
For developers
Add security without adding friction.
Connect your repository, scan your application and bring security directly into the workflow you already use.
Security that shows up where you already work: in the pull request, in the pipeline and in the code that runs your agents.
That means: no new dashboard to remember to check.
Start with one repository.
Connect a repository and Forolock maps the application, tests what it finds and reports what is exploitable.
- 1
Connect
- Install the GitHub app
- Choose repositories
- 2
Scan
- Application mapped
- Attack paths tested
- 3
Fix
- Review findings
- Merge suggested fixes
$ npx forolock init✓ repository connected✓ application mapped✓ 12 attack paths tested! 2 exploitable findingsrun `forolock open` to review
Security where code changes.
Forolock reviews pull requests like a teammate: one clear comment per proven issue, with the fix attached.
Tenant isolation bypass
Attack verified
/api/accounts/:id
Any signed-in user can read another account by changing the id. Scope the query to the session’s tenant.
Open fixPull request checks
Every change is tested before it merges, and only proven issues are reported.
Evidence inline
The comment shows the endpoint, the attack and why it matters.
Fix attached
Open the suggested fix as a commit or a follow-up pull request.
A command line for local checks.
The Forolock CLI will let you test a branch locally before you push, and script Forolock into your own tooling.
$ forolock login$ forolock scan --branch feature/billing$ forolock findings --status open
A security gate in your pipeline.
Run Forolock between build and deploy. Proven, high-severity issues stop the release; everything else is reported.
- Commit
- Build
- Forolock
- Security gate
- Deploy
# .github/workflows/deploy.yml
- name: Forolock security gate
uses: forolock/action@v1
with:
fail-on: exploitable-highEverything is programmable.
Findings, attack paths, policies and decisions, available to your own tools. The public API is not released yet; this shows its intended shape.
GET /v1/findings?status=open&exploitable=true
{
"data": [{
"id": "fnd_…",
"title": "Tenant isolation bypass",
"severity": "critical",
"exploitable": true,
"location": "/api/accounts/:id",
"attack_path": ["signup", "request_other_tenant", "read_record"],
"remediation": { "pull_request": "…" }
}]
}React to security events.
Send Forolock events to Slack, your ticketing system or your own services as they happen.
| Event | Meaning |
|---|---|
| finding.created | A new issue has been found. |
| finding.resolved | An issue has been fixed or closed. |
| attack.verified | A finding has been proven exploitable. |
| agent.action.blocked | An agent action was stopped by policy. |
| policy.triggered | A policy rule matched an action. |
Works with your stack.
Listed by category. None implies a partnership.
Source
- GitHubSupported integration
- GitLabSupported integration
AI coding
- Claude CodeSupported integration
- CodexSupported integration
- CursorSupported integration
Deployment
- VercelSupported integration
- CloudflareSupported integration
- AWSSupported integration
Data
- SupabaseSupported integration
- FirebaseSupported integration
- PostgresSupported integration
Agents
- MCPSupported integration
- OpenAI-compatible agentsSupported integration
- Agent frameworksSupported integration
Authorise agent actions at runtime.
One call before an agent acts. Forolock checks the action against your policy and returns a decision, with a reason.
const decision = await forolock.authorize({
agent: "support-agent",
action: "stripe.refund",
resource: "charge_8f2…",
context: { amount: 420, currency: "USD" },
});
if (decision.result !== "ALLOW") {
return decision.reason; // e.g. "Refunds over $250 need approval"
}- ALLOWWithin policy. The agent proceeds.
- BLOCKOutside policy. The action stops, with a reason.
- REQUIRE_APPROVALSensitive. A person approves first.
Examples to start from.
Worked examples for common setups. Full guides will be published in the docs.
Secure a Supabase app
Check row-level security, exposed keys and tenant isolation.
Status: Guide coming soon
Gate deploys on Vercel
Stop a release when an exploitable issue is found.
Status: Guide coming soon
Add approvals to an agent
Require sign-off for refunds, exports and outbound email.
Status: Guide coming soon