Skip to main content
Free to download — no account needed →
DocsContact
Local-First Security

Security that runs
where your code lives.

HZSec is a local security platform for developers. Scan your project, fix what's broken, and let an AI assistant trained on real breach history watch your back — without a single line of code leaving your machine.

$npm install -g hzsec-cli
40+
detection patterns
6
scan modes
0
bytes to cloud

Free forever · macOS · Windows · Linux · 100% local processing

HZSec — Security Platform
HZSec
▣ Scan Center
◈ Assistant
◎ Live Monitor
≡ Audit Log
⚙ Settings
Security Posture
Score: 78LOW THREATOWASP 71%
CRITICALAWS access key exposed in config
HIGHSSL/TLS disabled in server config
HIGHWildcard CORS policy detected
MEDIUMDebug mode enabled in production
Watch demo
40+
Detection patterns
secrets · configs · code · web · hardening
6
Scan modes
from quick to full-depth analysis
10
Breach cases in AI
Uber · Equifax · Log4Shell + more
0
Bytes to the cloud
everything runs on your machine
Built for Developers

One app.
Scan, defend, govern.

HZSec covers every stage of local security work — from finding what's wrong, to fixing it with AI that knows your code, to proving compliance when the audit comes.

Scan

Find what's already broken.

Six scan modes covering forty-plus detection patterns — secrets, configs, vulnerable code, hardening gaps, web exposure, system risks. Runs in seconds, entirely on your machine.

  • Security Scanner (6 modes)
  • Auto-fixes for common issues
  • Score history & trend chart
  • Audit log of every scan
Explore scanning
Defend

Fix what AI can see clearly.

An AI assistant that's already read your code, matched it against ten real-world breaches, and checked it against live CVE data — before you ask the first question.

  • AI Assistant with codebase context
  • Live Monitor for files & folders
  • Real breach case matching
  • Live CVE database (CISA + NVD)
Explore defending
Govern

Prove you're compliant.

Map every finding to OWASP, CIS, and SOC 2. Track your fix history. Surface long-open or recurring issues before they become an audit problem.

  • OWASP / CIS / SOC 2 mapping
  • Fix memory & recurrence tracking
  • Compliance gap calculations
  • Agentic fixes with diff review
Explore governance
Why This Matters

These breaches started
with issues HZSec detects.

Every breach case is embedded in HZSec's intelligence layer. When the scanner finds a matching pattern, the assistant tells you exactly what happened and how fast it was exploited.

Uber — AWS Keys in GitHub (2022)

57 million records exposed

$148M settlement
< 10 min to exploitHZSec detects: exposed API keys

Equifax — Disabled TLS Monitoring (2017)

147 million records

$575M FTC settlement
78 days undetectedHZSec detects: SSL/TLS disabled

Verkada — Hardcoded Admin Password (2021)

Mass surveillance exposure

150K cameras hijacked
Immediate accessHZSec detects: hardcoded credentials

Log4Shell — Dynamic Execution (2021)

CVE-2021-44228

100M+ systems vulnerable
< 2 hrs after disclosureHZSec detects: unsafe eval/exec patterns

Catch what attackers look for
before you ship.

Free to install, free to scan, free forever on the solo plan. No credit card, no code leaving your machine, no catch.

Free forever · macOS · Windows coming soon · 100% local processing