Hey, Im Tomek, founder of VulX. I would really appreciate any feedback or criticism.(Not advertisement I dont want your money)
quick backstory: Initially our company had a partnership with a GRC company. We have moved away from it to build something of our own and as of today, its live.
what it is:
The goal is bigger than a scan: every codebase keeping itself current, on its own. Not a report you read once and file away a repo that stays patched, keeps its dependencies honest, and tells you the moment something you shipped last month turned dangerous this morning. the vision of a codebase always being up to date with the latest vulnerabilities
VulX Watch
VulX Watch offers security for the code your AI writes.
AI can build and ship an entire app in hours. The problem? Most builders don't know what security risks the AI may have introduced or what they should even look for.
VulX Watch continuously reads your AI-written code and surfaces what matters: committed secrets, vulnerable dependencies, fake packages, injection patterns, and SQL/RLS issues.
Why VulX is different:
Not another scanner: no PRs, setup, or manual scans. Connect a repo and VulX keeps watching.
Nothing VulX finds can break your build. A scanner sitting in CI has to stay quiet about anything uncertain, because every false positive stops someone's work. VulX isn't in that path, so it can surface the things a gate would have to suppress and tell you how sure it is instead. A borderline finding costs you ten seconds of reading. That's what the confidence levels are for.
Independent from your AI: the tool that wrote your code shouldn't be the one checking its own work.
Evidence-first: every finding shows what was found, where it is, why it matters, and how confident VulX is.
Built for AI workflows: ask VulX about findings directly from Claude or Cursor via MCP.
AI-readable: VulX keeps security guidance in AGENTS.md so your AI has the right constraints when writing the next change.
No auto-fixes: VulX explains the fix in plain English; your own AI reviews and implements it.
Who it's for:
AI-native developers, indie hackers, startups, and teams building with Cursor, Claude, Lovable, Replit, Bolt, v0, and other AI coding tools.
Use it when:
ā You've shipped an AI-built app and want to know what's hiding in it
ā You're iterating quickly and don't want security to become a bottleneck
ā You want ongoing checks without adding another security workflow
Free while we build it.
Connect a GitHub repo: https://app.vulx.ai/signup
Or add VulX to Claude/Cursor via MCP: https://mcp.vulx.ai/mcp
Tell us where a finding doesn't land. That's exactly what we want to improve.