Golem AI
The security layer for vibe-coded apps. Golem AI is the security layer for vibe-coded apps: a security audit platform that runs full-scope offensive engagements without an operator at the keyboard. You provide a target domain. An AI agent in a hardened Linux sandbox performs reconnaissance, enumerates the attack surface, identifies vulnerabilities, attempts exploitation, and delivers an evidence-backed report — all in minutes to hours. Behind every audit is Golem, an autonomous red-team agent with full access to a pre-built offensive toolkit: nmap, nuclei, sqlmap, hydra, metasploit, bloodhound, and dozens of others. The agent plans its own attack chain, executes commands in a real shell, captures evidence, and writes the findings.Start here
Quickstart
Run your first audit in under five minutes.
Core Concepts
Workspaces, audits, findings, and the Golem agent.
Attack Methodology
The 10-phase chain Golem executes on every engagement.
API Reference
Programmatic access to audits, findings, and reports.
Audit modes
What you get from every audit
- Findings — confirmed vulnerabilities with severity, evidence, and remediation
- Security score — letter grade (A+ to F) derived from finding weights
- PDF report — executive-ready report with cover, summary, and per-finding pages
- Session recording — full asciinema replay of every command the agent ran
- Screenshots — visual evidence captured at the moment of discovery
Built for
Security Teams
Scale your offensive coverage without scaling headcount. Run continuous assessments across your entire surface.
MSSPs
Multi-tenant workspaces let you isolate client engagements with per-workspace billing, custom domains, and Slack delivery.
Developers
Trigger audits from CI on every release. Programmatic findings, PDF retrieval, and webhook callbacks.
Compliance Teams
Schedule recurring audits for SOC 2, PCI, and continuous compliance evidence.
Join our Discord
Share findings, ask questions, and connect with the Golem AI community.