We reproduced Anthropic's Mythos findings with public models. See the results >>

Hire your first AI security engineer.

Your team ships with Claude, Cursor, Codex, and Copilot. Add @vidoc to a Slack channel or GitHub PR - it reviews every change they open, verifies the real exploits, and replies like a teammate in one Slack digest a day.

Backed by the Vidoc Security Lab - we reproduced Anthropic's Mythos findings, including a FreeBSD remote-root bug, using public models. Read the study.

acme/api · PR #1284opened by Cursor

feat(uploads): add user-controlled image proxy

+86 −2 · 1 file changed · src/api/proxy/route.ts

vidocvidocreviewer
Vidoc is reading the diff…

AI made shipping fast. Security review didn't scale with it.

More code, less review

AI tools 3–10x your PR volume. Snyk, Dependabot, and Semgrep fire findings - but nobody owns the fix.

Scanners are loud and wrong

Hundreds of unverified findings. Engineers learn to ignore the channel.

Customers and auditors are waiting

SOC 2, ISO 27001, and procurement security questionnaires land on you.

Vidoc secures every PR. You read one digest.

Click through to see what your team would see, end-to-end, across a single example finding.

5 Open22 Closed today
Reviewed by Vidoc
  • feat(uploads): add user-controlled image proxy
    #1284opened 4 minutes ago byCcursor-bot· acme/api
    Vidoc reviewing
  • refactor: drain queue worker on SIGTERM
    #1282opened 12 minutes ago byMmaria-c· acme/api
    Vidoc · clean
  • fix(auth): session cookie expiry on refresh
    #1283opened 38 minutes ago byAalex-p· acme/web
    Vidoc · clean
+ 22 more reviewed since last syncVidoc cleared all of them

Vidoc reviews every PR, including the ones that don't need you. You only hear about the one that does.

Vidoc Security LabMay 2026

Mythos-level security,
on your codebase.

Read the full replication study

Using public models - GPT-5.4 and Claude Opus 4.6 - in an open-source coding agent, our research team reproduced three of four representative Anthropic Mythos findings, including the flagship FreeBSD remote-root NFS bug. The same engine now reviews every PR your team opens.

3 / 4

representative findings reproduced

Remote-root

flagship FreeBSD NFS bug

Public models

no special access required

Reply to Vidoc. It learns.

Tell Vidoc why a finding doesn't apply - in Slack, in the PR, in plain English. It remembers per repo and per team. No YAML, no triage dashboard.

Every suppression is audit-logged. You can override Vidoc; Vidoc cannot override you.

Slack#security · thread
#securityposted by Vidoc
vidoc
vidocAPP12:04 PM

Open redirect via returnTo on /auth/callback

Severity: Medium · verified  |  Repo: acme/web · PR #1305

User-controlled returnTo flows into a redirect with no obvious allowlist.

└── 2 replies· Last reply just now
MC
Maria Costa12:11 PM
@vidoc returnTo is allowlisted to our own domains in auth middleware - external redirects are dropped.
vidoc
vidocAPP12:11 PM

Got it, Maria. Marked VID-2918 as not-applicable for acme/web · /auth/callback. I'll keep flagging open redirects on routes that skip that middleware.

Fits the tools your team already opens.

GitHub logoGitLab logoSlack logoLinear logoCursor logoClaude logo

The questions
a CTO actually asks.

Still missing something? Email contact@vidocsecurity.com or grab time directly.

Find the bugs Cursor wrote last week.

Connect a repo. Vidoc returns a short, verified list of real AppSec issues - with exploitability, severity, and a PR-ready fix prompt for each one.