Institutional-grade, 100% local auditing platform.
Unified security reporting with SARIF 2.1.0 support.
Modular "Scanners" (Hunter, Linter, Docker Diff) allow for easy extension. Wrap industry-standard engines like Trivy, Checkov, and Kubeval as plugins.
High-contrast minimalist UI with a "Swiss-style" design. One-button audit for your entire infrastructure stack with standardized severity reporting.
Correlates findings between tools to detect complex risks. Match unused keys to K8s deployments and identify security gaps others miss.
Every finding follows the SARIF 2.1.0 standard. Seamlessly pipe results into GitHub Advanced Security, SonarQube, or DefectDojo.
Gatekeeper mode blocks builds with CRITICAL or HIGH findings. Integrate seamlessly into your existing pipelines.
100% local execution. No external API calls, zero data leakage. Your code never leaves your machine.
Standardized scanner for orphaned configuration keys within repository files.
Configurationshield hunt-configSecurity-focused linter for Kubernetes manifests, checking for privilege escalation.
Kubernetesshield k8s-lintDeep layer inspection and security risk scoring for comparing container versions.
Containersshield docker-diffEntropy-based leakage detection obeying .shieldignore whitelisting constraints.
Secretsshield scan-secretsOffline structural policy enforcer analyzing AWS JSON and Terraform HCL.
Cloudshield iam-validateAnalyzes requirements.txt and package.json against the OSV database.
Dependenciesshield osv-scanSecurity-focused linter for OpenAPI 3.x and GraphQL SDL specifications.
API Securityshield api-lintFull certificate chain and cipher suite auditor (A–F grading) for all endpoints.
Networkshield tls-auditMap privilege escalation paths in AWS/Terraform IAM using graph analysis.
IAM Analysisshield iam-analyzeGenerate CycloneDX 1.6 or SPDX 2.3 bill of materials with license risk scoring.
Supply Chainshield sbom-genBuild minimal seccomp/AppArmor security profiles using static/eBPF analysis.
Runtimeshield capsuleZero data leakage. No external API calls are made for code analysis.
Privacy CoreDevOpsShield is built on a foundation of absolute privacy. We believe security tools shouldn't require you to sacrifice the very thing they're meant to protect.
Join the growing community of DevOps engineers who've made the switch to local-first, privacy-focused security auditing.