Security audits for shipped code

We help VibeCoders build secure and maintainable products

Start freeLog in

Hackers don't break down doors. They look for the gap.Forge closes the gap before they find it.

What Forge does

  • Security on Autopilot

    Monitoring

    Your site gets checked weekly — no need to remember when you last scanned anything. Reports land in your inbox.

    Autopilot it now
  • Less tokens, no heavy hardware

    Value for money

    We provide a purpose-built harness that already optimizes token spend — nothing is built from scratch per scan, and no dedicated memory-heavy server is needed. You pay a flat price, not the cost of running checks yourself.

  • Fix, Don’t Just Find

    Actionable

    Every issue comes with a concrete step to close it, not just a red flag. You don’t just learn it’s broken — you learn how to make it right.

  • Check Every Release

    On-demand

    Ship a new version, run a scan. Per-release audits on demand, so a hole never reaches your users.

  • Built for Humans and Agents

    Both

    You read a friendly UI. Your agent (Cursor, Copilot, Claude, OpenClaw) drives the same engine through API/MCP. One engine, two ways in.

  • All under control

    Catalogue

    Every check we run today, and every one on the way — grouped by what it looks at, with what each one needs to start.

    All checks catalog
More features

How it works

  1. Add your domain

    Drop in your domain and verify ownership with a quick email or TXT record.

  2. Run your first check

    Passive checks (DNS, SSL, headers, SEO, OG) run instantly. Verified domains unlock active passes: crawling, forms, secret leaks, outdated components.

  3. Read a report you understand

    Every finding is a plain-English risk with a concrete fix, not tech noise.

  4. Bring your agent (or not)

    Connect your agent through MCP/API to read reports and trigger scans, or run checks yourself in the UI before each release.

  5. Stay covered automatically

    A weekly audit with an email report lands for every domain, no remembering required.

See it in action

  • Demo video coming soon
  • Demo video coming soon
  • Demo video coming soon

More examples on YouTube

Pricing

Free

  • 1 domain, no subdomains
  • Weekly automatic check with an email report — free while Forge is in beta, with 30 days' notice before that changes

Max (Enterprise)

By request
  • A dedicated pentest server in your private network
  • Unlimited tests, domains and subdomains

Frequently asked questions

Is it free to start?

Yes. After registration you get one free domain, with a weekly automatic check and an email report — free while Forge is in beta, with 30 days' notice before that changes. Pro covers 3 domains with up to 3 subdomains for each domain, and Max adds a dedicated pentest server in your private network.

Can my AI agent use Forge?

Yes. Forge exposes the same engine through API and MCP, so agents in Cursor, Copilot, Claude Desktop or OpenClaw can trigger scans and read reports. Humans read the UI, agents act through MCP.

Do I need to be a security expert to use Magery Forge?

No. Forge translates raw tech findings into plain language. Instead of "Missing Strict-Transport-Security header" you get "Your site allows unencrypted connections — here's how to turn on protection." Every finding ships as a simple risk plus concrete fix steps.

Is it safe? Will you hack or break my site?

All checks are non-destructive. Passive checks read only publicly visible data — DNS, SSL, headers, meta tags — the same stuff anyone on the internet can see. Active checks (crawling, forms, secret-leak scanning) only run after you verify domain ownership. We scan, we don't attack.

Why do I need to verify my domain?

Verification protects you. It makes sure active checks run only on your request as the real owner — not on someone else's whim. It's the gate that separates "reading what's public" from "probing deeper."

What's the difference between passive and active checks?

Passive checks read what your site already exposes — DNS, certificate, HTTP headers, SEO and social markup. They're available right away. Active checks go further — crawl pages, test forms, hunt secret leaks — and unlock after domain verification. Deeper verification, broader coverage.

Is Forge for me, or for professional security teams?

For you. Forge is built for VibeCoders and developers without a security team. It closes the gap between "I quickly shipped something" and "this is built like a professional team would." Pros can hook into the same engine via API/MCP — but the UI speaks your language.

Get in touch

[email protected]