Memory · EPSS · CISA KEV · ATT&CK · Sentinel

Security that thinks.
Not just scans.

ForgeSec scans your stack in 60 seconds, enriches every CVE with real-world EPSS scores and CISA KEV status, maps to ATT&CK techniques, and gets smarter with every scan — because it remembers your history.

No credit card Read-only Cancel anytime

Safety is the foundation, not a feature

ForgeSec operates in read-only mode by default — it inspects your system, scans your files, and analyzes your dependencies without making any changes. It cannot modify files, run commands, install packages, or take any action on your infrastructure unless you explicitly approve it step-by-step.

Never modifies filesNever executes commandsNever installs anythingExplicit confirmation for every actionFull audit trail of what it checked

Security that takes 60 seconds to set up

Not a week of onboarding. Not a consultant. Just connect and go.

01

Connect your project

Point ForgeSec at your repo, paste a GitHub URL, or run forgesec scan in your terminal. No agent, no config.

02

Sentinel audits and enriches

Dependencies, ports, auth logs, secrets — enriched with EPSS scores, CISA KEV status, and ATT&CK technique mapping.

03

Intelligence that compounds

Your Security Health Score tracks over time. Investigation agent explains root causes. Memory makes every scan smarter than the last.

Built different from every scanner you've tried

Scanners dump lists. ForgeSec acts like a senior engineer on your team.

Memory that compounds

ForgeSec remembers your tech stack, past findings, and explanation feedback. After 10 scans, it knows your infrastructure better than a new hire and personalises every analysis to your specific setup.

EPSS + CISA KEV threat intelligence

Every CVE is enriched with its EPSS exploit probability and CISA Known Exploited Vulnerability status. ForgeSec tells you which vulnerabilities are being actively exploited right now — not just which ones technically exist.

Sentinel — proactive threat detection

Compares every scan against your history. The moment a new CRITICAL finding appears that wasn't there before, Sentinel fires an email alert — before attackers can act.

Investigation agent

Ask 'Why does this keep appearing?' and ForgeSec investigates — pulling scan history, EPSS trends, and KEV status, then generating a root cause analysis with urgency classification and concrete action items.

Security Health Score

A 0-100 score (graded A–F) that tracks your security posture over time. Weighted by severity, EPSS probability, and KEV status — with a sparkline showing whether you're improving or declining.

Full transparency — why we flagged this

Every finding shows which scanner found it, why it was classified at that severity, and what the EPSS probability means. Scan diff shows exactly what's new and what got resolved since your last scan.

Malicious package detection

Detects typosquatted and abandoned packages beyond CVE databases — colourama, crossenv, and hundreds of known supply-chain attack packages. Flags them as MALICIOUS before they reach production.

CLI — scan from your terminal

pip install forgesec then run forgesec scan from any directory. Exit codes work in CI pipelines (0=clean, 1=high, 2=critical). forgesec watch re-scans on an interval and alerts on new issues.

ATT&CK mapping + Navigator export

Every finding is mapped to MITRE ATT&CK techniques. Download a Navigator layer JSON that opens directly in the official ATT&CK Navigator — colour-coded by risk score, EPSS, and KEV status.

Safe by design, not by policy

Read-only by default. No agents to install. No credentials stored. ForgeSec inspects your system without modifying a single file — unless you explicitly approve it.

Intelligence stack:FIRST EPSS · CISA KEV · Google OSV · MITRE ATT&CK v14 · pip-audit · npm audit · trufflehog · Claude Sonnet · Playwright cards · Supabase memory

Trusted by developers who ship fast

Not enterprise security teams. Builders who can't afford to wait.

Found 14 CVEs in my production stack within 60 seconds. Two of them were actually exploitable. This paid for itself immediately.

Marcus R.
Solo SaaS founder · $18k MRR

We were heading into a SOC2 audit with zero visibility into our dependency risk. ForgeSec gave us a full report in minutes, not weeks.

Priya M.
CTO · 12-person startup

The AI explanations are what got me. Not just a list of CVEs — it told me which three actually mattered for our specific stack. Game changer.

James L.
Staff Engineer · dev agency

Pricing that makes sense

A senior security engineer costs $150k/year. ForgeSec starts at $29/month.

14-day money-back guarantee · Cancel anytime · No hidden fees

Solo

For indie developers

$29/month
  • 1 project
  • Daily automated audit
  • Dependency CVE scanning
  • System config audit
  • Weekly email report
  • 14-day free trial
Most popular

Startup

For small teams moving fast

$99/month
  • 5 projects
  • Real-time monitoring
  • Memory across sessions
  • Slack + Telegram alerts
  • Compliance checklists
  • Priority support

Team

For companies with real stakes

$299/month
  • Unlimited projects
  • LangGraph investigation flows
  • Custom security playbooks
  • SOC2 readiness report
  • Dedicated Hermes memory
  • SLA + dedicated support

Enterprise / self-hosted? Contact us — we run on your infrastructure.

Get in touch

Enterprise pricing, partnerships, or just a question — we reply within 24 hours.

Not ready yet? Join the waitlist.

Get notified when we launch new features and early access offers.

Your stack has vulnerabilities right now.

ForgeSec will find them in 60 seconds. No configuration, no agent install, no security degree required.

Free 14-day trial · No credit card · Read-only by default