Catch security issues before they reach main.

Zagware Scanner is a free, open-source PR scanner — IaC misconfigurations, dependency vulnerabilities, and leaked secrets, in one container, with a single comment showing only what a PR actually introduces. Add the Git Tracking Platform when you need scan history, audit trails, and compliance reporting across your whole org.

Code editor with a pull request checklist showing scan checks

What we ship

Zagware Scanner — Code Security Scanning

Free, open-source, and self-hostable. Zagware Scanner runs on every pull request across GitHub, GitLab, Bitbucket, and Azure DevOps — combining KICS (IaC), Grype (SCA/dependency CVEs), and betterleaks (secrets) into one container, and diffing by fingerprint so you only see findings the PR introduces.

See how it works →

Git Tracking Platform — Reporting & Compliance

The optional backend for Scanner findings and your GitHub org's activity: scan history and trend charts, suppression audit trails, CIS GitHub Benchmark scans, real-time policy violation alerts, and change-management evidence for SOC-2 audits.

Explore the platform →

About

Zagware builds open-source security tooling for engineering teams. Zagware Scanner is free forever — no account, no lock-in — and detects IaC misconfigurations, vulnerable dependencies, and leaked secrets before they merge. The Git Tracking Platform is the paid backend teams add on when they need reporting, audit trails, and compliance evidence instead of just a PR comment.

We're also a software consultancy: platform integrations across GitHub, GitLab, Jira, ServiceNow, and Grafana, and bespoke internal tooling when off-the-shelf doesn't fit. Eng Team Reporter, pgbrowser, and PR Gate were built the same way we'll build yours — reach out if you need something custom.

Contact

Interested in working together? Reach out and let's talk.

[email protected]