Skip to content
A concrete stairway with a handrail rising through a quiet stone building

For developers

Add security without adding friction.

Connect your repository, scan your application and bring security directly into the workflow you already use.

Security that shows up where you already work: in the pull request, in the pipeline and in the code that runs your agents.

That means: no new dashboard to remember to check.

Start with one repository.

Connect a repository and Forolock maps the application, tests what it finds and reports what is exploitable.

  1. 1

    Connect

    • Install the GitHub app
    • Choose repositories
  2. 2

    Scan

    • Application mapped
    • Attack paths tested
  3. 3

    Fix

    • Review findings
    • Merge suggested fixes
TerminalCLI · Coming soon
$ npx forolock init✓ repository connected✓ application mapped✓ 12 attack paths tested! 2 exploitable findings  run `forolock open` to review

Security where code changes.

Forolock reviews pull requests like a teammate: one clear comment per proven issue, with the fix attached.

Pull request #482 · Add account settingsreview
Forolock SecurityCritical

Tenant isolation bypass

Attack verified

/api/accounts/:id

Any signed-in user can read another account by changing the id. Scope the query to the session’s tenant.

Open fix
  • Pull request checks

    Every change is tested before it merges, and only proven issues are reported.

  • Evidence inline

    The comment shows the endpoint, the attack and why it matters.

  • Fix attached

    Open the suggested fix as a commit or a follow-up pull request.

CLI

A command line for local checks.

The Forolock CLI will let you test a branch locally before you push, and script Forolock into your own tooling.

TerminalComing soon
$ forolock login$ forolock scan --branch feature/billing$ forolock findings --status open

A security gate in your pipeline.

Run Forolock between build and deploy. Proven, high-severity issues stop the release; everything else is reported.

  1. Commit
  2. Build
  3. Forolock
  4. Security gate
  5. Deploy
CI stepExample · proposed
# .github/workflows/deploy.yml
- name: Forolock security gate
  uses: forolock/action@v1
  with:
    fail-on: exploitable-high

Everything is programmable.

Findings, attack paths, policies and decisions, available to your own tools. The public API is not released yet; this shows its intended shape.

FindingsConceptual example
GET /v1/findings?status=open&exploitable=true

{
  "data": [{
    "id": "fnd_…",
    "title": "Tenant isolation bypass",
    "severity": "critical",
    "exploitable": true,
    "location": "/api/accounts/:id",
    "attack_path": ["signup", "request_other_tenant", "read_record"],
    "remediation": { "pull_request": "…" }
  }]
}

React to security events.

Send Forolock events to Slack, your ticketing system or your own services as they happen.

EventsProposed event contract
Proposed webhook events
EventMeaning
finding.createdA new issue has been found.
finding.resolvedAn issue has been fixed or closed.
attack.verifiedA finding has been proven exploitable.
agent.action.blockedAn agent action was stopped by policy.
policy.triggeredA policy rule matched an action.

Works with your stack.

Listed by category. None implies a partnership.

Source

  • GitHubSupported integration
  • GitLabSupported integration

AI coding

  • Claude CodeSupported integration
  • CodexSupported integration
  • CursorSupported integration

Deployment

  • VercelSupported integration
  • CloudflareSupported integration
  • AWSSupported integration

Data

  • SupabaseSupported integration
  • FirebaseSupported integration
  • PostgresSupported integration

Agents

  • MCPSupported integration
  • OpenAI-compatible agentsSupported integration
  • Agent frameworksSupported integration

Authorise agent actions at runtime.

One call before an agent acts. Forolock checks the action against your policy and returns a decision, with a reason.

Agent SDKPseudo-code · proposed
const decision = await forolock.authorize({
  agent: "support-agent",
  action: "stripe.refund",
  resource: "charge_8f2…",
  context: { amount: 420, currency: "USD" },
});

if (decision.result !== "ALLOW") {
  return decision.reason; // e.g. "Refunds over $250 need approval"
}
  • ALLOWWithin policy. The agent proceeds.
  • BLOCKOutside policy. The action stops, with a reason.
  • REQUIRE_APPROVALSensitive. A person approves first.

Examples to start from.

Worked examples for common setups. Full guides will be published in the docs.

Secure a Supabase app

Check row-level security, exposed keys and tenant isolation.

Status: Guide coming soon

Gate deploys on Vercel

Stop a release when an exploitable issue is found.

Status: Guide coming soon

Add approvals to an agent

Require sign-off for refunds, exports and outbound email.

Status: Guide coming soon