Nurbak is an AI pentester for your code. Connect GitHub and our own self-hosted model reads your repo like an attacker would: secrets (even in git history), IDOR, injection and vulnerable dependencies. Each finding can be fixed with a Pull Request. Product Hunt offer: 3 free fix PRs instead of 1.
Hi Product Hunt! I'm Fabián, the solo founder of Nurbak.
You may have seen Nurbak here before: first a one-time-link tool, then uptime monitoring. Talking to developers I kept hearing the same thing: we ship code faster than ever with AI, but a pentest happens once a year, if at all. And many teams don't want to send their code to yet another third-party AI to review it.
So Nurbak is now an AI pentester for your code:
- Connect GitHub and pick a repo, public or private
- Our own self-hosted model reads it like an attacker would: IDOR, injection, SSRF, missing auth, secrets (even in git history), vulnerable dependencies
- Every finding comes with severity, CWE, file and line, explained in plain words
- One click opens the fix as a Pull Request, with a regression test where it applies
The scan runs on our own model on ephemeral infrastructure: your code isn't sent to OpenAI or Anthropic to be scanned, it's deleted when the scan ends, and you can download an audit log of every AI interaction.
Product Hunt offer: sign up today and get 3 free fix PRs instead of 1, plus your security score and top 3 findings in full.
I'd love your honest feedback, especially on false positives. I'll be here all day answering.