Nullgaze learns your codebase over time. It remembers false positives, discovers new patterns, and gets smarter with every scan. Built for the millions of developers now shipping AI-generated code.
Hacker tier — no credit card required. Results in 30 seconds.
of AI code fails security tests
Veracode 2025
Lovable apps exposed by CVE-2025-48757
more XSS vulnerabilities in AI vs human code
Nullgaze was built after discovering these numbers. Your users deserve better.
Every scan runs a multi-layer detection pipeline
Scan
Paste any URL. Nullgaze fetches HTML, JavaScript bundles, sourcemaps, .env files, and config endpoints — fast.
Learn
Mark false positives once. Our FSRS-6 spaced repetition memory system remembers per-codebase. Confidence scores adjust automatically.
Protect
On every subsequent scan, known false positives are suppressed, confirmed threats are boosted, and only genuinely new vulnerabilities surface.
Purpose-built for AI-generated code
1import { createClient } from '@supabase/supabase-js'23const supabaseKey = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."CRITICAL4const supabase = createClient(url, supabaseKey)56export async function getUsers() {7 // Missing RLS check8 const { data } = await supabase.from('users').select('*')HIGH9 return data10}1112console.log('Token:', session.access_token)MEDIUM
Secret Detection
60+ regex patterns for AWS, Stripe, Supabase, GitHub, OpenAI, Anthropic, Firebase, and 50+ more services. Plus Shannon entropy analysis for unknown key formats.
AI-Code Anti-Patterns
Memory Intelligence
Built with
Built for developers shipping with
From Hacker to Enterprise. Your brain gets smarter at every tier.
Hacker
Free forever
- 5 scans/month
- All 701 detection patterns
- Quick + Deep scans
- Full FSRS-6 brain
- GitHub repo scanning
- SBOM export
- Competitor benchmark
- Security badge
Pro
Full power for solo devs
- Unlimited scans
- All scan depths
- LLM deep analysis
- Attack path chains
- Risk diff comparison
- PR Guardian CI/CD
- Security certificates
- Breach cost estimates
- AI Trust dashboard
- 10K API calls/mo
Team
Flat rate · 10 seats included
- Everything in Pro
- 10 seats included
- Shared team brain
- Compliance autopilot
- Scheduled scans
- 50K API calls/mo
- CI/CD + merge blocking
- Slack/webhook alerts
- Unlimited retention
- Priority support
Enterprise
Unlimited everything
- Everything in Team
- Unlimited seats
- Federated brain
- SSO / SAML
- Custom detection rules
- Unlimited API access
- White-label reports
- Dedicated support + SLA
All plans include HTTPS scanning and redacted findings. API access on Pro+. Cancel anytime.
Join the developers who stopped shipping blind.
No credit card required. Hacker tier is free forever.

