Choose a repository
Paste `owner/repo`, a GitHub URL, or connect GitHub with a read-only token for private repositories and higher API limits.
Run a free GitHub scan for AI frameworks, MCP servers, exposed secrets, privileged workflows, prompt-injection surfaces, attack paths, and remediation actions.
The free scanner is the first diagnostic layer after workspace creation: connect a GitHub repository, inspect AI-agent exposure, and export evidence your technical team can verify. Paid engagements add private review, business impact analysis, remediation ownership, and control-plane planning.
Paste `owner/repo`, a GitHub URL, or connect GitHub with a read-only token for private repositories and higher API limits.
Diomedi reads real repository files and looks for agent frameworks, MCP configs, prompt surfaces, secrets, tool use, data access, and workflow privilege.
Findings are ranked by severity and tied to files, evidence, likely owner, effort, validation step, and attack-path context.
Download an executive markdown report, raw JSON evidence, and a remediation plan that can be reviewed by engineering or security leadership.
AI agents can query databases, draft payments, modify repositories, trigger workflows, send messages, and call tools. Most companies cannot answer who owns them, what they can access, or how to shut them down.
Agents, bots, service accounts, API keys, and automations spread across tools without a central owner.
Non-human workers accumulate read, write, export, and spend capabilities faster than security reviews can track.
High-risk actions execute without approvals, audit context, emergency revoke, or policy evidence.
The current product helps you prove risk quickly. The paid pilot adds teams, approvals, policy, persistent evidence, and connectors.
Diomedi is built for companies where AI agents, MCP tools, repositories, credentials, and CI/CD permissions are already close to production. The engagement is scoped after qualification, so small teams are not overcharged and large companies do not receive a lightweight checklist.
Designed for software companies shipping AI agents, MCP tools, internal copilots, autonomous workflows, and AI-assisted engineering systems.
The first module is lightweight, cloud-friendly, and evidence-first. The enterprise roadmap is explicit.
The same scanner can support a startup audit, a procurement blocker, or a multi-team control-plane pilot. Diomedi qualifies the account first, then proposes the smallest engagement that can produce board-ready evidence.
For teams that need a fast baseline before AI tooling spreads across the company.
For teams facing security reviews, customer questions, investor diligence, or production AI risk.
For companies that need ongoing governance before AI agents can act near production systems.
For teams that need procurement-ready evidence, leadership reporting, and long-term AI control-plane expansion.
Short answers for security leaders, founders, and technical buyers evaluating Diomedi.
No. The current scanner calls the GitHub API, reads repository files, detects evidence, generates findings, builds attack paths, and exports reports. The enterprise login, persistent teams, SSO, and signed logs are the next paid pilot layer.
Yes. Public repository scans are free after workspace creation. Registration keeps each scan attached to a buyer profile, audit follow-up, and pilot onboarding path.
No. The optional token is used in memory for a private repository or higher rate limit scan and is not saved to browser storage.
Software companies using AI agents, MCP servers, internal copilots, AI automation, GitHub Actions, API keys, service accounts, or autonomous workflows.
The free scanner proves the direction of risk. The private assessment turns that evidence into an inventory, attack-path review, executive report, remediation plan, and pilot proposal tied to the company's size, urgency, compliance pressure, and production exposure.