MCP security
Scan every MCP server your agents load — across Claude Code, OpenCode,
VS Code, Cursor, and Claude Desktop — enforce an org allowlist, and audit
real usage, all from the ringzero-mcp CLI.
MCP security
Scan every MCP server your agents load — across Claude Code, OpenCode,
VS Code, Cursor, and Claude Desktop — enforce an org allowlist, and audit
real usage, all from the ringzero-mcp CLI.
Supply chain scanning
Find vulnerable dependencies in large Gradle builds or npm workspaces. Trace Gradle findings to introducing modules and teams, and inspect affected consumers with your own service and domain labels.
Security scanning
Host scanning is planned for infrastructure your organization controls. The sidecar and Scan Gateway integration is coming soon. Review the proposed registration flow and network requirements before planning a rollout.
Least-privilege credentials
Every API key is scoped — explicit permissions and a project restriction, fixed at creation. Limit CI keys to the scopes and projects they need; API keys cannot perform session-only administration.
One API
Everything talks to https://api.ringzero.tech/v1 with bearer
authentication and JSON bodies — the same API our Gradle and npm
integrations use.
New to RingZero? The product overviews on the main site explain what each capability does and why: MCP security · AI penetration testing · supply chain security · automated remediation