About
Evidence over promises
LyraShield AI is the evidence-backed release-assurance layer for AI-built software. We believe a security result should say what it knows — and what it does not — rather than turning scanner confidence into a universal verdict.
How LyraShield AI started
After processing 6.8 billion tokens across 2,728 AI coding sessions, our founder noticed something: the most-used tool in his AI workflow wasn't a scaffolding generator or a UI builder — it was a security review plugin, run 232 times. The insight was simple:AI can write code quickly, but most review processes haven't adapted.
Traditional security tools were built for human-written code with human review cadences. AI-generated code changes the equation: code arrives faster, patterns are different, and the review bottleneck shifts from "who writes it" to "who verifies it." LyraShield AI was built to close that gap with a methodology that preserves evidence provenance, coverage limits, and retest state as separate, inspectable facts.
Our mission
We do not claim that a clean scan proves an app is secure. We do not claim universal coverage. We record what was checked, what was verified, and what remains uncertain — then produce an immutable report that stakeholders can inspect. The Vibe Security 50 framework defines 43 code/URL review controls and 7 that require operational or human evidence outside the scan, so you always know the boundary of what a scan can and cannot establish.
Our approach
- Evidence states
- Every finding carries one of four states: detected candidate, independently verified, retest-confirmed, or inconclusive. A score never overrides these facts.
- Coverage receipts
- The Vibe Security 50 framework records per-control coverage: completed, limited, skipped, or not-applicable. You know exactly what was and was not checked.
- Deterministic retests
- When a fix is applied, a server-owned deterministic retest checks whether the condition is actually absent — not just whether the scanner stopped reporting it.
- Immutable reports
- Assurance reports are frozen at creation time with tamper-evident manifests. They can be shared with stakeholders without risk of silent modification.
Founder
Ankit Das
Founder & CEO
AI/ML engineer and 2x EthIndia prize winner with 16+ years of experience across Web3, AI, and application security. Ankit built LyraShield AI after processing 6.8 billion tokens across 2,728 AI coding sessions and realizing that the most-used tool in his own workflow wasn't a scaffolding tool or UI generator — it was a security review plugin. LyraShield AI is the product of that insight: AI can write code quickly, but most review processes haven't adapted.
Credentials & experience
2x EthIndia Prize Winner
Arbitrum Foundation & Scroll Network prizes (2023, solo); Coinbase CDP recognition (2024)
Certified Full-Stack Applied AI Engineer
OpenAI, LLMs, Langchain, Next.js, TypeScript, Node.js
Certified Web3 Developer
Solidity, DeFi, GameFi, NFTs — active since 2017
16+ Years Experience
CTO at FusionwaveAI, Head of Blockchain at Zuraverse, Web3 Consultant at Tegus
Building with AI, daily
From ChatGPT Codex usage data — the real numbers behind the decision to build LyraShield AI.
6.8B
AI tokens processed
across 2,728 coding sessions
232
Security review runs
the most-used plugin in his AI workflow
13h 4m
Longest single session
evidence of building with AI daily
69
Public repositories
Web3, AI, and security tooling
What we believe
- 01
A clean scan is not a security guarantee. A score is an interpretation aid derived from evidence. It does not override the underlying findings, coverage limits, or retest receipts.
- 02
Coverage is a fact, not a feeling. Which checks completed, were limited, were skipped, or did not apply — including retained limitations — must be visible on every report.
- 03
Evidence states are not interchangeable. Detected, independently verified, retest-confirmed, and inconclusive are separate states with distinct meanings. Scanner confidence alone never creates a verified state.
- 04
Fix proposals require approval binding. No Fix PR is opened until a server-generated patch is bound to an exact approval. The human stays in the loop.
- 05
AI-built apps need AI-aware security. Agent rule injection, MCP misconfiguration, and prompt-injected code paths are real risks that traditional SAST tools were not designed to catch.
Contact
For a security vulnerability, follow the coordinated disclosure process so the report reaches the monitored mailbox with the detail we need. For partnership or product questions, email abuse@lyrashieldai.com. Registration is open in the beta — create a free account to start a release record.
See the evidence approach in action.
Read the methodology or try the free browser-local tools.