Third-party software review

Review third-party software
before you approve it.

When someone asks, "Can I run that?", IT and security teams use CIRT to review source code and vendor security evidence, identify material gaps, and produce a defensible, shareable approval or deployment decision. Most reviews produce decision-ready output within minutes.

Built by a board-certified digital forensics examiner and expert witness20+ years in security and investigations

Evidence-linked findingsEncrypted at rest and in transitBring your own key available
Read-only product demo

See Can I Run That? in action

Explore a read-only demo with completed software and vendor reviews already loaded. See the actual workflow, findings, reports, and approval experience before signing up.

  • No account required
  • Read-only environment
  • Sample data already loaded
Explore the Live Demo
Evidence path 01

Source code evidence

Software, extensions, packages, repositories, and authorized archives.

Evidence path 02

Vendor security evidence

SaaS and commercial software documentation, including SOC 2 reports, penetration-test summaries, questionnaires, and trust-center evidence.

Shared outcome Evidence-backed approval decision

Documented, defensible, and ready to share.

01 / THE TRIGGER

When someone asks,
"Can I run that?"

A software or SaaS request reaches IT or security. CIRT organizes the available evidence into a repeatable review so the team can make a defensible approval decision.

01

A user wants a browser extension

Review what the extension does, the permissions it requests, and the material risks before approving installation.

02

Sales wants a SaaS tool by Friday

Read the vendor's SOC 2, penetration-test summary, questionnaire, and trust evidence without losing days to manual extraction.

03

A developer adds an NPM package

Evaluate provenance, install behavior, vulnerabilities, licensing, and supply-chain signals before it reaches production.

04

A client needs a documented approval

Give MSP and consulting clients a consistent, branded report instead of an undocumented yes or no.

START WITH THE AVAILABLE EVIDENCE

Two evidence paths. One approval decision.

Choose the path that matches the request. Both turn different forms of evidence into the same documented organizational decision.

WHO IT'S FOR

The people who have to make the call.

01

IT & GRC teams

Make documented software approvals without hours of inconsistent manual review.

02

MSPs

Turn repeatable third-party reviews into a documented client service.

03

Compliance teams

Produce due-diligence evidence for auditors, frameworks, clients, and leadership.

02 / PROCESS

Separate evidence paths.
One decision framework.

Source-accessible software and vendor documents need different review methods. Both support the same organizational approval decision.

PROCESS 01

Vendor security documentation review

For commercial software and SaaS evaluated through vendor-provided evidence.

  1. 01
    SUBMIT

    Provide vendor evidence

    Upload SOC 2 reports, penetration-test summaries, questionnaires, or trust-center exports.

  2. 02
    EVALUATE

    Analyze controls and gaps

    Identify covered controls, missing information, evidence gaps, and vendor risk signals.

  3. 03
    DECIDE

    Review the decision report

    Use cited evidence and documented uncertainty to make the final deployment decision.

VENDOR REVIEW OUTPUTDeployment Decision ReportControl coverage, evidence gaps, risk signals, and executive summary.
PROCESS 02

Automated source code security review

For public repositories, browser extensions, NPM packages, and authorized ZIP archives.

  1. 01
    SUBMIT

    Provide the software

    Share a public repository, extension, package, or authorized source archive.

  2. 02
    ANALYZE

    Run security analysis

    Apply a repeatable framework built from security and forensic practice.

  3. 03
    DECIDE

    Review the code report

    Inspect grades, evidence-linked findings, prioritized risks, and license status.

CODE REVIEW OUTPUTDeployment Decision ReportRisk grade, score, severity findings, executive summary, and license status.
03 / SIGNALS

Evidence before confidence.

The report separates what the evidence supports, what remains uncertain, and what needs human judgment.

01

Software provenance

Origin, release process, packaging consistency, and supply-chain context.

02

Organizational exposure

Credentials, authentication bypass, permissions, and data-handling concerns.

03

Undisclosed behavior

Signals that software may do more than its documentation describes.

04

Security risk rating

Prioritized weakness patterns with source evidence where available.

05

License compliance

Business-use permission, restrictions, obligations, and missing terms.

06

Vendor controls and gaps

Documented controls, missing evidence, uncertainty, and follow-up questions.

YOUR EVIDENCE STAYS PROTECTED

Sensitive inputs deserve direct answers.

Code files are discarded after processing. Vendor documents can be retained for continuity or configured not to persist. Data is encrypted in transit and at rest, and all-inclusive submissions are not used for AI model training.

Review Security & Trust
01

Source-minimizing

Code files are not retained after processing. Cryptographic file hashes and underlying file-level results are retained indefinitely by default. For a sensitive codebase, an option available during the initial scan can delete stored records for unique files first seen in that repository after report generation.

02

Customer-controlled

Delete assessments and retained vendor documents when they are no longer needed.

03

No AI model training by default

All-inclusive data is not used for AI model training. Bring your own key follows your Anthropic account settings.

04

Clear boundaries

See subprocessors, US processing, DPA availability, and exactly what Bring your own key changes.

04 / THE FOUNDATION

Built from the work,
not around it.

Can I Run That? was built by Brian Semrau, an information security consultant, board-certified digital forensics examiner, and expert witness with more than 20 years in the field.

Across thousands of security assessments, the bottleneck stayed the same: review was manual, time-consuming, and difficult to make consistent.

CIRT turns that repeatable framework into decision support that remains explicit about evidence, uncertainty, and human responsibility.

Brian SemrauSr. Digital Forensic Investigator / Expert Witness
SELECTED CREDENTIALSEST. 20+ YEARS
01

Information security practice

Security programs, breach remediation, forensic incident response, and expert witness engagements.

02

M.S. Cyber Forensics & Security

Illinois Institute of Technology, 4.0 GPA; B.S. in Information Technology Administration and Management, cum laude.

03

Board-certified digital forensics

Multiple forensic disciplines; adjunct faculty in vulnerability analysis, ethical hacking, and computer forensics.

04

SANS CTF winner and researcher

SEC642 and SEC540 CTF winner; published browser-extension privacy research and endpoint security guidance.

05 / PRICING

Choose who manages the AI.

Every plan uses the same review pipeline and report output. The difference is who supplies Anthropic access, how usage is billed, and how much source capacity is included.

Use your Anthropic accountLower CIRT subscription price. AI usage is billed separately by Anthropic based on actual consumption.

AI includedNo Anthropic account or separate AI bill required. AI usage is included in the CIRT subscription price.

TIER 1STARTER
$50/ month

AI included: $99 / month

For teams that want control over model usage and spend.

  • Seven-day trial
  • 10 code assessments / month
  • 2 vendor reviews / month
  • Up to 750,000 lines of code included per repository
  • Standard risk configuration
  • Web link, HTML, and PDF reports
Start Starter trial
TIER 3SCALE
$400/ month

AI included: $799 / month

For multi-client MSP use with API access.

  • Seven-day trial
  • 100 code assessments / month
  • 50 vendor reviews / month
  • No fixed lines-of-code cap; fair use applies
  • Multi-client organization support
  • White-label reports and API access
Start Scale trial

Overages: $5 per additional code assessment or vendor review, plus your Anthropic usage.

See Bring your own key lines-of-code surcharge details

500,000 additional lines of code: $15; 1,000,000: $30; 2,000,000: $60; over 4,000,000: contact us. Purchased additional lines-of-code capacity does not expire.

Observed early-access usage

Code assessments have averaged less than $2 in Anthropic usage. Vendor assessments are usually lower, depending on how many documents are analyzed. Actual cost varies with file count, code volume, model usage, and your Anthropic terms.

What counts as a code assessment? A supported source-accessible input such as a repository, package, or browser extension. Compiled binaries are not supported.

STARTER ECONOMICSIf a manual review takes four staff-hours, the $50 Bring your own key Starter plan breaks even at $12.50/hour, before Anthropic usage.
See the MSP revenue model
Bring your own key features that change by tier
CapabilityStarterProfessionalScale
Code assessments10 / month30 / month100 / month
Vendor reviews2 / month10 / month50 / month
Lines of code included per repository750,0002,000,000No fixed cap; fair use
Scheduled rescansNot includedIncludedIncluded
Multi-client supportNot includedNot includedIncluded
Report brandingStandardCo-brandedWhite-label
Open APINot includedNot includedIncluded

Usage: Included monthly assessments reset each billing cycle and do not roll over. Vendor reviews count per vendor, not per document.

Access: Integrations are built through the open API. SSO is available for $75/month, reflecting the authentication-provider cost.

Terms: Plans are month-to-month and may be canceled before renewal. Refunds follow the Refund Policy.

Timing: Most reviews produce decision-ready output within minutes, although exceptionally large or queued code assessments can take longer.

Billing and subscription management are handled by Paddle.

07 / FAQ

Questions,
answered directly.

AI-assisted review is useful when its limits, evidence, and data handling are explicit.

Read Security & Trust
01How accurate is the analysis?

CIRT applies a consistent framework and links findings to submitted evidence where available, but it does not guarantee complete or error-free detection. AI outputs can include false positives, false negatives, and misinterpretations. A qualified human should review material findings and make the final decision.

02What happens when the system is uncertain?

Uncertainty, missing documents, incomplete controls, and unanswered questions are treated as gaps to resolve. Missing evidence is not silently converted into a positive control conclusion.

03How long does a review take?

Most reviews complete within a few minutes. Code reviews use Anthropic batch processing, which can technically take up to 24 hours. For this workload, batch processing is normally faster and cheaper than comparable synchronous Anthropic calls, but completion time is not guaranteed.

04Can I submit private or confidential material?

You may upload material you are authorized to submit. Direct private-repository connections are not currently supported; repository scanning is designed primarily for open-source software. Authorized source can be provided as a ZIP. Review the Security & Trust page and your confidentiality obligations before submission.

05How long is submitted material retained?

Code files are discarded after processing. Cryptographic file hashes and underlying file-level assessment results from code reviews are retained indefinitely by default, including after the code review assessment itself is deleted. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and file-level results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. A file-level result is primarily a generated summary of the file's purpose and its associated security findings; in rare circumstances it may include a small code snippet. It cannot identify or reconstruct the submitted source file. Vendor documents are retained by default for documentation continuity, but retention can be disabled. The vendor assessment and its retained documents can be deleted at any time.

06Is submitted data used for AI model training?

No for all-inclusive plans. For Bring your own key, processing follows your Anthropic account and contract settings. If AI model training is enabled for that account, your Anthropic terms control that use.

07Can findings and reports be shared?

Yes. Reports can be shared by link through the web application or exported in HTML and PDF formats. They are designed to support internal approvals and conversations with auditors, clients, and stakeholders. Professional and Scale plans add co-branded or white-label options.

08Can I customize risk requirements or deal-breakers?

Vendor reviews support custom risk requirements and deal-breakers. Code reviews currently use the standard risk configuration and do not support customization.

09What integrations and SSO are available?

Integrations are limited to those built against the open API. SSO is available as a $75/month add-on.

10What does Bring your own key cost in practice?

Early-access code assessments have averaged less than $2 in Anthropic usage, and vendor assessments are usually lower depending on document count. Actual cost varies with file count, code volume, model usage, and your Anthropic terms. Bring your own key primarily provides cost control; it does not remove CIRT infrastructure or report processing.

11What happens if evidence is thin or unavailable?

The report documents what was supplied, identifies missing evidence and unanswered questions, and helps structure follow-up. It does not treat an absent SOC 2 report or unsupported claim as proof that a control exists.

12Does this replace my analyst or transfer liability?

No. CIRT organizes evidence and provides decision support. Your organization retains responsibility for validating findings, applying business context, and making the final approval decision.

13Why not just review this with Claude, ChatGPT, or another general-purpose AI tool?

General-purpose AI can summarize a security document or inspect source code. CIRT adds a repeatable review process around that analysis: consistent requirements and scoring, evidence-linked findings, explicit treatment of missing evidence and uncertainty, retained assessment history, deployment decisions, shareable reports, and scheduled rescans. Scale adds multi-client workflows. Bring your own key lets you use your own Anthropic account while retaining CIRT's review framework, workflow, reporting, and audit record.

14How is this different from Vanta, Drata, or Whistic?

Those platforms can manage questionnaires, evidence collection, and vendor-risk workflow. Compare CIRT with Vanta or Whistic. CIRT reads the evidence you submit, identifies controls and gaps, and produces a deployment-focused decision report. The tools can complement each other.

15How is this different from Snyk or Dependabot?

Snyk and Dependabot focus on vulnerabilities in code your team develops and ships. CIRT evaluates whether someone else's software or service should be approved to run in your environment.

16What if a review fails or exceeds its size allowance?

If an assessment fails for a reason attributable to CIRT, its assessment allowance is restored automatically. Large repositories use the published lines-of-code surcharge schedule. Failures caused by invalid Bring your own key credentials, insufficient Anthropic credit, unsupported customer input, or third-party outages outside CIRT's control do not receive that representation. Platform-access and refund issues follow the Refund Policy.

GET STARTED

Make the next
approval defensible.

Build each third-party software decision from consistent evidence and an explicit record of uncertainty. Most reviews produce decision-ready output within minutes, although exceptionally large or queued code assessments can take longer.

Create your account
By creating an account, you agree to our Privacy Policy and Terms of Service.