Golem AI
The security layer for vibe-coded apps. Golem AI is a security audit platform that runs full-scope offensive audits against your web and mobile apps from an external attacker’s point of view. You register an app, prove you own it, and launch an audit. A deterministic baseline scanner and an AI red-team agent in a hardened sandbox perform reconnaissance, enumerate your attack surface, identify vulnerabilities, attempt exploitation, and deliver evidence-backed findings — in minutes to hours. Behind every audit is Golem, an autonomous red-team agent with full access to a pre-built offensive toolkit: nuclei, subfinder, httpx, katana, ffuf, sqlmap, dalfox, and custom probes. The agent plans its own attack chain, executes commands in a real shell, and captures evidence for everything it reports.Start here
Quickstart
Add your app and run your first audit.
Core Concepts
Apps, drafts, audits, findings, and the Golem agent.
Attack Methodology
The phased chain Golem executes on every engagement.
API Reference
Programmatic access to apps, audits, findings, and reports.
Audit modes
What you get from every audit
- Findings — confirmed vulnerabilities with severity, evidence, and remediation
- Security score — a 0–100 score and letter grade with a full, auditable breakdown
- Coverage summary — proof of what was actually tested, so a partial scan can never look like a clean bill of health
- Markdown report + PDF — executive summary, findings with evidence, and remediation priorities
- CVE enrichment — CVSS, CISA KEV, and EPSS context on every finding that maps to a published CVE
- CVE Intelligence — a live catalog of every published CVE, plus per-app exposure tracking
- Slack + email notifications — audit created, completed, failed, and critical-finding alerts