Catch security issues before you get hacked.
CyberDuty combines AI-native security scanning and a remedy dashboard into one developer-friendly CLI. Give your developers fast, repeatable security scanning built for the AI age.
"If you don't use a tool like CyberDuty, you will get hacked sooner or later. We have it embedded in our CI & dev process, so we can ship with confidence."
MPT was built for a world that no longer exists.
When software shipped quarterly, an annual penetration test made sense. Today, engineering teams ship dozens of times a week. Traditional MPT doesn't just fall short — it creates a dangerous illusion of security while your real attack surface grows undetected between sprints.
Your annual pentesting is pointless.
You ship every sprint. Your pentest happens once a year. Every feature or config change in between is a business liability, or worse, a company killer.
- Every sprint widens the security gap. New routes, dependencies, APIs, container images can introduce vulnerabilities the last pentest has never seen.
- Enterprise deals, compliance audits, and cyber insurers want ongoing evidence. A year-old PDF document is not a security program. Timestamped security scans give the evidence you need.
- Fixing is cheapest when context is fresh. CyberDuty lets the engineer who shipped the change see the security issue and fix it before a malicious actor finds it.
Know your risk before your customers do.
CyberDuty: when the code changes, security gets checked. No waiting for an annual report. No vague scanner dump that nobody owns or understands.
-
$Stop absorbing breach costs.Problems found in local development cost a fraction of problems found by customers, regulators, or attackers.
-
✓Clear ownership, not chaos.The engineer who shipped the change sees the finding immediately — no ticket lost in a security backlog.
-
↻Security becomes a habit.Run CyberDuty before every release. It becomes invisible — until it catches something that would have been very expensive in production.
-
⚑Evidence for everyone who asks.Show board members, customers, insurers, and auditors that security is embedded in your delivery process.
Docker ready. No new infrastructure.
CyberDuty works with the Docker setup your team already uses. Just install the CLI and get going. There's nothing to provision, no agents to deploy, no cloud to configure.
Your app, running normally
Start your application in Docker or Docker Compose — exactly as your team already does.
One command to scan
Point CyberDuty at the running container and tell it what to test. Everything runs automatically.
Prioritized findings
Open the local dashboard to review risks by severity, each with clear evidence and remediation.
Ship with evidence
Fix what matters and ship with confidence. Make security real-time, not an afterthought.
Let Claude scan while you build.
CyberDuty fits your Claude Code workflow in two ways — you invoke it, or Claude does.
In the Claude terminal
Run cyber pentest directly inside a Claude Code session. Claude reads the structured output and proposes fixes before you've switched tabs.
As an MCP tool
Register CyberDuty as an MCP server. Claude invokes cyber_pentest automatically during code review — structured results come back, remediations go straight into your editor. No copy-paste. No context switch.
Let me fix config.js:12 first…
the diff in the editor panel →
One command from a security signal.
CyberDuty Scanner runs from your terminal against any Dockerized application. The full reference covers every command, flag, engine option, and configuration setting.
Stop guessing. Start scanning.
CyberDuty installs in minutes and runs against any Dockerized application. Get a real security signal before your next release.