NewThreat Lab & Compliance Lab — turn any scan into a graded, exportable report.Get Pro →
ProLabs & Exports

Prove your teamknows whatit's doing.

Generate, in one click, a Security Assessment and a Compliance Report you can hand to any client, auditor, or investor. Give them proof, not promises.

Everything runs on your machine. Only an anonymized findings summary is sent for AI synthesis.
A real Trojan Compliance Report PDF — grade B, score 79, 197 packages assessed for license and privacy risk.
A real Trojan Security Assessment PDF — grade F, threat index 78, 67 findings across 483 packages.
Real exports · one click
Built from six enginesSAST · CodeSCA · DependenciesSecretsIaC · InfraSBOMDAST · Live web
Two AI Labs

One scan in. Two assessments out.

Each Lab reads your findings and returns an executive-grade verdict — then exports it as a branded, auditor-ready PDF.

Pro
Threat Lab

Security Assessment

Runs your findings through Claude to build an attacker's-perspective threat model — what actually chains together, and what to fix first.

Threat Index (0–100) and letter grade A–FPlain-language verdict & the key risks that matterAttack vectors with severity & exploitabilityRanked priority fixes — command + file:line
Exports PDFExports TXT
Pro
Compliance Lab

Compliance Report

Combines license analysis with privacy & data-flow analysis into one assessment — the legal and regulatory picture, in plain English.

Compliance Grade A–F and score 0–100License verdict — permissive vs. copyleft flaggedPrivacy verdict — PII touched & third partiesPrioritized recommendations for counsel
Exports PDFLegal disclaimer
Anatomy of a report

The output looks
like it cost $5,000.

A branded certificate — grade badge, executive summary, the findings that matter, a unique Report ID and a QR code back to trojancli.com. Hand it to anyone.

1Run any local scan
2Open a Lab, click Generate
3Export to PDF
TROJAN
SECURITY ASSESSMENT
PROJECT
zephwrites
GENERATED
Jul 25, 2026 · 08:16
REPORT ID
L1VZZXJZL3PLCGHH
SECURITY GRADE
C
THREAT INDEX
64/ 100
0 = secure · higher = more exposed
Scan to verify at
trojancli.com
EXECUTIVE SUMMARY

Three findings chain into a plausible account-takeover path: a hardcoded credential grants a foothold, an unrate-limited login enables credential stuffing, and an outdated dependency exposes a known RCE. Individually moderate; together, a critical path. Priority fixes below close it in under a day.

TOP ATTACK VECTORS
VectorSeverityExploit
Credential → account takeoverEasy
SQL injection via user inputModerate
Outdated lodash — known CVEHard
14 findings3 priority fixesSOC 2 · OWASP coverage mappedGenerated by Trojan Security · trojancli.com

Illustrative Security Assessment. The Compliance Report follows the same certificate format with a license-risk table and privacy assessment.

Who it's for

One document, many rooms.

Auditors

Hand over a dated, ID'd assessment that maps to SOC 2 and OWASP — no screen-share required.

Clients

Prove your code is safe before you ship it to them. A branded PDF closes the security-review loop.

Procurement

Answer the vendor security questionnaire with a document instead of a spreadsheet.

Leadership

Give the board a grade and a verdict they can read in a minute — not a raw findings dump.

Local-first

Scanning runs on your machine. Only an anonymized findings summary is sent for AI synthesis — never your code.

AI-explained

Claude turns raw findings into a plain-language verdict a founder — and their board — can actually act on.

One click to PDF

Every Lab exports a branded, auditor-ready certificate with a Report ID and QR code — ready to send.

ProLabs are a Pro feature

Turn your next scan
into a document.

Both Labs, unlimited reports, and PDF export — on every project you scan.

$12/ month
$99/ year · save 31%
Upgrade to ProCompare plans