OpenHack finds logic-based vulnerabilities that traditional scanners can't and verifies them end-to-end at 40× cheaper using open-source models.
Proven against real-world software

Introducing OpenHack
Why OpenHack
Traditional scanners rely on pattern matching and produce mountains of noise. OpenHack uses open-source reasoning models to understand your code semantically, verify each finding with a working exploit, and eliminate false positives.
Out of 768 known vulnerabilities
Percentage of reported findings that are real
Benchmarked against 768 known vulnerabilities across 17 open-source applications.
Benchmarked
The new generation of security agents isn't measured against legacy SAST — it's measured against benchmarks like CVE-Bench, where agents have to discover and exploit real CVEs end-to-end. OpenHack runs alongside frontier-model agents on the leaderboard, using a fully open-source model that's up to 40× cheaper to run.
Mean one-day pass@1 across 6 runs
Zero-day pass@1 (no CVE description)
Cheaper than frontier-model agents
CVE-Bench (UIUC Kang Lab) is a benchmark of 40 critical real-world web CVEs. Each task requires the agent to discover and exploit the vulnerability end-to-end in a live sandbox. OpenHack runs neck-and-neck with the published leader using an open-source model — one-day range across 6 runs: 27.5% – 35.0%.
Works with your stack
How it works
One command. No config files, no YAML, no setup wizards.
Point it at any codebase. It understands the stack automatically.
Review validated findings with PoC exploits. Apply one-click fix PRs.
OpenHack's harness is fully open source and exclusively uses the best open-source models to find, validate, and verify logic-based vulnerabilities.
Platform
The OpenHack platform understands your entire business context to find, prioritize, and fix the vulnerabilities that actually matter. Automated threat modeling, business impact scoring, and validated findings with working exploits.
Ingests your codebase, infrastructure, auth flows, and business logic to build a complete understanding.
Generates threat models derived from your real architecture. Every threat is validated with a working PoC.
Ranks findings by actual business impact, not generic CVSS. Exploitability in your specific deployment.
CLI
The OpenHack CLI brings the full power of the security engine to your local workflow. Scan any codebase, get validated findings with exploits, and generate fix PRs without leaving the terminal.
Track record
A missing await keyword on getServerSession() in Papermark's TUS file upload endpoint causes a complete authentication bypass, allowing unauthenticated attackers to upload arbitrary files up to 2 GB.
Read advisoryUser-controlled redirect URLs from the OAuth state parameter are passed directly to res.redirect() without validation in Stripe Payment and Feishu Calendar callback handlers, allowing redirection to arbitrary external domains.
Read advisoryFAQ
Connect your repos and get validated findings with real exploits.
Secure your entire engineering organization with SSO, audit logs, compliance reports, and dedicated support.
Contact Sales