Guardn is a code security scanner and browser IDE with 300+ rules covering secrets, injection, insecure patterns, dependency risks, infrastructure misconfigurations, and supply chain vulnerabilities. Every scan result is cryptographically signed with post-quantum attestation (ML-DSA-65).
How do I scan code?
Navigate to the Code Editor, paste or write code, and Guardn scans automatically as you type. You can also use the Scan page to paste code or point to a file path. Results appear instantly with severity ratings and remediation guidance.
What does the score mean?
The security score (0-100) reflects the severity and quantity of findings. 90+ is excellent, 70-89 is good, 50-69 needs attention, and below 50 indicates critical issues. The score weights critical and high findings more heavily.
Features
AI Security Chat
The AI assistant has context about your current code and findings. Ask it to explain vulnerabilities, suggest fixes, or review your security posture. It can also execute terminal commands with your approval.
PQ Attestation
Post-quantum attestation uses ML-DSA-65 (NIST FIPS 204) to cryptographically sign scan results. This proves results haven't been tampered with and provides a verifiable audit trail. When CycleCore PQCaaS is available, signatures are chained; otherwise, local SHA-256 fallback is used.
Scan History
Every scan is saved with full findings, scores, and timestamps. You can filter by severity or filename, export to CSV, and compare scans to track security improvements over time.
Custom Rules
Pro and Team plans support custom regex rules. Define patterns specific to your codebase or organization's security policies.
Keyboard Shortcuts
Ctrl+K
Open command palette
Ctrl+?
Show keyboard shortcuts
Ctrl+S
Save current file
Ctrl+N
New file
Ctrl+B
Toggle sidebar
Ctrl+J
Toggle terminal
Security & Privacy
Where is my code stored?
Code scanned via paste is processed in-memory and not persisted to disk. Files in the workspace are stored locally in your browser session. Scan results (findings only, not source code) are stored in an encrypted SQLite database on the server.
Is my API key safe?
AI provider API keys are stored in your browser's localStorage only. They are never sent to Guardn's servers -- they're sent directly to the AI provider (Anthropic, OpenAI, Groq, or your local Ollama instance).