Welcome to the Platform
This is a comprehensive repository and extension security analysis platform that helps you identify and understand security risks in your code and extensions.
What is This Platform?
This platform provides comprehensive security analysis for your repositories, extensions, and vendors. Uncover security vulnerabilities, code quality issues, and compliance concerns with detailed reports and actionable insights. Make informed security decisions with AI-powered assessment capabilities.
Key Features
- Code & Extension Security: Analyze repositories, browser extensions, NPM packages, and custom code for vulnerabilities and compliance issues
- Vendor Security Assessment: AI-powered vendor due diligence with document analysis, security questionnaires, and compliance artifact review
- Detailed Risk Reports: Get risk grades, severity levels, and file-level findings with actionable remediation guidance
- Scheduled Scans & Automation: Set up recurring scans to track security over time and integrate with your CI/CD pipelines
- Team Collaboration: Invite team members, manage sub-organizations, and share reports to improve security awareness
- Flexible Deployment: Use your own Anthropic API key (BYOK) or the platform's shared key with full control over your data
Getting Started
New to this platform? Start here:
- Sign Up & Login — Create your account and get started
- Platform Navigation — Learn your way around the dashboard
Repository & Code Security
Ready to analyze your code?
- Submit a Repository — Submit a repository for analysis by Git URL
- Submit a Browser Extension — Upload or analyze a browser extension
- Submit a Source Code ZIP — Upload any
.ziparchive of source code for analysis - Submit an NPM Package — Analyze an NPM package from npmjs.com
- Monitor Scan Progress — Track your analysis in real-time
- Pre-processing & Chunking — What happens behind the scenes before AI analysis (large repos)
- View Security Reports — Understand your findings and risk levels
- Open Source Intelligence Analysis — Understand package inventory, advisory coverage, and confirmed malware matches
- Sensitive Data Exfiltration Override — How scans that exfiltrate ultra-sensitive data are automatically capped at grade D
- Share Reports — Share results with your team or grant individual user access
- Export as Markdown — Download reports in Markdown format
Vendor Security Review
Assess third-party security with AI-powered due diligence:
- Vendor Security Review — Comprehensive vendor assessment with document analysis, questionnaires, and security scoring
Team Collaboration & Organization
Manage teams and organize your platform:
- Team Management — Invite and manage team members for collaboration
- Read-Only Roles — Grant view-only access to team members and stakeholders
- Demo Mode — Configure a shared, read-only demonstration environment
- Sub-Organizations — Create and manage sub-organizations within your account (Tier 3)
- Organization Settings — Configure your organization preferences
Advanced Features
Explore additional platform capabilities:
- Scan History — Review past scans and re-analyze repositories
- Automated Scheduling — Set up recurring scans for continuous monitoring
- File Result Retention — Optionally remove repository-unique file details for sensitive codebases
- Account Security & Passkeys — Manage passkeys and account security
Bring Your Own Key (BYOK) Configuration
Using your own Anthropic API key?
- BYOK Overview — Understand Bring Your Own Key
- Anthropic Setup — Create an account and get an API key
- Platform Configuration — Add your API key to the platform
- Key Management — Maintain and rotate your keys
- Troubleshooting — Resolve common BYOK issues
Integrate & Automate
Use the API to integrate security scanning into your CI/CD pipelines and tooling:
- API Reference Overview — What the API offers and plan tier requirements
- Authentication — Generate API keys and use them as bearer tokens
- Endpoints — Full list of available operations with request/response fields
- Examples — Ready-to-run curl and Python snippets
- Error Reference — HTTP error codes and how to resolve them
Release Notes
- v2.0.0 — Rebranded to "Can I Run That?", pre-processing status for large scans, subscription management features, critical security updates, and hardened security controls
- v1.2.0 — Vendor security reviews, API access, generic ZIP upload, malicious code detection, and security updates
- v1.1.0 — Multi-tenancy sub-organizations, security hardening, and BYOK improvements
- v1.0.1 — Passkey authentication, NPM analysis, report sharing improvements
Help & Support
- FAQ & Common Errors — Solutions to frequent issues
- Contact Support — Get help from our team