Nullgaze learns your codebase over time. It remembers false positives, discovers new patterns, and gets smarter with every scan. Built for the millions of developers now shipping AI-generated code.
Free tier — no credit card required. Results in 30 seconds.
of AI code fails security tests
Veracode 2025
Lovable apps exposed by CVE-2025-48757
more XSS vulnerabilities in AI vs human code
Nullgaze was built after discovering these numbers. Your users deserve better.
Every scan runs a multi-layer detection pipeline
Scan
Paste any URL. Nullgaze fetches HTML, JavaScript bundles, sourcemaps, .env files, and config endpoints — fast.
Learn
Mark false positives once. Our FSRS-6 spaced repetition memory system remembers per-codebase. Confidence scores adjust automatically.
Protect
On every subsequent scan, known false positives are suppressed, confirmed threats are boosted, and only genuinely new vulnerabilities surface.
Purpose-built for AI-generated code
1import { createClient } from '@supabase/supabase-js'23const supabaseKey = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."CRITICAL4const supabase = createClient(url, supabaseKey)56export async function getUsers() {7 // Missing RLS check8 const { data } = await supabase.from('users').select('*')HIGH9 return data10}1112console.log('Token:', session.access_token)MEDIUM
Secret Detection
60+ regex patterns for AWS, Stripe, Supabase, GitHub, OpenAI, Anthropic, Firebase, and 50+ more services. Plus Shannon entropy analysis for unknown key formats.
AI-Code Anti-Patterns
Memory Intelligence
Built with
Built for developers shipping with
From free scans to full team protection. Your brain gets smarter at every tier.
Free
Try it out
- 3 scans/month
- All detection patterns
- Quick scan depth
- GitHub repo scanning
Starter
For solo developers
- 25 scans/month
- Quick + Deep scans
- GitHub repo scanning
- Brain memory system
- Security badge
Pro
Full power
- Unlimited scans
- All scan depths
- GitHub repo scanning
- AI Trust dashboard
- Wrapped security reports
- API access + CLI
- Brain memory system
- Security badge
- Fast support
Team
$79/seat/mo · min 5 seats
- Everything in Pro
- Shared team brain
- Unlimited GitHub repos
- CI/CD + PR comments
- Merge blocking
- Slack/webhook alerts
- White-label badge
- 1-year retention
Enterprise
Brain Platform
- Cross-repo brain federation
- Brain API access
- Unlimited seats
- SSO / SAML
- Custom detection rules
- Compliance dashboards
- White-label reports
- Brain export & versioning
- Dedicated brain engineer
- SLA guarantee
All plans include HTTPS scanning and redacted findings. API access on Pro+. Cancel anytime.
Join the developers who stopped shipping blind.
No credit card required. First scan is always free.

