Live now· #34 this week
InsurStaq

InsurStaq

Private AI security engineer for your Mac

SubscriptionAISecurity149 impressions#34 this week1 comment

Comments

>log in to comment
  • Yaman Khetan[maker]· 1d ago

    Hey everyone 👋 I'm Yaman, the founder of InsurStaq. I built it because most security tools want your source code on their servers, and a lot of teams can't send it. So everything runs on your Mac. Point InsurStaq at a repository and it shows you: • attack paths an outsider could reach, down to the file and line • exposed secrets, including old ones in Git history • vulnerable dependencies and infrastructure-as-code risks • readiness evidence for SOC 2, ISO 27001, PCI DSS and OWASP ASVS You can ask it about your own code in plain English. InsurStaq's own security model, fine-tuned for security work, explains findings and drafts fixes. Nothing changes until you confirm, and every fix is re-scanned on your Mac. It needs macOS 14 or later and is built for Apple silicon. Plans start at $19/month. I'd love your feedback, especially on what it finds (or misses) in your own repos. I'm here to answer questions.

InsurStaq is a private AI security engineer for your Mac. Point it at a repo: it maps routes and auth, finds injection, exposed secrets (Git history too), vulnerable dependencies and IaC risks, and traces attack paths from the internet to the exact line. InsurStaq's own security model, fine-tuned for security work, explains findings and drafts fixes you approve, each re-scanned on your Mac. Readiness evidence for SOC 2, ISO 27001, PCI DSS and OWASP ASVS. Your code never leaves the machine.
  • Local AI code security scanner for macOS
  • Runs entirely on-device, no code leaves the Mac
  • Traces attack paths and proposes fixes
  • Supports Apple silicon, macOS 14 or later
  • Offers team and enterprise plans for security firms

InsurStaq is a private AI security engineer that scans code locally on macOS, maps attack paths, suggests fixes, and generates audit evidence.

for
Developers and security teams who want to scan their own code on their Mac, without uploading it.
pricing
paid
license
MIT
KarmSakha/insurstaq-plugins 0 0Shellupdated a day ago
works withCursorClaude CodeCodexGitHub CopilotVS CodeXcodeJetBrainsTerminal

Key features

5 features of InsurStaq
  • Full-stack attack graph — Maps routes, auth, inputs, sinks and builds a security graph showing attacker paths.
  • AI-generated fixes — Drafts fixes for findings. Nothing changes until you approve, and each fix is re-scanned on your Mac.
  • Compliance evidence — Exports technical evidence mapped to SOC 2, ISO 27001, PCI DSS and OWASP ASVS.
  • Guard mode — Checks the code you and your AI coding tools change for new security issues before you ship.
  • Zero-cloud privacy — All scanning, graph building and model inference run on the Mac; no source code leaves the device.

Use cases

  • Identify and close injection paths before code is shipped
  • Generate SOC 2 audit evidence directly from code
  • Catch new security issues in changed code before it ships
  • Check what Cursor, Claude Code or Codex changed before you commit

InsurStaq FAQ

Does any code leave my machine during scanning?+

No, all scanning, graph building and model inference run locally and no source code is uploaded.

Can InsurStaq work with my existing editor or AI coding assistant?+

Yes, optional plugins let Cursor, Claude Code, Codex and GitHub Copilot query a local InsurStaq process for verdicts.

What compliance frameworks does InsurStaq support for evidence?+

It maps findings to SOC 2, ISO 27001, PCI DSS and OWASP ASVS.

How does InsurStaq differ from traditional static scanners?+

Instead of listing line-level issues, it shows the full attacker path from input to sink and drafts a fix you approve, re-scanned on your Mac.

Is there a free tier or trial?+

Plans start at $19/month. You can explore the product demo and sample findings on insurstaq.ai before buying.

Edited by the makers, based on insurstaq.ai · Oct 5, 2026. Details may change; check the official site.