NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

SECENG DEFEND

AI Runtime Configuration Security

Catch AI-specific misconfigurations before they reach production.

Scan .env files, Docker Compose, Kubernetes manifests, GitHub Actions, Vercel, Supabase, and other config formats for AI-specific unsafe defaults. Detect exposed model APIs, unauthenticated AI runtimes, permissive CORS, debug flags, missing auth, and provider credential risks before they become incidents.

ARE YOUR AI CONFIGS SAFE TO DEPLOY?

Multi-format

Scan .env, Docker Compose, Kubernetes, GitHub Actions, Vercel, Supabase, and YAML/JSON configs in a single pass.

AI-specific rules

Rules tuned for AI-adjacent risks: exposed model endpoints, unauthenticated AI runtimes, vector DB exposure, and provider credential leaks.

Prioritized findings

Findings ranked by severity with specific line numbers, categories, and remediation guidance.

No execution

Static analysis only — no deployment access required, no production system interaction.

Core capabilities

What SecEng AI Config Linter does.

Environment Variable Analysis

Detect secrets in configs, public AI runtime binding, permissive CORS, debug flags, and missing auth across .env and example files.

Container & Compose Review

Flag AI service ports bound to 0.0.0.0, missing auth, no TLS termination, and unsafe default credentials in Docker Compose and Kubernetes.

CI/CD Pipeline Audit

Review GitHub Actions workflows for exposed AI provider keys, unsafe model endpoint usage, and missing secret controls.

Platform Config Review

Check Vercel, Supabase, and platform-specific configs for public AI endpoint exposure and missing access controls.

Prioritized Output

Every finding includes file path, line number, category, severity, evidence, and a specific remediation recommendation.

Evidence-Ready Export

Export findings as JSON for engineering backlog, Jira tickets, or security review evidence.

Evidence & signals

What you get out of the box.

Supported Formats

  • .env / .env.example
  • Docker Compose
  • Kubernetes YAML
  • GitHub Actions
  • Vercel config
  • Supabase config
  • Generic JSON/YAML

Risk Categories

  • Exposed model APIs
  • Unauthenticated AI runtimes
  • Permissive CORS
  • Debug flags enabled
  • Provider credential leaks
  • Missing auth
  • Vector DB exposure

Deliverables

  • Prioritized findings
  • Line-level evidence
  • Remediation guidance
  • JSON export
  • Engineering backlog items

AI SECURITY ENGINEERING WORKBENCH

Ready to put SecEng AI Config Linter to work?

AI Config Linter is an active-development SecEng Workbench capability. We review your deployment configuration files and return prioritized findings without executing production workloads.

Also in the Workbench

WHAT AI DO WE HAVE?

SecEng Surface Scanner

Browser, Repo & IDE AI Discovery

Explore

WHERE CAN AI CODE BECOME AN ATTACK PATH?

SecEng Code Scanner

AI Attack-Path SAST

Explore

WHAT DID IT ACTUALLY DO?

SecEng Runtime Proxy

MITM Capture, Replay & Runtime Evidence

Explore

HOW CAN IT FAIL UNDER ATTACK?

SecEng Adversarial Range

AI Red-Team Scenario Harness

Explore

WHAT CAN AGENTS ACTUALLY DO?

SecEng Authority Graph

Agent Authority & Approval-Path Analysis

Explore

WAS RETRIEVAL AUTHORIZED?

SecEng RAG Test Harness

Retrieval & Context Security Test Harness

Explore

SecEng Threat Canvas

AI Threat Modeling & Trust-Boundary Mapping

Explore

SecEng Trust Scanner

Public AI Trust Signal Scoring

Explore

Atlassian Threat Canvas

Security Data Flow Canvas for Jira + Confluence

Explore

SecEng Agent Permission Analyzer

Agent Tool Permission Security Analysis

Explore

SecEng Artifact Analyzer

Static Artifact Intelligence

Explore

SecEng Injection Harness

Prompt Injection Testing

Explore

SecEng Prompt Reviewer

Prompt & Corpus Security Review

Explore

SecEng Model Gateway

Governed AI Routing, Policy Enforcement & Spend Control

Explore

SecEng Program Blueprint Kit

AI Security Program Build

Explore

SecEng Output Safety Tester

AI Output Safety Testing

Explore

SecEng Evidence Scorecard

AI Product Security Assessment & Maturity Scoring

Explore

WHAT CAN YOUR AI TOOLS REALLY DO?

SecEng Tool Capsule Analyzer

AI Tool Capability & Permission Analysis

Explore

WHERE ARE YOUR PRODUCTION PROMPTS?

SecEng Prompt Asset Scanner

Prompt Asset Inventory & Security Review

Explore

WHAT CAN YOUR AGENTS ACTUALLY DO?

SecEng Agent Authority Diff

Agent Authority Review & Hardening

Explore

WHICH AI DEPENDENCIES CHANGE RELEASE RISK?

SecEng Supply Chain Scanner

AI Supply Chain Risk Analysis

Explore

CAN YOU PROVE WHAT YOUR EVALS COVER?

SecEng Eval Coverage Auditor

AI Security Eval Coverage Evidence

Explore

AIPSA Evidence Packs

Structured Security Assessment Outputs

Explore