Velcon preview

Connect a repository

Velcon runs a scheduled penetration test against your application and returns findings to GitHub — inline on your code, plus a report you can hand to someone.

Connect GitHub

What Velcon asks for

contents: readRead your source to find where vulnerabilities live. Never written to.
security_events: writePublish findings to GitHub Code Scanning, inline on the affected lines.
checks: writeReport scan status against a commit.

A GitHub App, not OAuth — tokens are scoped to the repositories you pick, expire on their own, and you can revoke access from GitHub without asking us.

Not connectable yet This preview is live, but no GitHub App is wired to it yet.