Open research.
Open code.
We build in the open, contribute to the ecosystem, and share what we learn so the entire security community benefits.
Tools we built
for everyone.
MCP server that brings the full S4E platform into your AI assistant. Connect Cursor, Claude Desktop, Claude Code, VS Code, or Windsurf and manage assets, launch Full/Light/Crawler scans, read findings, tune crawling, and review posture, all in natural language over HTTP. Per-user API token auth; no credentials stored on the server.
View on GitHubReal-time security alert client. Monitors your assets continuously and fires notifications the instant a new vulnerability appears, a port opens, or a certificate expires.
View on GitHubPre-built scan sequences for compliance, pentest, and reconnaissance. PCI-DSS, ISO 27001, full attack surface mapping. Select a goal, hit run, S4E does the rest.
View on GitHubA security layer between AI coding agents and your shell. Every command Claude Code, Cursor, or Codex suggests passes through ShellGuard first: logged, policy-checked, and blocked or allowed. Single Go binary, sub-millisecond overhead.
View on GitHubNative macOS menu bar app for ShellGuard. One-click hook setup for every AI tool, live activity log, mode switching, and a policy editor, all from the menu bar. The security logic lives in the CLI; this is the GUI layer on top.
View on GitHubWe give back
to the ecosystem.
Security intel,
always one tab away.
Install the S4E extension and get a live security snapshot of every site you visit severity breakdown, active findings, and instant scan access right from your browser toolbar.


Real-world data
for researchers.
Aggregated and fully anonymized vulnerability scan data, available to academic researchers and security professionals. No PII, no raw targets pure signal for your research.
Request AccessWant to collaborate?
Reach out if you're working on security research, open source tooling, or data sharing initiatives.