NewTrojan 2.1 — private org rules and scan history are live in Pro.See what's new →
Security without the security team

Your security team,
until you hire one.

Agentic AI-powered penetration testing. Static code analysis. Dependency and privacy scanning. MCP-native. Investor-ready reports. All on your desktop.

Run your first scanDownload for macOSDownload for Windows

macOS (Apple Silicon) · Windows (x64) · v0.2.1 · CLI also available

Why Trojan

01

No security expertise needed

AI reads every vulnerability found by the scanners and explains it in your terms — based on how much technical knowledge you have. You don’t need to be tech-savvy to ship your ideas in peace.

02

Local-first

Your code never leaves your machine. No cloud uploads, no third-party access. Keep your sensitive codebase private while you scale.

03

Investor-ready reports

When a client or VC asks about your security posture — one click generates a professional report. Go from “we’ll get to it” to “here’s our latest scan” in seconds.

What Trojan catches

Leaked secrets

API keys, tokens and passwords committed by accident — the number-one way small teams get breached. Trojan finds them in your history, not just the latest commit.

Risky dependencies

Known vulnerabilities in the open-source packages you install, matched to public advisories — with the safe version to upgrade to.

Dangerous code

Injection, broken auth, unsafe defaults — the patterns attackers probe for first. Trojan reads intent, not just keywords.

Plain-English fixes

Every finding explains the risk in words a founder can act on, and the exact change for the engineer. No CVE jargon required.

ProLabs & Exports

Prove your team
knows what it's doing.

Generate, in one click, a Security Assessment and a Compliance Report you can hand to any client, auditor, or investor. Give them proof, not promises.

Pro
Threat Lab

Attacker's-perspective threat model — grade, threat index, attack vectors and ranked fixes.

Pro
Compliance Lab

License & privacy assessment — grade, copyleft flags, PII data flows and recommendations.

A real Trojan Compliance Report PDF — grade B, score 79, 197 packages assessed for license and privacy risk.
A real Trojan Security Assessment PDF — grade F, threat index 78, 67 findings across 483 packages.
Real exports
Trojan — what one scan coversTRJ-01Rev 2.1
No.CoverageValueRemark
01Detection rules3,400+Updated weekly from public advisories
02Languages supported14JS/TS, Python, Go, Ruby, Rust, Java…
03Median scan time4.2 sOn a 100,000-line repository
04Code sent to our servers0 bytesScanning runs entirely on your machine
Private by default

Your code never
leaves your machine.

Most scanners upload your source to their cloud. Trojan doesn't. The entire scan runs locally — on your laptop or inside your own CI. We can't see your code, because we never receive it.

Runs locallyNo source uploadWorks offline & air-gapped
Read the privacy policy →
How Trojan ranks risk

Five levels.
Ranked, not colored.

No wall of red. Trojan sorts every finding by how likely it is to be exploited and how much it would hurt — so you always know what to do first, and when it's safe to stop.

CRITICALExploitable right now. Fix before you ship.
HIGHLikely exploitable. Fix this week.
MEDIUMWorth fixing. Put it on the board.
LOWMinor. Fix it when you're nearby.
INFOGood to know. No action needed.
Pricing

Start free. Upgrade when you need more.

Free
$0/month

Full scanning engine. Up to 5 reports. No card required.

All five scanners (Semgrep, Trivy, Gitleaks, Checkov, Syft)Up to 5 low & medium vulnerability reportsLocal web UI reportPre-commit hook integrationCI mode with SARIF output
Start for free
ProMost popular
$12/month
Billed monthly · Save 31% annually

Full reports, AI explanations, fix instructions, MCP integration.

Everything in FreeFull report — all severities unlockedSimply — plain-English vulnerability explanationsActions — step-by-step fix instructionsWatch mode — live updates as you fixMCP integration for Claude, Cursor & Copilot
Get Pro
TeamBest value
$39/month
5 seats · $7.80/seat/month

Pro features for your whole team. One subscription, everyone covered.

Everything in ProShared team subscriptionEach developer scans on their own machineOne bill for the whole teamPriority support
Get Team
See full plan comparison →
Start now

Ready to see what's
hiding in your code?

Run your first scan in under a minute. No account, no credit card, nothing uploaded.

Run your first scan$npx trojan scan