Company

Security tooling
that gets out of the way.

We build focused tools for modern software teams — the kind building with AI, shipping fast, and who need security that doesn't slow them down.

Mission

Security teams shouldn't spend hours manually triaging scan results. Developers building with AI shouldn't ship with exposed API keys or misconfigured headers because they didn't know what to check. PatchVex builds tooling that surfaces the right information, in the right format, at the right time — without requiring a security background to use.

What we're building

Web Scanner

A free, no-account website security scanner aimed at developers building AI-assisted apps. Checks TLS, headers, cookies, CORS, and AI-specific risks like exposed LLM API keys. Results in seconds.

Learn more →

VulnPilot

An open-source CLI for security teams managing vulnerability programs. Takes Nessus exports and cross-references against CISA KEV and FIRST EPSS to rank findings by actual exploitation activity — then generates SOC 2 and ISO 27001 audit evidence in one command.

Learn more →

Our values

Local-first

Scan data is sensitive. Where a tool runs locally, it should stay local. VulnPilot processes your vulnerability data entirely on your machine. The Web Scanner only fetches publicly accessible URLs.

No vendor lock-in

You should be able to inspect every line of code that touches your security data. VulnPilot is MIT licensed. The Web Scanner doesn't require an account for its core free function.

Prioritization over volume

Generating a list of 5,000 findings is easy. Helping a team decide what to fix in the next two-week sprint is the hard part. Both products are built around that — not detection as a KPI.

Honest tooling

No fake loading bars. No inflated severity counts to make the product look more valuable. No upsell gates in the middle of a scan. If we find nothing, we tell you.

Get in touch

Questions, feedback, or security disclosures — we read everything.