ARC AI Security Scanner

ARC AI Security Scanner

Defensive security review for AI applications — agents, MCP, RAG, prompts and data flows.

Free, no accountOpen source (MIT)Nothing stored19 deterministic rules
Remove secrets, credentials, API keys, access tokens, and customer data before you paste. Use sanitized architecture and configuration text. If a live credential is detected, the request is refused and nothing is stored — rotate the credential anyway. This tool does not exploit systems; it only reviews what you describe.
0 / 40,000
Nothing you paste is stored or used for training. Data policy

How this works

Your text is split into statements and matched against a published pack of deterministic rules. Every finding quotes the sentence that triggered it and names the rule id, so you can check the reasoning rather than trust it. The score comes from a fixed rubric, not from a model. Where the description is silent, the report says so instead of filling the gap.

This is a defensive configuration review — not a penetration test, not exploitation guidance, and not a compliance certification.

The full rule catalog is published at /docs. Same engine, same rules, no hidden scoring.