match on real taint sources and sink receivers - not loose name matching - so you chase vulnerabilities, not noise.
Injection, XSS, SSRF, broken crypto, secrets, security misconfiguration and more - mapped to CWE and OWASP references.
Export a polished, shareable report - great for audits, clients, and compliance evidence. Also exports JSON & SARIF.
Every finding ships with the offending snippet, an explanation, and concrete guidance to fix it - no guesswork.
No pipelines to configure. No secrets to hand over. Just point and scan.
Open SaaSecure and choose any project directory on your machine. That's the entire setup.
The Rust engine walks your files and flags vulnerabilities in seconds - all computation stays on-device.
Review findings with remediation guidance, then export a branded PDF, SARIF, or JSON report.
One tool for polyglot teams. SaaSecure understands the syntax of the languages you actually ship.
SQL, OS command & code injection
Reflected & stored cross-site scripting
Weak ciphers, modes & hashing
Server-side request forgery
Hard-coded keys & credentials
Missing headers, TLS & more
The SaaSecure CLI (saasecure-cli.exe) brings the same 100% offline, blazing fast Rust SAST engine directly into your CI/CD pipelines, pre-commit scripts, and terminal workflows.
Download the standalone executable and place it in your runner or PATH. Point it at any directory to run scans instantly without installation.
In the desktop app, navigate to Settings → CI / Automation and click Generate CI Token. Pass it via --token or the SAASECURE_CI_TOKEN environment variable.
Use baseline snapshots to track pre-existing issues and fail builds only on newly introduced vulnerabilities. Export results to SARIF, JSON, or PDF.
# 1. Download the Windows binary (or use curl / Invoke-WebRequest) Invoke-WebRequest -Uri "https://files.saasecure.dev/win/saasecure-cli.exe" -OutFile "saasecure-cli.exe" # 2. Run a scan against the current project directory .saasecure-cli.exe . --token <YOUR_CI_TOKEN> # 3. Export to SARIF for GitHub Code Scanning / SonarQube ingestion .saasecure-cli.exe ./src --format sarif --output report.sarif # 4. Generate a branded PDF audit report .saasecure-cli.exe . --format pdf -o security-audit.pdf
SAASECURE_CI_TOKEN in your environment variables so you don't have to pass --token on every invocation.
0 cloud uploads
# Step 1: Snapshot existing codebase findings into a deterministic baseline .saasecure-cli.exe . --update-baseline git add .saasecure/baseline.json && git commit -m "security: record initial baseline" # Step 2: Gate on subsequent PRs - fail ONLY if new HIGH or CRITICAL issues were added .saasecure-cli.exe . --baseline --fail-on high # Step 3: Fast diff scans on Pull Requests (only analyze files modified vs main) .saasecure-cli.exe . --since origin/main --fail-on high
.saasecure/baseline.json use normalized relative paths, ensuring cross-platform compatibility between Windows and Linux runners.
--since calculates the merge-base with your target branch, delivering sub-second scan speeds on active PRs.
.github/workflows/saasecure.yml)name: SaaSecure Code Analysis on: pull_request: branches: [main] permissions: contents: read security-events: write # Required for GitHub Code Scanning SARIF upload jobs: security-scan: runs-on: windows-latest steps: - uses: actions/checkout@v4 with: fetch-depth: 0 # Preserves history for --since diff calculations - name: Download SaaSecure CLI run: Invoke-WebRequest -Uri "https://files.saasecure.dev/win/saasecure-cli.exe" -OutFile "saasecure-cli.exe" - name: Run SAST Scan & Generate SARIF env: SAASECURE_CI_TOKEN: ${{ secrets.SAASECURE_CI_TOKEN }} run: .saasecure-cli.exe . --baseline --fail-on high --format sarif -o results.sarif - name: Upload Findings to GitHub Security Tab uses: github/codeql-action/upload-sarif@v3 if: always() # Upload findings even if --fail-on caused exit code 1 with: sarif_file: results.sarif
SAASECURE_CI_TOKEN, and paste your generated token.
| Flag / Option | Default | Description |
|---|---|---|
| --format <fmt> | text | Report format: text, json, sarif, or pdf. |
| -o, --output <file> | stdout | Destination file path (required when exporting to PDF). |
| --fail-on <lvl> | high | Exit code 1 threshold: critical, high, medium, or low. |
| --baseline [path] | auto | Applies .saasecure/baseline.json so only new findings trigger failure. |
| --update-baseline | - | Records current findings into baseline file and exits 0. |
| --since <gitref> | - | Scans only files changed since specified git ref (e.g. origin/main). |
| --token <token> | $env | CI bearer token. Falls back to SAASECURE_CI_TOKEN env variable. |
Bearer Token Security & Rotation
Your CI token acts as a bearer credential inside automated runners. You can rotate or immediately revoke it anytime from the desktop app's Settings → CI / Automation tab. Tokens are refreshed seamlessly during runs with offline fallback tolerance.
Deep dives into real-world vulnerability teardowns, AST static analysis, secret detection, and shifting security left.
Why traditional regex linters flood developers with 90% false alarms, and how concrete syntax trees with Rust and tree-sitter enable high-precision taint tracking in milliseconds.
Hands-on engineering lessons from discovering and disclosing high-severity cross-site request forgery and authorization bypass vulnerabilities to Google and public portals.
How engineering teams introduce SAST scanners into legacy codebases without breaking continuous integration, using deterministic baselines and diff-aware scans.
Buy once, own it forever. No subscription lock-in - your tool keeps working even when updates end.
For trying SaaSecure on your projects.
For individual developers shipping to production.
Founding price - going to $99 after launch
Renew updates later for just $49/yr
For small teams shipping together.
Up to 5 seats
Renew updates later for just $99/yr
What happens when updates end? Your license is perpetual - SaaSecure keeps scanning forever on every version released during your window. Renew only if you want the newest rules, languages, and detection improvements.
Everything you need to know about SaaSecure, local scanning, and perpetual licensing.
No. SaaSecure is 100% local. Your source code, abstract syntax trees, and vulnerability findings never leave your laptop or server. No source files are uploaded, no cloud processing is used, and zero telemetry is collected.
SaaSecure uses an honest, perpetual model — no subscription trap. When you purchase Pro or Team, you own that version forever. Your license includes 1 full year of software updates and new detection rule packs.
When the 1-year window expires, your scanner continues working indefinitely on every version released during your window. Renewing updates is optional ($49/yr for Pro, $99/yr for Team) whenever you want the latest rules and language features.
SaaSecure scans JavaScript, TypeScript, Python, Java, PHP, Go, and Dart codebases.
It identifies critical OWASP Top 10 vulnerabilities including SQL Injection, OS Command Injection, Reflected & Stored XSS, SSRF, IDOR / broken access control, broken cryptography (weak ciphers and hashing), security misconfigurations, and hard-coded secrets. Every finding includes code snippets, severity ranking, and actionable remediation steps.
Traditional linters and basic scanners rely on crude regex matching that flags harmless variable names or comments. SaaSecure's Rust engine utilizes tree-sitter to parse concrete syntax trees (CST).
Our rules track untrusted data flow from real taint sources directly into sensitive execution sinks (e.g. database queries, shell execs, HTML output), ensuring you spend your time fixing genuine security risks rather than triaging noise.
The Team license provides access to saasecure-cli.exe, a standalone executable with zero external runtime dependencies.
Generate a bearer token from the desktop app and supply it via SAASECURE_CI_TOKEN in your GitHub Actions, GitLab CI, or Jenkins runners. Use --baseline to snapshot existing codebase findings into version control so builds fail only on newly introduced vulnerabilities (--fail-on high), and export findings to SARIF for the GitHub Security tab.
Yes. SaaSecure verifies the activation fingerprint locally on your machine. Once activated, scans operate completely offline without needing an active internet connection.
The client incorporates an automatic 14-day offline grace window between online heartbeat checks, ensuring that developers traveling, working remotely without internet, or operating behind strict corporate firewalls can continue scanning without disruption.
Licenses are tied to non-reversible hardware fingerprints. Pro includes 1 device seat, and Team includes up to 5 device seats.
If you get a new computer or wipe your operating system, simply open Settings → About → Deactivate License on your old machine. This notifies the server to immediately free up the seat. If you ever lose access to your machine or key, use the Recover Key button on this site to have your license key emailed back to you.
Yes! You can download SaaSecure Free immediately — no account or credit card required. The free version allows unlimited local scans across all 7 languages and reports the full summary of findings and severities.
For Pro and Team purchases, we back your license with a 14-day money-back guarantee. If SaaSecure doesn't find vulnerabilities or doesn't fit your engineering workflow, simply contact support for a prompt refund.
We're here to help. Reach out to our security engineering team anytime.
SaaSecure scans locally, privately, and fast. No cloud. No compromises.