We are full force into cloud-based AI security scanners. Foil does it on your Mac, locally. Your code never leaves. It doesn't just alert: it explains why, validates the finding, and rewrites the code and does it 100% local, no API, no telemetry, no training the next model with your own code. It's edge AI built for developers, consultant or pentesters after a whitebox test, who can't (or won't) share the code.
As an offensive security expert, I bumped multiple times into white-box application assessment projects where having access to source code speeds up the discovery and testing of vulnerabilities. Every time you run a client's project, code is confidential.
For months, I have been running claude code against my own codebase to find vulns, and despite all the hype for Mythos, it is already working very well.
I started dreaming of a solution that keeps my code confidential, safe, where I am authorised to use AI without leaking the code to a cloud provider. Here I started developing Foil: It's an AI security scanner that runs 100% on locally — no cloud, no API keys, no pay tokens.
I like to think I built the local-alternative, sure it will never be as powerful and precise as a massive Google or Anthropic model, but running on a constrained environment, completely building on M-series (metal gpu of apple silicon), I started realising that it wasn't easy but I could make it. It could be a game changer... excited, it works, certainly there is space for improvement but it's just the beginning of the journey...
thank you guys for voting, helping, sharing this initiative = helping me and other people to make it better = getting an awesome product...
Foil AI Code Security
DiffSense
Cool! What model is it running on?
Foil AI Code Security
read at the medium article to understand how it works: https://medium.com/@vito.rallo/your-code-on-their-servers-the-case-for-local-ai-security-scanning-974f4cdc94af