# CybeDefend

> Agent-time application security for AI coding agents. CybeDefend enforces your security policy inside Claude Code, Cursor, Windsurf, GitHub Copilot, OpenAI Codex, Gemini, Cline, Continue, Zed and Antigravity. VibeDefend, our agent-time guard, mines your business-logic rules on first scan and applies them on every prompt. Logic flaws caught and remediated before the pull request is even opened.

We unify reachability-aware SAST, SCA, IaC, container and CI/CD scanning, plus secret detection and Cybe AutoFix verified patches, in a single Security Code Knowledge Graph queried by the agent on every prompt. Founded in 2025 by Florentin Ledy, Axel Paulin and Julien Zammit. Headquartered in Lille, France, with a Seattle (WA) office opening in 2026. EU + US data regions, SOC 2 Type II audit under way, GDPR compliant.

## Available languages

- [English (global)](https://www.cybedefend.com/en): Canonical English copy. Default for non-EU traffic.
- [Français (France)](https://www.cybedefend.com/fr): Site complet en français. Marketing surface + manifesto + blog FR.
- [Español (España)](https://www.cybedefend.com/es): Sitio completo en español. Páginas de producto, precios, contacto.
- [Português (Portugal)](https://www.cybedefend.com/pt): Site completo em português (PT-PT). Páginas de produto, preços, contacto.
- [Italiano (Italia)](https://www.cybedefend.com/it): Sito completo in italiano. Pagine prodotto, prezzi, contatti.
- [Deutsch (Deutschland)](https://www.cybedefend.com/de): Vollständige Site auf Deutsch. Produktseiten, Preise, Kontakt.

## Platform

- [Platform overview](https://www.cybedefend.com/en/platform): Unified Security Code Knowledge Graph across SAST, SCA, IaC, container, secrets, runtime. Every finding mapped to its exploit path, blast radius and owner.
- [SAST. Agent-time static analysis](https://www.cybedefend.com/en/sast): Reachability-aware, framework-aware, taint-tracking SAST that runs at agent-time. Drastically fewer false positives than legacy scanners, sub-1.2s P95 on 100k LOC repos. Native in Claude Code, Cursor, Windsurf, GitHub Copilot, OpenAI Codex, Gemini, Cline, Continue, Zed, Antigravity.
- [SCA. Reachability-aware dependency security](https://www.cybedefend.com/en/sca): Tells you which CVEs your code actually triggers. License risk, supply-chain provenance, malicious-package detection across npm, PyPI, Maven, Go, Gradle, NuGet, Cargo, Composer, Hex, RubyGems.
- [IaC security. Terraform, Kubernetes, CloudFormation, Ansible](https://www.cybedefend.com/en/iac): Static analysis for Terraform, CloudFormation, K8s, Helm, Kustomize, Ansible, Pulumi, CDKTF. CIS Benchmarks, NIST 800-53/171, AWS Well-Architected built in. AI triage on every finding. AWS, GCP, Azure, DigitalOcean, Hetzner, Scaleway, OVH.
- [CI/CD security](https://www.cybedefend.com/en/cicd): Dedicated scanner for GitHub Actions, GitLab CI and Jenkinsfile pipeline configs. Workflow injection, unpinned actions, OIDC trust drift, GITHUB_TOKEN over-privilege caught before any runner picks up the job.
- [Container security](https://www.cybedefend.com/en/container): Connect a registry, every image gets pulled and scanned in our pods. CVEs at OS-package and application-dependency level. AI triage drops the noise. Docker Hub, ECR, ACR, GCR, GHCR, Quay, Harbor, JFrog, Scaleway.
- [Secret detection](https://www.cybedefend.com/en/secrets-detection): Provider-specific signatures (AWS, GCP, Azure, GitHub, Stripe, OpenAI, Anthropic, Slack and more) plus Shannon-entropy fallback. Full git-history sweep at first install. AI triage on every match.
- [AI-BOM. AI Bill of Materials scanner](https://www.cybedefend.com/en/ai-bom): Scanner that catalogues every AI component in your repos: models (HuggingFace IDs, OpenAI / Anthropic / Google names, local GGUF/ONNX), datasets, versioned prompts, agents (LangChain, LlamaIndex, CrewAI, ReAct), MCP servers consumed and guardrails (Llama Guard, Guardrails AI, NeMo). One scan emits an EU AI Act Annex IV compliance report (Regulation EU 2024/1689), a NIST AI RMF mapping and a CycloneDX AI-BOM. Plugs in via the cybedefend-action GitHub Action or the CybeDefend CLI.
- [Cybe Analysis. Cross-tool correlation engine (ASPM)](https://www.cybedefend.com/en/cybe-analysis): One graph that dedupes, prioritises and routes findings from SAST, SCA, IaC, container and secrets to the actual owner via CODEOWNERS + Git history. Imports Snyk, Mend, Checkmarx, Veracode, Trivy, Grype, Semgrep.
- [Cybe AutoFix. Verified, agent-applied patches](https://www.cybedefend.com/en/cybe-autofix): AI-generated fix grounded in your code style, ships a regression test, signed by your bot, CI-gated. High verified fix rate on high-severity SAST findings, every patch carries a regression test before it merges.
- [Cybe Security Champion. IDE security copilot](https://www.cybedefend.com/en/cybe-security-champion): AI security copilot inside Claude Code, Cursor, Windsurf, GitHub Copilot, Gemini CLI, Cline, Continue, Zed. Reviews diffs, explains findings, writes the secure version.
- [VibeDefend. Agent-time security at every prompt](https://www.cybedefend.com/en/vibedefend): Reviews every prompt your AI agent receives in real time. Learns your project's business-logic rules on the first scan, keeps learning every few prompts. Memory that holds across long sessions. Native on Claude Code, Cursor, Windsurf, GitHub Copilot, OpenAI Codex, Gemini, Cline, Continue, Zed and Antigravity.

## Pricing

- [Pricing](https://www.cybedefend.com/en/pricing): Solo (free, 50 AI credits forever) → Developer from $18/mo (€17/mo) → Team from $229/mo (€179/mo) → Scale from $593/mo (€549/mo) → Enterprise (custom). Static scans (SAST - SCA - IaC - secrets) unlimited and free on every plan. EU + US data regions.

## Integrations

- [Integrations directory](https://www.cybedefend.com/en/integrations): VibeDefend agent-time security (any MCP-compatible agent: Claude Code, Cursor, Windsurf, Antigravity, GitHub Copilot, Gemini CLI, Cline, Continue, Zed), VS Code and the full JetBrains family (IntelliJ, PhpStorm, WebStorm, PyCharm, DataGrip, Rider, CLion, RustRover, GoLand, RubyMine, AppCode). Source: GitHub, GitLab. Container registries: Docker Hub, ECR, ACR, GCR, GHCR, Quay, Harbor, JFrog Artifactory, Scaleway. CI: GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Bitbucket Pipelines, CircleCI, TeamCity, Bamboo, REST API, CLI. Tracking: Jira, GitHub Issues, GitLab Issues. Notifications: Slack.

## Story & Manifesto

- [Manifesto. Find, Fix, Repeat. Secure your Coding Agent.](https://www.cybedefend.com/en/manifesto): Florentin Ledy on why the post-PR security review model is broken (find / fix / repeat), and what replaces it: VibeDefend, agent-time AppSec that reviews every prompt and enforces your business-logic rules before code is written. Vibe-coding rewrote the rules.
- [About CybeDefend](https://www.cybedefend.com/en/about): Three engineers in Lille rebuilding AppSec for the AI agent era. Founded 2025 by Florentin Ledy, Axel Paulin, Julien Zammit.

## Research & Engineering

- [Antigravity's Sandbox Protects Your Laptop, Not Your Codebase](https://www.cybedefend.com/en/blog/is-google-antigravity-safe): Is Google Antigravity safe? What the sandbox blocks, how permission rules really match, why Windows is different, and the risk no sandbox catches.
- [Your CLAUDE.md Works on the Rules You Did Not Need](https://www.cybedefend.com/en/blog/does-claude-code-follow-claude-md): Does Claude Code follow CLAUDE.md? In 90 graded runs, a realistic rules file scored exactly the same as no file at all. What worked instead, measured.
- [Codex danger-full-access, --yolo and Unsafe Mode: What Each Flag Disables](https://www.cybedefend.com/en/blog/codex-danger-full-access-flags-explained): Codex danger-full-access, --dangerously-bypass-approvals-and-sandbox (--yolo), -a never and --full-auto: what each removes, when it is safe, what to use instead.
- [Your Agent Never Escaped the Sandbox. It Did Not Need To.](https://www.cybedefend.com/en/blog/ai-coding-agent-sandbox-escape): Seven sandbox escapes across four coding agents, and almost none of them broke the box. What the Trust Handoff Flaw means for how you contain an agent.
- [Nobody Is Reviewing Your Agent's Pull Requests](https://www.cybedefend.com/en/blog/ai-agent-pull-request-security-review): A human alone reviews an agent's pull request 8% of the time. What the UK AI Security Institute incident means for your review process.
- [The 12 Best AI Security Platforms for Vulnerability Detection, and the One Question That Now Separates Them](https://www.cybedefend.com/en/blog/best-ai-security-platform-vulnerability-detection): Twelve platforms scored on what they detect, what survives triage and where the verdict lands, with each vendor's positioning as it stands today.
- [Your Model Got Smarter. Your Code Did Not Get Safer.](https://www.cybedefend.com/en/blog/does-a-newer-ai-model-write-safer-code): Capability doubled in one model generation while security stayed flat. Why upgrading the model and telling it to be secure both fail under measurement.
- [Instruction File Injection: How AGENTS.md and CLAUDE.md Hijack Coding Agents](https://www.cybedefend.com/en/blog/instruction-file-injection-agents-md-claude-md): AGENTS.md and CLAUDE.md load with near system-prompt authority. How instruction file injection works, the named 2026 incidents, and how to defend your repo.
- [Blog index](https://www.cybedefend.com/en/blog): All research, write-ups, tutorials. New every week.

## Trust & Compliance

- [Security policy](https://www.cybedefend.com/en/security): GDPR compliant (EU), SOC 2 Type II audit under way. Vulnerability disclosure at security@cybedefend.com.
- [Privacy policy](https://www.cybedefend.com/en/legal/privacy-policy)
- [Data Processing Agreement (DPA)](https://www.cybedefend.com/en/legal/dpa)
- [Sub-processors](https://www.cybedefend.com/en/legal/subprocessors)
- [Terms of use](https://www.cybedefend.com/en/legal/terms-of-use)

## Contact

- [Contact](https://www.cybedefend.com/en/contact): Demo, sales, partnership, support, security disclosure. Replies in under 4 hours from the team in Lille (Mon-Sun, 9 AM - 9 PM UTC+1). General inquiries: contact@cybedefend.com.

## Optional

- [Sitemap (XML)](https://www.cybedefend.com/sitemap.xml): All localised URLs across six locales (EN, FR, ES, PT, IT, DE).
- [Robots](https://www.cybedefend.com/robots.txt)
- [Long-form llms-full.txt](https://www.cybedefend.com/llms-full.txt): Same map plus inlined summaries.
- [Documentation](https://docs.cybedefend.com): API, MCP, CLI, CI references.

## Localised page index

- [Home (EN)](https://www.cybedefend.com/en)
- [Home (FR)](https://www.cybedefend.com/fr)
- [Home (ES)](https://www.cybedefend.com/es)
- [Home (PT)](https://www.cybedefend.com/pt)
- [Home (IT)](https://www.cybedefend.com/it)
- [Home (DE)](https://www.cybedefend.com/de)
- [Platform (EN)](https://www.cybedefend.com/en/platform)
- [Platform (FR)](https://www.cybedefend.com/fr/platform)
- [Platform (ES)](https://www.cybedefend.com/es/platform)
- [Platform (PT)](https://www.cybedefend.com/pt/platform)
- [Platform (IT)](https://www.cybedefend.com/it/platform)
- [Platform (DE)](https://www.cybedefend.com/de/platform)
- [SAST (EN)](https://www.cybedefend.com/en/sast)
- [SAST (FR)](https://www.cybedefend.com/fr/sast)
- [SAST (ES)](https://www.cybedefend.com/es/sast)
- [SAST (PT)](https://www.cybedefend.com/pt/sast)
- [SAST (IT)](https://www.cybedefend.com/it/sast)
- [SAST (DE)](https://www.cybedefend.com/de/sast)
- [SCA (EN)](https://www.cybedefend.com/en/sca)
- [SCA (FR)](https://www.cybedefend.com/fr/sca)
- [SCA (ES)](https://www.cybedefend.com/es/sca)
- [SCA (PT)](https://www.cybedefend.com/pt/sca)
- [SCA (IT)](https://www.cybedefend.com/it/sca)
- [SCA (DE)](https://www.cybedefend.com/de/sca)
- [IaC (EN)](https://www.cybedefend.com/en/iac)
- [IaC (FR)](https://www.cybedefend.com/fr/iac)
- [IaC (ES)](https://www.cybedefend.com/es/iac)
- [IaC (PT)](https://www.cybedefend.com/pt/iac)
- [IaC (IT)](https://www.cybedefend.com/it/iac)
- [IaC (DE)](https://www.cybedefend.com/de/iac)
- [CI/CD (EN)](https://www.cybedefend.com/en/cicd)
- [CI/CD (FR)](https://www.cybedefend.com/fr/cicd)
- [CI/CD (ES)](https://www.cybedefend.com/es/cicd)
- [CI/CD (PT)](https://www.cybedefend.com/pt/cicd)
- [CI/CD (IT)](https://www.cybedefend.com/it/cicd)
- [CI/CD (DE)](https://www.cybedefend.com/de/cicd)
- [Container (EN)](https://www.cybedefend.com/en/container)
- [Container (FR)](https://www.cybedefend.com/fr/container)
- [Container (ES)](https://www.cybedefend.com/es/container)
- [Container (PT)](https://www.cybedefend.com/pt/container)
- [Container (IT)](https://www.cybedefend.com/it/container)
- [Container (DE)](https://www.cybedefend.com/de/container)
- [Secret detection (EN)](https://www.cybedefend.com/en/secrets-detection)
- [Secret detection (FR)](https://www.cybedefend.com/fr/secrets-detection)
- [Secret detection (ES)](https://www.cybedefend.com/es/secrets-detection)
- [Secret detection (PT)](https://www.cybedefend.com/pt/secrets-detection)
- [Secret detection (IT)](https://www.cybedefend.com/it/secrets-detection)
- [Secret detection (DE)](https://www.cybedefend.com/de/secrets-detection)
- [AI-BOM (EN)](https://www.cybedefend.com/en/ai-bom)
- [AI-BOM (FR)](https://www.cybedefend.com/fr/ai-bom)
- [AI-BOM (ES)](https://www.cybedefend.com/es/ai-bom)
- [AI-BOM (PT)](https://www.cybedefend.com/pt/ai-bom)
- [AI-BOM (IT)](https://www.cybedefend.com/it/ai-bom)
- [AI-BOM (DE)](https://www.cybedefend.com/de/ai-bom)
- [Cybe Analysis (EN)](https://www.cybedefend.com/en/cybe-analysis)
- [Cybe Analysis (FR)](https://www.cybedefend.com/fr/cybe-analysis)
- [Cybe Analysis (ES)](https://www.cybedefend.com/es/cybe-analysis)
- [Cybe Analysis (PT)](https://www.cybedefend.com/pt/cybe-analysis)
- [Cybe Analysis (IT)](https://www.cybedefend.com/it/cybe-analysis)
- [Cybe Analysis (DE)](https://www.cybedefend.com/de/cybe-analysis)
- [Cybe AutoFix (EN)](https://www.cybedefend.com/en/cybe-autofix)
- [Cybe AutoFix (FR)](https://www.cybedefend.com/fr/cybe-autofix)
- [Cybe AutoFix (ES)](https://www.cybedefend.com/es/cybe-autofix)
- [Cybe AutoFix (PT)](https://www.cybedefend.com/pt/cybe-autofix)
- [Cybe AutoFix (IT)](https://www.cybedefend.com/it/cybe-autofix)
- [Cybe AutoFix (DE)](https://www.cybedefend.com/de/cybe-autofix)
- [Cybe Security Champion (EN)](https://www.cybedefend.com/en/cybe-security-champion)
- [Cybe Security Champion (FR)](https://www.cybedefend.com/fr/cybe-security-champion)
- [Cybe Security Champion (ES)](https://www.cybedefend.com/es/cybe-security-champion)
- [Cybe Security Champion (PT)](https://www.cybedefend.com/pt/cybe-security-champion)
- [Cybe Security Champion (IT)](https://www.cybedefend.com/it/cybe-security-champion)
- [Cybe Security Champion (DE)](https://www.cybedefend.com/de/cybe-security-champion)
- [VibeDefend (EN)](https://www.cybedefend.com/en/vibedefend)
- [VibeDefend (FR)](https://www.cybedefend.com/fr/vibedefend)
- [VibeDefend (ES)](https://www.cybedefend.com/es/vibedefend)
- [VibeDefend (PT)](https://www.cybedefend.com/pt/vibedefend)
- [VibeDefend (IT)](https://www.cybedefend.com/it/vibedefend)
- [VibeDefend (DE)](https://www.cybedefend.com/de/vibedefend)
- [Pricing (EN)](https://www.cybedefend.com/en/pricing)
- [Pricing (FR)](https://www.cybedefend.com/fr/pricing)
- [Pricing (ES)](https://www.cybedefend.com/es/pricing)
- [Pricing (PT)](https://www.cybedefend.com/pt/pricing)
- [Pricing (IT)](https://www.cybedefend.com/it/pricing)
- [Pricing (DE)](https://www.cybedefend.com/de/pricing)
- [About (EN)](https://www.cybedefend.com/en/about)
- [About (FR)](https://www.cybedefend.com/fr/about)
- [About (ES)](https://www.cybedefend.com/es/about)
- [About (PT)](https://www.cybedefend.com/pt/about)
- [About (IT)](https://www.cybedefend.com/it/about)
- [About (DE)](https://www.cybedefend.com/de/about)
- [Contact (EN)](https://www.cybedefend.com/en/contact)
- [Contact (FR)](https://www.cybedefend.com/fr/contact)
- [Contact (ES)](https://www.cybedefend.com/es/contact)
- [Contact (PT)](https://www.cybedefend.com/pt/contact)
- [Contact (IT)](https://www.cybedefend.com/it/contact)
- [Contact (DE)](https://www.cybedefend.com/de/contact)
- [Manifesto (EN)](https://www.cybedefend.com/en/manifesto)
- [Manifesto (FR)](https://www.cybedefend.com/fr/manifesto)
- [Manifesto (ES)](https://www.cybedefend.com/es/manifesto)
- [Manifesto (PT)](https://www.cybedefend.com/pt/manifesto)
- [Manifesto (IT)](https://www.cybedefend.com/it/manifesto)
- [Manifesto (DE)](https://www.cybedefend.com/de/manifesto)
- [Integrations (EN)](https://www.cybedefend.com/en/integrations)
- [Integrations (FR)](https://www.cybedefend.com/fr/integrations)
- [Integrations (ES)](https://www.cybedefend.com/es/integrations)
- [Integrations (PT)](https://www.cybedefend.com/pt/integrations)
- [Integrations (IT)](https://www.cybedefend.com/it/integrations)
- [Integrations (DE)](https://www.cybedefend.com/de/integrations)
- [Blog (EN)](https://www.cybedefend.com/en/blog)
- [Blog (FR)](https://www.cybedefend.com/fr/blog)
- [Blog (ES)](https://www.cybedefend.com/es/blog)
- [Blog (PT)](https://www.cybedefend.com/pt/blog)
- [Blog (IT)](https://www.cybedefend.com/it/blog)
- [Blog (DE)](https://www.cybedefend.com/de/blog)

<!--
This file follows the llmstxt.org convention. AI crawlers and
LLMs use it as a hierarchical index of canonical CybeDefend
resources. For humans, start at https://www.cybedefend.com instead.
-->
