Builder / vibe coder
Make a clearer launch call
See priority risks, what the review could not prove, and the next action without reading a jargon-only report.

Open beta · Release assurance for AI-built apps
Review the repo, URL, or API you are about to ship. Get scoped findings, approval-gated fixes, a fresh retest, and one shareable release record.
Evidence is limited to the authorized scope and checks that ran. No security guarantee.






From "it works" to "ready to ship"
AI builds fast. LyraShield keeps what you checked, how you checked it, and what changed after in one reviewable record instead of scattered chats and manual checks.
Live in open beta
Review a repository, public URL, or API. Use a passive Lite Check for a quick public-surface read, or create an account for the full evidence loop.
01 / Target
Name your repo, live URL, or API before anything runs. Nothing is tested outside the boundary you explicitly approve.
02 / Review
Deterministic checks find known signals. AI-assisted review examines logic, auth flows, and data handling. Separate coverage layers show what kind of evidence you actually have.
Vibe Security 50
The control ledger separates 43 code or URL review controls from 7 evidence-required controls. Unmatched or unsupported checks remain inconclusive, never silently passed.
43 review controls · 7 evidence-required03 / Evidence
Detected, independently verified, retest-confirmed, and inconclusive remain distinct. Missing proof stays visible; it never becomes a silent pass.
Illustrative evidence ledger
See which check produced the signal, whether independent proof exists, and whether a fresh retest confirmed the change. Shared records omit repository coordinates and raw secrets.
04 / Fix
Review a plain-English explanation and staged patch proposal. PR execution stays blocked until a server-generated patch is bound to your exact approval.
Where you build
Use the hosted MCP server and supported agent integrations to inspect results and prepare approval-gated remediation without copying findings between tools.
05 / Retest
A fresh, server-owned scan checks the fix. Complete deterministic coverage can confirm it; engine-only absence stays inconclusive.
06 / Report
Scope, coverage, findings, fixes, retest outcomes, and limits become one immutable release record. Shared versions exclude repository coordinates and raw secrets.
Scope stated · limitations retainedYour first release record
Create a workspace, add the target you are shipping, and choose the depth of review. LyraShield keeps the resulting scope, evidence, and retest outcome together.
Live URL scan · passive and read-only
Paste your live app URL for a passive check of exposed secrets, browser protections, frontend data-layer signals, and HTTPS. We fetch only the public URL you authorize. No login or installation.
For checks that never leave your browser, use the browser-local tools.
What it covers / what it cannot proveWant the full repo and target loop? Create an account.
A passive check reads what your app already exposes publicly. It can show you what is missing; it cannot prove nothing is wrong. The deeper questions — auth flows, logic, and whether a fix actually held — need the full loop.What the Lite Check covers, and what it cannot prove
Release assurance
Seven of the Vibe Security 50 controls describe practice, not code. The vault collects, reviews, and versions encrypted evidence for audit trails, monitoring, backup tests, sandboxing, test independence, multi-agent trust, and accountable review.
Upload an attestation and encrypted artifacts. A reviewer accepts, rejects, or requests a revision. Every change creates a new version, never an overwrite.
Accepted evidence is captured in immutable private assurance reports. Public shared reports keep AI-assurance data out.
AI safety evaluation
The MCP guard is evaluated against two open frameworks: the OWASP Gen AI Red Teaming Guide and the MLCommons AILuminate demo prompt set. Results, methodology, known limitations, and what this isnot are all public.
42 test cases across 4 assessment areas. 85.7%expected-outcome match rate. 5 bypasses fixed, 2 limitations documented.
Not "OWASP certified." Evaluated against their guidance.
292 content-safety prompts run through the guard to verify it filters injection and does not over-reach into content moderation.
Not MLCommons-certified. Not a score — a scope boundary check.
Builder / vibe coder
See priority risks, what the review could not prove, and the next action without reading a jargon-only report.
Agency / freelancer
Share a scoped report of what was checked and retested without exposing repository coordinates or raw evidence.
Small team / startup CTO
Keep scope, approvals, audit history, and fresh retest outcomes together as your team ships faster.
Create a workspace, add an authorized repository, public URL, or API target, then choose the review depth. LyraShield keeps the resulting scope, findings, evidence states, fix proposals, and fresh retest outcomes in one release record.
Only what the retained evidence supports. We keep detected candidates, independently verified findings, validated fixes (retest-confirmed), inconclusive retests, and checks that were limited or not applicable distinct. Missing proof stays visible.
No. LyraShield creates approval-gated fix proposals that explain the issue and stage a server-generated patch. Every code change requires your explicit review and approval. Nothing auto-merges.
No. LyraShield complements specialist scanners rather than replacing them: SCA, secrets scanning, dependency checks, and repo review are coverage layers inside a wider release-assurance workflow that adds evidence states, approval-gated fix proposals, and retests. Specialist tools may still provide deeper coverage in their own category.
It is a private workspace where you collect, review, and version proof for the seven Vibe Security 50 controls that cannot be established by a repository or URL scan: audit trails, monitoring, backup tests, sandboxing, test independence, multi-agent trust, and accountable review. Accepted evidence is frozen into immutable private assurance reports; public shared reports do not include it.
Live today: the free Lite Check, six browser-local tools, the full release-assurance platform in open beta, the Operational Evidence Vault, an MCP server, GitHub integration, a published CLI, and a GitHub Action with a diff-aware gate and SARIF output. In detail: free Lite Check (passive public URL scan); the full platform with open registration covering target, review, evidence, fix proposal, retest, and report; the Operational Evidence Vault for the seven evidence-required controls; the MCP server for agent-native use; and the GitHub Action running in your own CI. Near-term roadmap: deeper deterministic coverage, richer SARIF interop, and expanded shareable report variants. Published plan prices are available on /pricing; purchase admission remains off during open beta.
Scans run in hardened, short-lived environments. The full platform retains scope, receipts, findings, and evidence states, not a copy of your source. Shared reports exclude repository coordinates, file paths, and raw secrets.
The Lite Check passively reads an authorized public URL for a bounded set of surface signals. The full platform can review repositories, URLs, and APIs, retain control-level evidence, stage approval-gated fixes, run fresh retests, and produce a shareable release record.
Target → review → evidence → retest
Create a workspace, add the target you are shipping, and choose the depth of review. Nothing auto-merges and missing evidence stays visible.