Skip to content
LyraShield AIOpen beta

Free security tools for AI-built apps

Get a useful answer before creating an account. Each focused check runs in your browser, keeps sensitive input on your device, and states what it cannot prove.

Read the guide

WebMCP Security Checker

Check browser-registered WebMCP tools locally for unsafe exposure, missing confirmation, weak schemas, and 7 more assurance controls.

Local analyzer · Files and pasted code never leave your device.

Open tool

AI App Launch Security Checklist

Use a free AI app security checklist to document launch controls, find the most important gaps, and prioritize what to verify before release.

Local analyzer · No code or target data is collected.

Open tool

AI App Security Scanner

Scan selected source files locally for AI-specific security signals mapped to the OWASP Top 10 for LLM Applications (2025).

Local analyzer · Files and pasted code never leave your device.

Open tool

Security Headers and CORS Checker

Paste HTTP response headers into this free local checker to review CSP, HSTS, CORS, clickjacking, referrer, permissions, and cookie signals.

Local analyzer · Headers stay in your browser.

Open tool

Secret Exposure Scanner

Scan selected text files locally for common API keys, access tokens, private keys, and assigned credentials. Matches are redacted and never uploaded.

Local analyzer · Files never leave your device.

Open tool

Supabase RLS Policy Checker

Review pasted Supabase RLS policy SQL locally for missing enablement, permissive rules, bypass risks, and absent ownership or tenant predicates.

Local analyzer · SQL stays in your browser.

Open tool

JWT and Session Inspector

Decode a non-production JWT locally, inspect algorithm and time claims, and review Secure, HttpOnly, and SameSite attributes on session cookies.

Local analyzer · Tokens are decoded locally and are never verified or sent.

Open tool

Free tools questions

How do these free security tools work?

Each tool performs a focused deterministic check in your browser. The page explains exactly what input it reviews, what signals it reports, and what the result cannot establish.

Are inputs uploaded?

No. The checklist, pasted headers, selected files, SQL, JWTs, and cookie values are processed on your device by the page code. Use non-production tokens and review each tool's stated limits.

Does a clear result mean my app is secure?

No. Each tool reports a focused set of signals. A clear result does not prove the whole application is secure; it only means the specific checks did not find a signal.

Need an app-wide assurance record?

The complete product adds authorized target scanning, SCA and secret checks, explicit coverage receipts, evidence states, approval-gated fix proposals, server-owned retests, immutable reports, schedules, notifications, and workspace-scoped audit history. Read the evidence methodology before interpreting a result.

Create a free account