日本語

Bugoon Security

A macOS app for systematic security reviews, with Claude, of repositories that you or your team maintain. Each finding comes with the relevant code and the reasoning behind it.

Download

We are preparing the first release. When it is published, the link to the dmg and its SHA-256 will appear here.

Bugoon Security is free. It is a separate product from Bugoon (the in-browser bug reporting service) and comes with no warranty. Support is by email to the contact address below.

Requirements

Claude usage is billed to your own Anthropic, AWS or Google Cloud account. The app shows an estimated cost before each scan and stops a scan when it reaches the cost limit you set.

Getting started

  1. Open the dmg and drag Bugoon Security to the Applications folder.
  2. We recommend verifying the app first.
  3. Open Bugoon Security from Applications. The app is notarized by Apple, so the only prompt is the usual one for apps downloaded from the internet.
  4. In Settings, under Using Claude, choose how to use Claude (API key, Amazon Bedrock or Google Vertex AI), the model and the cost limit.
  5. In Settings, under Repository, add the folder of the repository to review.
  6. Start a scan. You can check the list of files sent to the AI before anything is sent.

Setting up Claude

Anthropic API key

  1. Sign in to the Claude Console and add a payment method.
  2. Under API Keys, choose Create Key and give it a name, for example bugoon-security. The key is shown only once.
  3. In the app, under Settings and Using Claude, choose API key, paste the key and save it to the Keychain.

The key is stored only in the macOS Keychain and is never shown on screen. Setting a monthly limit under Limits in the Console adds a second safeguard on top of the app's cost limit.

Amazon Bedrock

Enable Anthropic models in Bedrock for your AWS account, and set up AWS credentials on this Mac (~/.aws/credentials or aws configure). The app does not store AWS credentials.

An app opened from the Finder does not receive environment variables set in your terminal. Set the region and other values like this before opening the app. They are cleared when the Mac restarts.

launchctl setenv AWS_REGION us-east-1
launchctl setenv AWS_PROFILE default

Only AWS_REGION, AWS_PROFILE, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_SESSION_TOKEN are passed on. Reopen the app afterwards and choose Amazon Bedrock.

Google Vertex AI

Enable Claude models in Vertex AI for your Google Cloud project, and create credentials with gcloud auth application-default login. Then set these before opening the app.

launchctl setenv CLOUD_ML_REGION us-east5
launchctl setenv ANTHROPIC_VERTEX_PROJECT_ID your-project-id

Only CLOUD_ML_REGION, ANTHROPIC_VERTEX_PROJECT_ID and GOOGLE_APPLICATION_CREDENTIALS are passed on. Reopen the app afterwards and choose Google Vertex AI.

gitleaks and osv-scanner

Neither tool is bundled with the app. The app looks for them on PATH and in the Homebrew locations /opt/homebrew/bin and /usr/local/bin. The easiest way to install them is with Homebrew.

brew install gitleaks osv-scanner

Once installed, the versions found are shown in Settings.

Verifying the app

You can check in Terminal that the dmg you downloaded has not been altered and that the app is signed by RUBY JOBS K.K.

Compare the SHA-256

shasum -a 256 ~/Downloads/Bugoon-Security_VERSION_aarch64.dmg

Check that the value matches the one listed under Download and the sha256 in /latest.json.

Check the signature and notarization

spctl -a -vv "/Applications/Bugoon Security.app"

The app is signed by RUBY JOBS K.K. and notarized by Apple if the output includes all three of these:

The bundled claude (Anthropic's Claude Code) is included unmodified, as signed by Anthropic.

What is not guaranteed

Code leaves this Mac only when it is sent to Claude. You can review what will be sent beforehand, and values such as keys are redacted. No telemetry is sent.

Announcements (optional)

Get an email when a new version of Bugoon Security is out or when an update fixes something urgent. We send nothing else. You do not need to sign up to download.

We will send you a confirmation email (in Japanese). You are not signed up until you click the link in it. You can unsubscribe at any time from any announcement email. See "Signing up for announcements" in the privacy policy for how we handle your address.

Contact

Send bug reports, security reports and questions to info+bugoon-security@rubyjobs.jp. Please do not disclose a vulnerability publicly until a fix has been released. The same address is shown in the app's Settings.

Operated by RUBY JOBS K.K. · Terms of use · Privacy policy