Secure your code at the speed of thought.
eidosSec is an AI-powered security scanner that combines traditional static analysis with Large Language Models to provide accurate, actionable vulnerability findings. It runs 100% locally using Docker—your code never leaves your machine.
- Installation Guide - Windows (WSL2), Linux, and macOS setup.
- Supported Tools - List of all 21+ integrated security scanners (Semgrep, Bandit, Trivy, CodeQL, Gosec, etc.).
- API Reference - REST API documentation and usage examples.
- Project Roadmap - Development timeline and future features.
- Multi-Engine Scanning: Orchestrates 21+ open-source security tools for comprehensive coverage (SAST, SCA, Secrets, IaC).
- Intelligent Deduplication: Merges duplicate findings from multiple tools to reduce noise.
- Real-time Progress: Watch scans execute live via WebSocket streams.
- Private & Secure: Self-hosted architecture ensures no code exfiltration.
- Production Ready: Fully tested on production server with 88/88 tests passing.
-
Clone the repository:
git clone https://github.com/your-org/eidosSec.git cd eidosSec -
Start with Docker Compose:
docker-compose up -d --build
-
Access the Dashboard: Open http://localhost:3000 in your browser.
eidosSec is a monorepo consisting of:
backend/: FastAPI application (Python)frontend/: React + Vite application (TypeScript/Tailwind)scanner/: Celery worker & tool wrappers (Python)
See Installation Guide for local development instructions.
Contributions are welcome! Please check the Project Roadmap to see what we're working on.
This project is licensed under the MIT License - see the LICENSE file for details.
