ARC AI Security Scanner

Roadmap

ARC AI Security Scanner is at the beta stage. This page is the real plan, not a marketing page — items move only when they actually ship. Anything not listed here is not planned, and the fastest way to change that is to open an issue.

Shipped

  • Deterministic rule engine with published SEC-* rule ids
  • Evidence-backed findings — every finding quotes your own words
  • Security surface inventory from the text you submit
  • Published scoring rubric with per-dimension explanations
  • 19-rule pack across boundary, tools, RAG, secrets, observability, egress
  • Sequenced defensive blueprint tied to the findings that produced it
  • Honest limitations block, including what could not be seen
  • Free public API plus JSON and Markdown export
  • Golden-case suite including thin, healthy, and adversarial inputs
  • Production deploy at arc-ai-security-scanner.vercel.app

Next

  • Expanded rule pack from real submissions and reported false positives
  • Optional model-assisted narrative — phrasing only, never a new claim or number
  • Shareable report link with an expiring, revocable URL
  • PDF export in addition to Markdown and JSON

Later

  • Structured step-by-step input as an alternative to free text
  • Document upload, once a safe parsing path is in place
  • Comparison between two assessments over time
  • Deeper integration with the other ARC Labs assessments
  • Optional read-only repository scan

Out of scope

Active exploitation, credential testing, malware analysis, destructive actions, scanning arbitrary third-party targets, and any “certified secure” claim. See the repository for the full product brief.