Skip to content
LyraShield AIOpen beta

Open beta · Release assurance for AI-built apps

Ship AI-built apps with evidence, not hope.

Review the repo, URL, or API you are about to ship. Get scoped findings, approval-gated fixes, a fresh retest, and one shareable release record.

  • Nothing auto-merges
  • Missing evidence stays visible
  • Works with GitHub and coding agents
Using a coding agent? Set up LyraShield →

Evidence is limited to the authorized scope and checks that ran. No security guarantee.

The LyraShield evidence console home view in dark mode. A launch verdict reads "Inconclusive — nothing was checked", above a four-step readiness track of target ready, evidence captured, blockers cleared and assurance shared. The security score shows as unavailable, and 46 open findings are broken down as 3 critical, 6 high, 37 medium and 0 low.The LyraShield evidence console home view in light mode, showing the same "Inconclusive — nothing was checked" launch verdict, readiness track, and 46 open findings broken down as 3 critical, 6 high, 37 medium and 0 low.
The Issues view in the LyraShield console in dark mode. Findings are listed with a severity, an evidence state, an open status, and a CWE and CVSS reference.The Issues view in the LyraShield console in light mode. Findings are listed with a severity, an evidence state, an open status, and a CWE and CVSS reference.
The Coding Agents page in the LyraShield console in dark mode. Cards for Devin, VS Code, Cline, OpenCode, Kilo Code, Zed and more each show a copyable install command.The Coding Agents page in the LyraShield console in light mode. Cards for Devin, VS Code, Cline, OpenCode, Kilo Code, Zed and more each show a copyable install command.
The evidence console, three ways. Dashboard: this run's verdict readsinconclusive — nothing was checked, reported honestly instead of rounded up to a pass. Issues: findings carried with their evidence state, not just a severity. Coding Agents: setup for the client you already use. Account details are blurred throughout.

From "it works" to "ready to ship"

One reviewable record of what you checked, fixed, and retested before you ship.

AI builds fast. LyraShield keeps what you checked, how you checked it, and what changed after in one reviewable record instead of scattered chats and manual checks.

Live in open beta

Start with the surface you need to ship.

Review a repository, public URL, or API. Use a passive Lite Check for a quick public-surface read, or create an account for the full evidence loop.

  • Repository, URL, and API targets
  • GitHub and coding-agent workflows
  • Approval-gated fixes and fresh retests

01 / Target

Choose what you are actually shipping.

Name your repo, live URL, or API before anything runs. Nothing is tested outside the boundary you explicitly approve.

02 / Review

Run checks that do not blur together.

Deterministic checks find known signals. AI-assisted review examines logic, auth flows, and data handling. Separate coverage layers show what kind of evidence you actually have.

Vibe Security 50

Coverage stays explicit, including what needs human evidence.

The control ledger separates 43 code or URL review controls from 7 evidence-required controls. Unmatched or unsupported checks remain inconclusive, never silently passed.

43 review controls · 7 evidence-required

03 / Evidence

Keep "we saw it" separate from "we proved it".

Detected, independently verified, retest-confirmed, and inconclusive remain distinct. Missing proof stays visible; it never becomes a silent pass.

  • Detected
  • Independently verified
  • Retest-confirmed
  • Inconclusive

Illustrative evidence ledger

Every conclusion carries its basis and its limit.

See which check produced the signal, whether independent proof exists, and whether a fresh retest confirmed the change. Shared records omit repository coordinates and raw secrets.

  • Finding and evidence state
  • Control-level coverage receipt
  • Retest outcome and stated limitations

04 / Fix

Get a fix proposal you review. Nothing auto-merges.

Review a plain-English explanation and staged patch proposal. PR execution stays blocked until a server-generated patch is bound to your exact approval.

Where you build

Bring the review loop into your coding agent.

Use the hosted MCP server and supported agent integrations to inspect results and prepare approval-gated remediation without copying findings between tools.

  • OAuth-first agent connections
  • GitHub-aware review context
  • No automatic merge or silent write

05 / Retest

Confirm with a fresh check, not the same conversation.

A fresh, server-owned scan checks the fix. Complete deterministic coverage can confirm it; engine-only absence stays inconclusive.

06 / Report

Ship one report that shows limits too.

Scope, coverage, findings, fixes, retest outcomes, and limits become one immutable release record. Shared versions exclude repository coordinates and raw secrets.

Scope stated · limitations retained

Your first release record

Turn the next release into evidence your team can review.

Create a workspace, add the target you are shipping, and choose the depth of review. LyraShield keeps the resulting scope, evidence, and retest outcome together.

Live URL scan · passive and read-only

See your app's gaps in 30 seconds. Free, no signup.

Paste your live app URL for a passive check of exposed secrets, browser protections, frontend data-layer signals, and HTTPS. We fetch only the public URL you authorize. No login or installation.

For checks that never leave your browser, use the browser-local tools.

What it covers / what it cannot prove

Want the full repo and target loop? Create an account.

What a result looks likeSample values · your result depends on your app
  • Security headers3 missingNo Content-Security-Policy, no HSTS, no X-Content-Type-Options.
  • Frontend data-layer signals1 to reviewA client bundle references a key-shaped string. Worth a look before launch.
  • HTTPS and redirectsCleanValid certificate, HTTP redirects to HTTPS.
  • CORS policyNot applicableNo cross-origin API surface was reachable from the public page.

A passive check reads what your app already exposes publicly. It can show you what is missing; it cannot prove nothing is wrong. The deeper questions — auth flows, logic, and whether a fix actually held — need the full loop.What the Lite Check covers, and what it cannot prove

Release assurance

Operational Evidence Vault

Seven of the Vibe Security 50 controls describe practice, not code. The vault collects, reviews, and versions encrypted evidence for audit trails, monitoring, backup tests, sandboxing, test independence, multi-agent trust, and accountable review.

Submit and review

Upload an attestation and encrypted artifacts. A reviewer accepts, rejects, or requests a revision. Every change creates a new version, never an overwrite.

Freeze into reports

Accepted evidence is captured in immutable private assurance reports. Public shared reports keep AI-assurance data out.

AI safety evaluation

Prompt-injection guard, tested in the open

The MCP guard is evaluated against two open frameworks: the OWASP Gen AI Red Teaming Guide and the MLCommons AILuminate demo prompt set. Results, methodology, known limitations, and what this isnot are all public.

OWASP Gen AI Red Teaming

85.7%

42 test cases across 4 assessment areas. 85.7%expected-outcome match rate. 5 bypasses fixed, 2 limitations documented.

Not "OWASP certified." Evaluated against their guidance.

MLCommons AILuminate

Scope check

292 content-safety prompts run through the guard to verify it filters injection and does not over-reach into content moderation.

Not MLCommons-certified. Not a score — a scope boundary check.

One release record, useful at every handoff

Builder / vibe coder

Make a clearer launch call

See priority risks, what the review could not prove, and the next action without reading a jargon-only report.

Agency / freelancer

Hand off evidence, not a chat transcript

Share a scoped report of what was checked and retested without exposing repository coordinates or raw evidence.

Small team / startup CTO

Make the release review repeatable

Keep scope, approvals, audit history, and fresh retest outcomes together as your team ships faster.

Questions

What happens after I create an account?

Create a workspace, add an authorized repository, public URL, or API target, then choose the review depth. LyraShield keeps the resulting scope, findings, evidence states, fix proposals, and fresh retest outcomes in one release record.

What does a LyraShield result actually prove?

Only what the retained evidence supports. We keep detected candidates, independently verified findings, validated fixes (retest-confirmed), inconclusive retests, and checks that were limited or not applicable distinct. Missing proof stays visible.

Does LyraShield automatically fix my code?

No. LyraShield creates approval-gated fix proposals that explain the issue and stage a server-generated patch. Every code change requires your explicit review and approval. Nothing auto-merges.

Is this a replacement for my other security scanners?

No. LyraShield complements specialist scanners rather than replacing them: SCA, secrets scanning, dependency checks, and repo review are coverage layers inside a wider release-assurance workflow that adds evidence states, approval-gated fix proposals, and retests. Specialist tools may still provide deeper coverage in their own category.

What is the Operational Evidence Vault?

It is a private workspace where you collect, review, and version proof for the seven Vibe Security 50 controls that cannot be established by a repository or URL scan: audit trails, monitoring, backup tests, sandboxing, test independence, multi-agent trust, and accountable review. Accepted evidence is frozen into immutable private assurance reports; public shared reports do not include it.

What is live today and what is on the roadmap?

Live today: the free Lite Check, six browser-local tools, the full release-assurance platform in open beta, the Operational Evidence Vault, an MCP server, GitHub integration, a published CLI, and a GitHub Action with a diff-aware gate and SARIF output. In detail: free Lite Check (passive public URL scan); the full platform with open registration covering target, review, evidence, fix proposal, retest, and report; the Operational Evidence Vault for the seven evidence-required controls; the MCP server for agent-native use; and the GitHub Action running in your own CI. Near-term roadmap: deeper deterministic coverage, richer SARIF interop, and expanded shareable report variants. Published plan prices are available on /pricing; purchase admission remains off during open beta.

Do you store my codebase?

Scans run in hardened, short-lived environments. The full platform retains scope, receipts, findings, and evidence states, not a copy of your source. Shared reports exclude repository coordinates, file paths, and raw secrets.

How is the Lite Check different from the full review?

The Lite Check passively reads an authorized public URL for a bounded set of surface signals. The full platform can review repositories, URLs, and APIs, retain control-level evidence, stage approval-gated fixes, run fresh retests, and produce a shareable release record.

Target → review → evidence → retest

Create your first release record.

Create a workspace, add the target you are shipping, and choose the depth of review. Nothing auto-merges and missing evidence stays visible.

  1. Create workspace
  2. Add target
  3. Choose review
Prefer to work from your coding agent? View agent setup