FAQs

Frequently Asked Questions

Developer And Enterprise, In Plain Words.

What Sekura does, how to start, what a report contains, and how your code and billing are handled — grouped so you can jump to what you need.

Sekura — owl-in-shield mark

FAQ

Common questions

Everything a developer or an enterprise buyer tends to ask, grouped so you can jump to what you need. Plain language — no acronyms to decode.

What Sekura does

What is Sekura?
Sekura is autonomous security testing. Its AI agents probe your code the way an attacker would and report only the weaknesses they could actually exploit — each one with a working proof and a one-line fix.
How is this different from a vulnerability scanner?
A scanner gives you a long list of possible issues ranked by a score. Sekura confirms each finding by exploiting it, and reports only what it can prove. If something cannot be exploited in your environment, it is not reported — so there is no pile of maybes to triage.
Are the findings real, or theoretical?
Real. Each finding carries the exact request and response that demonstrate it, so you can check it yourself in a couple of minutes without taking our word for it.
What does Sekura test that a single tool misses?
In one pass it looks at your application, the AI and model parts of it, and whether your cryptography would survive a future quantum computer — surfaces most teams buy separate tools for and then line up by hand.
Can Sekura test my running application, not only the code?
Yes — on the enterprise plans. LiveScan and MasterScan test your live application, signed in, against the host you run; because live testing touches a system you operate, it is enterprise-only: you contact us, provide VPN tunnel details and sign an SLA and a liability release first. The self-serve paid plans test your code and a private lab copy of your application.

Getting started and the free first scan

How do I start?
Sign in with GitHub, choose a repository, and Sekura runs the full test. Your first scan is free.
What does the Free Scan cost, and what does it ask for?
Nothing, and one thing: sign in. No card, no company, no phone number. One repository, one code test.
Do I need to install anything?
No. For the self-serve plans Sekura runs on its own infrastructure. To scan continuously inside your own pipeline, one workflow file is added to your repository.
Can I scan a private repository?
Yes — install the Sekura GitHub App on it and grant the repository. Public repositories can be scanned without the App.
How long does a scan take?
Usually about ten to fifteen minutes. While it runs, the page shows which phase it is in, so a wait is never a blank spinner.

Plans and cadence

What plans are there?
Start with a free code scan. Scan Once is a $199 one-off that also tests a private lab copy of your app. The monthly plans keep a repository checked on a schedule: Scan Always ($20 a month, code test, weekly), ScanPlus Always ($100, adds a lab copy, weekly) and ScanPro Always ($300, adds a lab copy, daily). Live-application and network testing are enterprise plans — LiveScan and MasterScan.
What is the Free Scan?
A free code test of one repository, run once, no card. It is the quickest way to see a real report on your own code.
What does a paid plan add?
Two things, by plan: a regular cadence — weekly or daily — so a repository stays checked, and a test of a private lab copy of your application on ScanPlus, ScanPro and the enterprise plans. Every scan includes remediation guidance.
Can I change plans?
Yes, from your dashboard at any time. The monthly plans come with a 10-day free trial, so you get at least two scans before the first charge.

Reports and proof

How do I get my report?
It is emailed to you, in the body of the message, at a verified address on your account. It also stays in your dashboard.
What is in a report?
A summary first, including what was and was not checked. Then each finding in four parts: what a stranger could do in one plain sentence, the evidence that proves it, how it was confirmed, and a one-line fix.
How long are reports kept?
The full report and its proof are kept for 60 days so a failed delivery can be retried, then deleted. A short summary — findings by severity and how the scan was billed — stays after that.
Does Sekura fix the issues for me?
It hands back the change. Depending on what you have granted, the fix arrives as a pull request in your repository, or as a patch inside the report for you to apply.
Will I get false positives?
No. If Sekura cannot prove a finding by exploiting it, the finding is not reported.

Your code, data and privacy

Does Sekura see my source code?
It depends on the plan. On the free scan and the self-serve Once and Always plans, Sekura clones your repository into an isolated container on its own infrastructure, reads it, and destroys the container. Running Sekura in your own pipeline or on-premises, only the findings and the content sent to the model leave your environment.
Does Sekura change my code?
No. It only ever reads your repositories; it never writes to them.
Is my code used to train models?
No. Sekura never uses your code to train models for other customers.
What happens to my data if I delete my account?
Deleting your account cancels any subscription in the same step and deletes your stored reports immediately. One record is kept: the authorization showing you permitted the testing — it is retained as legal evidence, and the privacy notice says so.

GitHub access, accounts and organizations

How does signing in work?
Sekura signs you in with GitHub and nothing else. The first time, GitHub shows its authorization page; after that, Sekura greets you by name and one click takes you in.
I never saw a GitHub page — did it sign me in?
Yes. GitHub asks you to authorize Sekura once per account, then recognises you and sends you straight back. To see the page again, revoke Sekura under GitHub → Settings → Applications and sign in again.
Sekura signed me in as the wrong account.
Sekura shows whoever signed in last on this browser under Welcome back. Press the × on that row to forget it, or choose Use a different GitHub account. Switching signs you out of the first account; it does not join the two.
I want repositories from another account or organization in the same Sekura account.
Do not sign in twice. Install the Sekura App on that account or organization, and its repositories appear in your existing Sekura account. On the scan page, Don’t see a repository? takes you there.
GitHub did not release an email address.
Sekura needs one email to send reports to. Under GitHub → Settings → Emails, make an address public or untick Keep my email addresses private, then sign in again.

Billing, cancellation and refunds

When am I charged?
Never for the Free Scan. Scan Once is $199, paid once. The monthly plans — Scan Always $20, ScanPlus $100, ScanPro $300 — take a card at purchase and start a 10-day free trial, so you get at least two scans before the first charge: one when you set it up, and one on the weekday you choose.
Can I cancel a scan right after I start it?
Yes, within 5 minutes of starting it. A scan that is cancelled, or that produces no report, does not spend your free scan.
Do I get a refund if I cancel a paid scan?
Cancelling a paid scan returns a credit to your account rather than a refund. Credits are shown on your account and are spent before any card is charged.
How do I cancel a monthly plan?
From your dashboard, at any time.
Can I test more than one app or network?
Yes. An additional target app is $100 — a month on the monthly plans, one-time on Scan Once. On MasterScan, nodes beyond the first ten are $100 per ten.
What happens if my card fails to renew?
The month you already paid for is honoured to its end.

Enterprise, deployment and POC

What does enterprise add?
Testing of your live application — signed in, against the host you run — and network security. The enterprise plans are LiveScan Always ($300 a month: code and live-application testing, daily) and MasterScan Always ($600 a month: adds network security and ten nodes, daily). On-premises deployment is available too.
How do I buy an enterprise plan?
The prices are published — LiveScan $300 a month, MasterScan $600 a month, extra nodes $100 per ten — but enterprise plans are not bought online. You contact us, provide VPN tunnel details, and sign an SLA and a liability release before any live testing runs.
What does live-application testing need?
The URL where your application runs, proof that you control that host, and a test account’s credentials, provided over a VPN tunnel. Sekura signs in as that test account and never changes its password, creates accounts or deletes anything.
Who pays for model inference?
Bring your own model key, or use ours. On-premises deployments include inference, so they do not come with a model-procurement problem attached.
How do I evaluate Sekura for my company?
Request a POC. Tell us what you are protecting and where it has to run, and the team follows up.

Integrations and compliance

What does Sekura work with?
Meta Muse through a REST API, GitHub Actions and self-hosted runners, model providers including Anthropic Claude and OpenAI GPT (and private endpoints on Enterprise), and Slack, Teams, Jira, Outlook and Confluence for notifications and fixes.
Does Sekura help with compliance?
Findings are mapped automatically to 14 compliance frameworks — SOC 2, ISO 27001, PCI DSS, HIPAA, NIST and more — so audit prep is a byproduct of every scan.
Can I use Sekura from an AI agent?
From Meta Muse, yes. Ask Muse to connect Sekura; it opens a link where you sign in with GitHub, install the App on the repositories you want scanned, and approve — there is no key to copy. The agent then does what your dashboard does, and every paid action is quoted to you and confirmed before anything happens. Claude comes later.
Does running in my own CI keep my code in place?
Yes. Sekura runs on your GitHub Actions runner; your source never leaves your repository, and only the findings come back.

Support

How do I get help?
Write to support@sekura.ai, or use the support panel in the product. A support assistant answers common questions and hands anything else to a person.
Something in sign-in went wrong.
Most sign-in snags are GitHub verifying a new device or rate-limiting repeated sign-ins. Signing in at github.com first, then returning to Sekura, usually clears it. If it persists, contact support with the time of the attempt and the browser you used.