Golem AI

The security layer for vibe-coded apps. Golem AI is a security audit platform that runs full-scope offensive audits against your web and mobile apps from an external attacker’s point of view. You register an app, prove you own it, and launch an audit. A deterministic baseline scanner and an AI red-team agent in a hardened sandbox perform reconnaissance, enumerate your attack surface, identify vulnerabilities, attempt exploitation, and deliver evidence-backed findings — in minutes to hours. Behind every audit is Golem, an autonomous red-team agent with full access to a pre-built offensive toolkit: nuclei, subfinder, httpx, katana, ffuf, sqlmap, dalfox, and custom probes. The agent plans its own attack chain, executes commands in a real shell, and captures evidence for everything it reports.
Golem AI is offensive security tooling. You are responsible for ensuring you have explicit written authorization to test every target. Apps must be verified before Golem audits them, and every audit requires accepting the authorized-testing terms.

Start here

Quickstart

Add your app and run your first audit.

Core Concepts

Apps, drafts, audits, findings, and the Golem agent.

Attack Methodology

The phased chain Golem executes on every engagement.

API Reference

Programmatic access to apps, audits, findings, and reports.

Audit modes

What you get from every audit

  • Findings — confirmed vulnerabilities with severity, evidence, and remediation
  • Security score — a 0–100 score and letter grade with a full, auditable breakdown
  • Coverage summary — proof of what was actually tested, so a partial scan can never look like a clean bill of health
  • Markdown report + PDF — executive summary, findings with evidence, and remediation priorities
  • CVE enrichment — CVSS, CISA KEV, and EPSS context on every finding that maps to a published CVE
  • CVE Intelligence — a live catalog of every published CVE, plus per-app exposure tracking
  • Slack + email notifications — audit created, completed, failed, and critical-finding alerts