ForgeSec scans your stack in 60 seconds, enriches every CVE with real-world EPSS scores and CISA KEV status, maps to ATT&CK techniques, and gets smarter with every scan — because it remembers your history.
ForgeSec operates in read-only mode by default — it inspects your system, scans your files, and analyzes your dependencies without making any changes. It cannot modify files, run commands, install packages, or take any action on your infrastructure unless you explicitly approve it step-by-step.
Not a week of onboarding. Not a consultant. Just connect and go.
Point ForgeSec at your repo, paste a GitHub URL, or run forgesec scan in your terminal. No agent, no config.
Dependencies, ports, auth logs, secrets — enriched with EPSS scores, CISA KEV status, and ATT&CK technique mapping.
Your Security Health Score tracks over time. Investigation agent explains root causes. Memory makes every scan smarter than the last.
Scanners dump lists. ForgeSec acts like a senior engineer on your team.
ForgeSec remembers your tech stack, past findings, and explanation feedback. After 10 scans, it knows your infrastructure better than a new hire and personalises every analysis to your specific setup.
Every CVE is enriched with its EPSS exploit probability and CISA Known Exploited Vulnerability status. ForgeSec tells you which vulnerabilities are being actively exploited right now — not just which ones technically exist.
Compares every scan against your history. The moment a new CRITICAL finding appears that wasn't there before, Sentinel fires an email alert — before attackers can act.
Ask 'Why does this keep appearing?' and ForgeSec investigates — pulling scan history, EPSS trends, and KEV status, then generating a root cause analysis with urgency classification and concrete action items.
A 0-100 score (graded A–F) that tracks your security posture over time. Weighted by severity, EPSS probability, and KEV status — with a sparkline showing whether you're improving or declining.
Every finding shows which scanner found it, why it was classified at that severity, and what the EPSS probability means. Scan diff shows exactly what's new and what got resolved since your last scan.
Detects typosquatted and abandoned packages beyond CVE databases — colourama, crossenv, and hundreds of known supply-chain attack packages. Flags them as MALICIOUS before they reach production.
pip install forgesec then run forgesec scan from any directory. Exit codes work in CI pipelines (0=clean, 1=high, 2=critical). forgesec watch re-scans on an interval and alerts on new issues.
Every finding is mapped to MITRE ATT&CK techniques. Download a Navigator layer JSON that opens directly in the official ATT&CK Navigator — colour-coded by risk score, EPSS, and KEV status.
Read-only by default. No agents to install. No credentials stored. ForgeSec inspects your system without modifying a single file — unless you explicitly approve it.
Not enterprise security teams. Builders who can't afford to wait.
“Found 14 CVEs in my production stack within 60 seconds. Two of them were actually exploitable. This paid for itself immediately.”
“We were heading into a SOC2 audit with zero visibility into our dependency risk. ForgeSec gave us a full report in minutes, not weeks.”
“The AI explanations are what got me. Not just a list of CVEs — it told me which three actually mattered for our specific stack. Game changer.”
A senior security engineer costs $150k/year. ForgeSec starts at $29/month.
14-day money-back guarantee · Cancel anytime · No hidden fees
For indie developers
For small teams moving fast
For companies with real stakes
Enterprise / self-hosted? Contact us — we run on your infrastructure.
Enterprise pricing, partnerships, or just a question — we reply within 24 hours.
Get notified when we launch new features and early access offers.