Local-first AI security

Catch what your AI assistant gets wrong — before it ships.

Leaked secrets, vulnerable dependencies, prompt injection. PreAI detects, blocks, and proves it in your editor and CI — and its own analysis runs entirely on your machine, with zero telemetry.

Zero telemetry 100% on-device 14-day free trial No runtime dependencies

Works inside your editor & AI agents

VS Code Cursor Windsurf Claude Code Antigravity Copilot (via MCP gateway)
The new attack surface

AI writes code fast. It also ships risk.

Every prompt, dependency, and tool call is a way for secrets to leak or an agent to be steered. Three failure modes show up again and again.

Leaked secrets & PII

API keys, tokens, and regulated personal data get pasted into prompts, committed to repos, and fed into an assistant's context window — where you can't get them back.

Vulnerable & poisoned deps

Assistants confidently suggest packages — including known-vulnerable versions, typosquats, and hallucinated names that attackers register to ship you malware.

Hijacked AI agents

Prompt injection hidden in a README, a poisoned MCP tool, or an over-permissioned agent can turn your helper into the attacker — reading files and running commands you never approved.

One tool, four jobs

Detect, prevent, govern, and prove — locally

PreAI rolls four classes of security control into one editor extension, reusing the same engine end to end. No SaaS backend, no data egress.

Detect

Real-time scanning as you type.

  • Secrets & credentials
  • Regulated PII (incl. India: Aadhaar, PAN, GSTIN)
  • Malicious & insecure-code patterns
  • SCA across 11 ecosystems

Prevent

Guard blocks risky actions before they run.

  • Allow / ask / redact / deny per action
  • Claude Code, Cursor, Windsurf, Antigravity
  • MCP gateway covers Copilot
  • Observe → ask → enforce modes

Govern

See and control your AI exposure.

  • Which AI tools can read your secrets
  • MCP tool-poisoning & rug-pull detection
  • Untrusted model-file (pickle) scanning
  • Data-residency / egress classification

Prove

Audit-grade evidence on demand.

  • CycloneDX SBOM + SARIF export
  • OWASP LLM & MITRE ATLAS tagging
  • CI/CD PR gate (Team)
  • Centralized audit log (Team)
The difference that matters

PreAI never sends your code anywhere.

Cloud-based AI-security tools scan your code by sending it, your dependencies, and the findings to their servers. PreAI does its analysis entirely on-device and transmits nothing — so regulated, IP-sensitive, and air-gapped teams can finally use it. Your AI assistant may still send code to its own cloud; PreAI is the tool that shows you what it's exposing — and can redact or block it.

No telemetryNo analytics, no install ID, no usage tracking. Ever.
No scan-data egressSource, secrets, and findings never transmit off your machine.
Self-hostable feedThe threat-intel feed can run fully inside your network — even air-gapped.
Why PreAI

Deeper coverage, without the cloud

How PreAI compares to a typical cloud-based AI-security tool.

CapabilityPreAITypical cloud tool
Your code & findings stay on your machineAlways local · zero telemetryUploaded to vendor servers
Prompt-injection detection (direct + indirect)Evasion-resistant, every agent-readable surfaceBasic, if any
Pre-execution blocking of agent actions5 hosts + MCP gatewayOften detect-only
MCP security — tool-poisoning + rug-pull/driftYes, baselinedRarely
AI exposure & shadow-AI governanceSees which tools reach your secretsNo
Dependency SCA — 11 ecosystems + reachabilityYesLimited
Untrusted model-file (pickle) scanningYesRarely
Regulated PII incl. India (Aadhaar/PAN/GSTIN)First-classRarely
Compliance evidence — SBOM, SARIF, OWASP/ATLAS tagsBuilt inSometimes
Hallucinated-package (slopsquat) detectionYesRarely
Air-gapped / self-hosted + offline licenseYesNo
Zero runtime dependencies (minimal attack surface)YesVaries

Compared with typical cloud-based AI-security tools; specific capabilities vary by vendor.

Built to be trusted

Security you can audit, not just install

An open core, an explicit zero-egress contract, and detection mapped to the standards your auditors already use.

11

package ecosystems / 18 lockfile formats

0

bytes of telemetry or runtime dependencies

OWASP · ATLAS

every finding tagged to the standards

Ed25519

signed threat-intel feed, verified fail-closed

Ship AI-assisted code without shipping the risk.

Start a 14-day free trial, or pick the plan that fits your team. Your code stays yours.