Comments
>log in to commentHey everyone 👋 I'm Yaman, the founder of InsurStaq. I built it because most security tools want your source code on their servers, and a lot of teams can't send it. So everything runs on your Mac. Point InsurStaq at a repository and it shows you: • attack paths an outsider could reach, down to the file and line • exposed secrets, including old ones in Git history • vulnerable dependencies and infrastructure-as-code risks • readiness evidence for SOC 2, ISO 27001, PCI DSS and OWASP ASVS You can ask it about your own code in plain English. InsurStaq's own security model, fine-tuned for security work, explains findings and drafts fixes. Nothing changes until you confirm, and every fix is re-scanned on your Mac. It needs macOS 14 or later and is built for Apple silicon. Plans start at $19/month. I'd love your feedback, especially on what it finds (or misses) in your own repos. I'm here to answer questions.
- Local AI code security scanner for macOS
- Runs entirely on-device, no code leaves the Mac
- Traces attack paths and proposes fixes
- Supports Apple silicon, macOS 14 or later
- Offers team and enterprise plans for security firms
InsurStaq is a private AI security engineer that scans code locally on macOS, maps attack paths, suggests fixes, and generates audit evidence.
- for
- Developers and security teams who want to scan their own code on their Mac, without uploading it.
- pricing
- paid
- license
- MIT
Key features
- Full-stack attack graph — Maps routes, auth, inputs, sinks and builds a security graph showing attacker paths.
- AI-generated fixes — Drafts fixes for findings. Nothing changes until you approve, and each fix is re-scanned on your Mac.
- Compliance evidence — Exports technical evidence mapped to SOC 2, ISO 27001, PCI DSS and OWASP ASVS.
- Guard mode — Checks the code you and your AI coding tools change for new security issues before you ship.
- Zero-cloud privacy — All scanning, graph building and model inference run on the Mac; no source code leaves the device.
Use cases
- Identify and close injection paths before code is shipped
- Generate SOC 2 audit evidence directly from code
- Catch new security issues in changed code before it ships
- Check what Cursor, Claude Code or Codex changed before you commit
InsurStaq FAQ
Does any code leave my machine during scanning?+
No, all scanning, graph building and model inference run locally and no source code is uploaded.
Can InsurStaq work with my existing editor or AI coding assistant?+
Yes, optional plugins let Cursor, Claude Code, Codex and GitHub Copilot query a local InsurStaq process for verdicts.
What compliance frameworks does InsurStaq support for evidence?+
It maps findings to SOC 2, ISO 27001, PCI DSS and OWASP ASVS.
How does InsurStaq differ from traditional static scanners?+
Instead of listing line-level issues, it shows the full attacker path from input to sink and drafts a fix you approve, re-scanned on your Mac.
Is there a free tier or trial?+
Plans start at $19/month. You can explore the product demo and sample findings on insurstaq.ai before buying.
Edited by the makers, based on insurstaq.ai · Oct 5, 2026. Details may change; check the official site.








