socbox

About

We catch vulnerabilities at push speed.

Right now you can use our free public code scanner — paste a public Git URL and get a SAST, secrets, CVE, and IaC report, no login. We're building the rest: a container-security platform for engineering teams that ship hourly, not quarterly. We were engineers tired of policy meetings; we're building the gate that should have existed already.

What we do

What's live today is the free public code scanner: paste a public Git URL and get a SAST, secrets, CVE, and IaC report in your browser — no account required. It's the same scanning core everything else is built on.

The platform we're building puts that scan between your CI pipeline and your build output. Every artifact gets a fresh scan — CVEs, secrets, license drift, and policy violations — before it ships. Bad artifacts get blocked at the gate; good ones get a signed attestation and a link to the audit log. This, and everything beyond the public scanner, is coming soon and will live behind an account.

We are a thin, fast layer on top of the open-source security ecosystem. What we add is the policy engine, the multi-tenant control plane, the audit log built for SIEM export, and the kind of UI that doesn't make engineers want to disable scanning.

Why we started

socbox exists because we wanted an easy way for anyone to have a code scanner. We're security enthusiasts — 12+ years of security each, across industries — building a foundation to offer good security at low prices for the shops that can't afford mainstream security tools. We want to help everyone stay secure.

The product follows from that: block at push, don't flood the dashboard, and treat compliance as a side effect of doing the right thing instead of a separate project.

How we work

Contact