Source code evidence
Software, extensions, packages, repositories, and authorized archives.
When someone asks, "Can I run that?", IT and security teams use CIRT to review source code and vendor security evidence, identify material gaps, and produce a defensible, shareable approval or deployment decision. Most reviews produce decision-ready output within minutes.
Built by a board-certified digital forensics examiner and expert witness20+ years in security and investigations
Explore a read-only demo with completed software and vendor reviews already loaded. See the actual workflow, findings, reports, and approval experience before signing up.
Software, extensions, packages, repositories, and authorized archives.
SaaS and commercial software documentation, including SOC 2 reports, penetration-test summaries, questionnaires, and trust-center evidence.
Documented, defensible, and ready to share.
A software or SaaS request reaches IT or security. CIRT organizes the available evidence into a repeatable review so the team can make a defensible approval decision.
Review what the extension does, the permissions it requests, and the material risks before approving installation.
Read the vendor's SOC 2, penetration-test summary, questionnaire, and trust evidence without losing days to manual extraction.
Evaluate provenance, install behavior, vulnerabilities, licensing, and supply-chain signals before it reaches production.
Give MSP and consulting clients a consistent, branded report instead of an undocumented yes or no.
Choose the path that matches the request. Both turn different forms of evidence into the same documented organizational decision.
Public repositories, browser extensions, NPM packages, and authorized ZIP uploads.
Explore software reviews COMMERCIAL SOFTWARE & SAASSOC 2 reports, penetration-test summaries, questionnaires, and trust-center evidence.
Explore vendor reviewsMake documented software approvals without hours of inconsistent manual review.
Turn repeatable third-party reviews into a documented client service.
Produce due-diligence evidence for auditors, frameworks, clients, and leadership.
Source-accessible software and vendor documents need different review methods. Both support the same organizational approval decision.
For commercial software and SaaS evaluated through vendor-provided evidence.
Upload SOC 2 reports, penetration-test summaries, questionnaires, or trust-center exports.
Identify covered controls, missing information, evidence gaps, and vendor risk signals.
Use cited evidence and documented uncertainty to make the final deployment decision.
For public repositories, browser extensions, NPM packages, and authorized ZIP archives.
Share a public repository, extension, package, or authorized source archive.
Apply a repeatable framework built from security and forensic practice.
Inspect grades, evidence-linked findings, prioritized risks, and license status.
The report separates what the evidence supports, what remains uncertain, and what needs human judgment.
Origin, release process, packaging consistency, and supply-chain context.
Credentials, authentication bypass, permissions, and data-handling concerns.
Signals that software may do more than its documentation describes.
Prioritized weakness patterns with source evidence where available.
Business-use permission, restrictions, obligations, and missing terms.
Documented controls, missing evidence, uncertainty, and follow-up questions.
Code files are discarded after processing. Vendor documents can be retained for continuity or configured not to persist. Data is encrypted in transit and at rest, and all-inclusive submissions are not used for AI model training.
Review Security & TrustCode files are not retained after processing. Cryptographic file hashes and underlying file-level results are retained indefinitely by default. For a sensitive codebase, an option available during the initial scan can delete stored records for unique files first seen in that repository after report generation.
Delete assessments and retained vendor documents when they are no longer needed.
All-inclusive data is not used for AI model training. Bring your own key follows your Anthropic account settings.
See subprocessors, US processing, DPA availability, and exactly what Bring your own key changes.
Can I Run That? was built by Brian Semrau, an information security consultant, board-certified digital forensics examiner, and expert witness with more than 20 years in the field.
Across thousands of security assessments, the bottleneck stayed the same: review was manual, time-consuming, and difficult to make consistent.
CIRT turns that repeatable framework into decision support that remains explicit about evidence, uncertainty, and human responsibility.
Security programs, breach remediation, forensic incident response, and expert witness engagements.
Illinois Institute of Technology, 4.0 GPA; B.S. in Information Technology Administration and Management, cum laude.
Multiple forensic disciplines; adjunct faculty in vulnerability analysis, ethical hacking, and computer forensics.
SEC642 and SEC540 CTF winner; published browser-extension privacy research and endpoint security guidance.
Every plan uses the same review pipeline and report output. The difference is who supplies Anthropic access, how usage is billed, and how much source capacity is included.
Use your Anthropic account: $50 / month
For small teams getting consistent about approvals.
Use your Anthropic account: $150 / month
For MSPs and teams standardizing reviews across projects.
Use your Anthropic account: $400 / month
For multi-client use, larger volume, and API access.
Overages: $10 per additional code assessment or vendor review.
200,000 additional lines of code: $15; 500,000: $37.50; 1,000,000: $75; over 2,000,000: contact us. Purchased additional lines-of-code capacity does not expire.
AI included: $99 / month
For teams that want control over model usage and spend.
AI included: $299 / month
For MSPs and IT teams scaling standardized reviews.
AI included: $799 / month
For multi-client MSP use with API access.
Overages: $5 per additional code assessment or vendor review, plus your Anthropic usage.
500,000 additional lines of code: $15; 1,000,000: $30; 2,000,000: $60; over 4,000,000: contact us. Purchased additional lines-of-code capacity does not expire.
Code assessments have averaged less than $2 in Anthropic usage. Vendor assessments are usually lower, depending on how many documents are analyzed. Actual cost varies with file count, code volume, model usage, and your Anthropic terms.
What counts as a code assessment? A supported source-accessible input such as a repository, package, or browser extension. Compiled binaries are not supported.
| Capability | Starter | Professional | Scale |
|---|---|---|---|
| Code assessments | 10 / month | 30 / month | 100 / month |
| Vendor reviews | 2 / month | 10 / month | 50 / month |
| Lines of code included per repository | 750,000 | 2,000,000 | No fixed cap; fair use |
| Scheduled rescans | Not included | Included | Included |
| Multi-client support | Not included | Not included | Included |
| Report branding | Standard | Co-branded | White-label |
| Open API | Not included | Not included | Included |
Usage: Included monthly assessments reset each billing cycle and do not roll over. Vendor reviews count per vendor, not per document.
Access: Integrations are built through the open API. SSO is available for $75/month, reflecting the authentication-provider cost.
Terms: Plans are month-to-month and may be canceled before renewal. Refunds follow the Refund Policy.
Timing: Most reviews produce decision-ready output within minutes, although exceptionally large or queued code assessments can take longer.
Billing and subscription management are handled by Paddle.
These guides cover vendor evidence, SOC 2 reports, source-readable software, browser extensions, and NPM packages. Each teaches the manual process before explaining where automation can help.
Learn which evidence each path provides, which questions it cannot answer, and how business context changes the decision.
Read the guide → VENDOR REVIEWScope the use, collect evidence, test claims, document gaps, and reach a decision that remains explainable later.
Read the guide →AI-assisted review is useful when its limits, evidence, and data handling are explicit.
Read Security & TrustCIRT applies a consistent framework and links findings to submitted evidence where available, but it does not guarantee complete or error-free detection. AI outputs can include false positives, false negatives, and misinterpretations. A qualified human should review material findings and make the final decision.
Uncertainty, missing documents, incomplete controls, and unanswered questions are treated as gaps to resolve. Missing evidence is not silently converted into a positive control conclusion.
Most reviews complete within a few minutes. Code reviews use Anthropic batch processing, which can technically take up to 24 hours. For this workload, batch processing is normally faster and cheaper than comparable synchronous Anthropic calls, but completion time is not guaranteed.
You may upload material you are authorized to submit. Direct private-repository connections are not currently supported; repository scanning is designed primarily for open-source software. Authorized source can be provided as a ZIP. Review the Security & Trust page and your confidentiality obligations before submission.
Code files are discarded after processing. Cryptographic file hashes and underlying file-level assessment results from code reviews are retained indefinitely by default, including after the code review assessment itself is deleted. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and file-level results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. A file-level result is primarily a generated summary of the file's purpose and its associated security findings; in rare circumstances it may include a small code snippet. It cannot identify or reconstruct the submitted source file. Vendor documents are retained by default for documentation continuity, but retention can be disabled. The vendor assessment and its retained documents can be deleted at any time.
No for all-inclusive plans. For Bring your own key, processing follows your Anthropic account and contract settings. If AI model training is enabled for that account, your Anthropic terms control that use.
Yes. Reports can be shared by link through the web application or exported in HTML and PDF formats. They are designed to support internal approvals and conversations with auditors, clients, and stakeholders. Professional and Scale plans add co-branded or white-label options.
Vendor reviews support custom risk requirements and deal-breakers. Code reviews currently use the standard risk configuration and do not support customization.
Integrations are limited to those built against the open API. SSO is available as a $75/month add-on.
Early-access code assessments have averaged less than $2 in Anthropic usage, and vendor assessments are usually lower depending on document count. Actual cost varies with file count, code volume, model usage, and your Anthropic terms. Bring your own key primarily provides cost control; it does not remove CIRT infrastructure or report processing.
The report documents what was supplied, identifies missing evidence and unanswered questions, and helps structure follow-up. It does not treat an absent SOC 2 report or unsupported claim as proof that a control exists.
No. CIRT organizes evidence and provides decision support. Your organization retains responsibility for validating findings, applying business context, and making the final approval decision.
General-purpose AI can summarize a security document or inspect source code. CIRT adds a repeatable review process around that analysis: consistent requirements and scoring, evidence-linked findings, explicit treatment of missing evidence and uncertainty, retained assessment history, deployment decisions, shareable reports, and scheduled rescans. Scale adds multi-client workflows. Bring your own key lets you use your own Anthropic account while retaining CIRT's review framework, workflow, reporting, and audit record.
Those platforms can manage questionnaires, evidence collection, and vendor-risk workflow. Compare CIRT with Vanta or Whistic. CIRT reads the evidence you submit, identifies controls and gaps, and produces a deployment-focused decision report. The tools can complement each other.
Snyk and Dependabot focus on vulnerabilities in code your team develops and ships. CIRT evaluates whether someone else's software or service should be approved to run in your environment.
If an assessment fails for a reason attributable to CIRT, its assessment allowance is restored automatically. Large repositories use the published lines-of-code surcharge schedule. Failures caused by invalid Bring your own key credentials, insufficient Anthropic credit, unsupported customer input, or third-party outages outside CIRT's control do not receive that representation. Platform-access and refund issues follow the Refund Policy.
Build each third-party software decision from consistent evidence and an explicit record of uncertainty. Most reviews produce decision-ready output within minutes, although exceptionally large or queued code assessments can take longer.
By creating an account, you agree to our Privacy Policy and Terms of Service.