Bugoon Security
A macOS app for systematic security reviews, with Claude, of repositories that you or your team maintain. Each finding comes with the relevant code and the reasoning behind it.
Download
We are preparing the first release. When it is published, the link to the dmg and its SHA-256 will appear here.
Bugoon Security is free. It is a separate product from Bugoon (the in-browser bug reporting service) and comes with no warranty. Support is by email to the contact address below.
Requirements
- A Mac with Apple silicon (M1 or later) running macOS 13 or later. Intel Macs are not supported at this time.
- A way to use Claude: an Anthropic API key, Amazon Bedrock, or Google Vertex AI. A claude.ai subscription (Pro, Max and so on) cannot be used.
- A git repository that you or your team maintain.
- Recommended: gitleaks (checks for keys and passwords) and osv-scanner (checks dependencies for known vulnerabilities). Without them, those checks are skipped.
Claude usage is billed to your own Anthropic, AWS or Google Cloud account. The app shows an estimated cost before each scan and stops a scan when it reaches the cost limit you set.
Getting started
- Open the dmg and drag Bugoon Security to the Applications folder.
- We recommend verifying the app first.
- Open Bugoon Security from Applications. The app is notarized by Apple, so the only prompt is the usual one for apps downloaded from the internet.
- In Settings, under Using Claude, choose how to use Claude (API key, Amazon Bedrock or Google Vertex AI), the model and the cost limit.
- In Settings, under Repository, add the folder of the repository to review.
- Start a scan. You can check the list of files sent to the AI before anything is sent.
Setting up Claude
Anthropic API key
- Sign in to the Claude Console and add a payment method.
- Under API Keys, choose Create Key and give it a name, for example
bugoon-security. The key is shown only once. - In the app, under Settings and Using Claude, choose API key, paste the key and save it to the Keychain.
The key is stored only in the macOS Keychain and is never shown on screen. Setting a monthly limit under Limits in the Console adds a second safeguard on top of the app's cost limit.
Amazon Bedrock
Enable Anthropic models in Bedrock for your AWS account, and set up AWS credentials on this Mac (~/.aws/credentials or aws configure). The app does not store AWS credentials.
An app opened from the Finder does not receive environment variables set in your terminal. Set the region and other values like this before opening the app. They are cleared when the Mac restarts.
launchctl setenv AWS_REGION us-east-1
launchctl setenv AWS_PROFILE default
Only AWS_REGION, AWS_PROFILE, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_SESSION_TOKEN are passed on. Reopen the app afterwards and choose Amazon Bedrock.
Google Vertex AI
Enable Claude models in Vertex AI for your Google Cloud project, and create credentials with gcloud auth application-default login. Then set these before opening the app.
launchctl setenv CLOUD_ML_REGION us-east5
launchctl setenv ANTHROPIC_VERTEX_PROJECT_ID your-project-id
Only CLOUD_ML_REGION, ANTHROPIC_VERTEX_PROJECT_ID and GOOGLE_APPLICATION_CREDENTIALS are passed on. Reopen the app afterwards and choose Google Vertex AI.
gitleaks and osv-scanner
Neither tool is bundled with the app. The app looks for them on PATH and in the Homebrew locations /opt/homebrew/bin and /usr/local/bin. The easiest way to install them is with Homebrew.
brew install gitleaks osv-scanner
- gitleaks looks for keys and passwords in the code and in the git history. Values it finds are redacted.
- osv-scanner checks dependencies listed in lockfiles for known vulnerabilities, and the AI checks whether the vulnerable code is actually called. By default only the local vulnerability database is used and nothing is sent over the network. If you allow it in Settings, the database is downloaded for each scan. Lockfile contents and code are never sent.
Once installed, the versions found are shown in Settings.
Verifying the app
You can check in Terminal that the dmg you downloaded has not been altered and that the app is signed by RUBY JOBS K.K.
Compare the SHA-256
shasum -a 256 ~/Downloads/Bugoon-Security_VERSION_aarch64.dmg
Check that the value matches the one listed under Download and the sha256 in /latest.json.
Check the signature and notarization
spctl -a -vv "/Applications/Bugoon Security.app"
The app is signed by RUBY JOBS K.K. and notarized by Apple if the output includes all three of these:
acceptedsource=Notarized Developer IDorigin=Developer ID Application: RUBY JOBS K.K. (MY6U279MM8)
The bundled claude (Anthropic's Claude Code) is included unmodified, as signed by Anthropic.
What is not guaranteed
- Finding nothing does not prove there is no problem. AI reviews miss things.
- Resolved means that the check which confirmed a finding no longer holds at that commit. It does not prove the code is safe.
- The correctness of AI findings, checks and suggested fixes is not guaranteed. Whether to apply them is your decision.
- Only repositories on your own computer that you or your team maintain may be reviewed. The app is not for examining other people's systems.
Code leaves this Mac only when it is sent to Claude. You can review what will be sent beforehand, and values such as keys are redacted. No telemetry is sent.
Announcements (optional)
Get an email when a new version of Bugoon Security is out or when an update fixes something urgent. We send nothing else. You do not need to sign up to download.
We will send you a confirmation email (in Japanese). You are not signed up until you click the link in it. You can unsubscribe at any time from any announcement email. See "Signing up for announcements" in the privacy policy for how we handle your address.
Contact
Send bug reports, security reports and questions to info+bugoon-security@rubyjobs.jp. Please do not disclose a vulnerability publicly until a fix has been released. The same address is shown in the app's Settings.
Operated by RUBY JOBS K.K. · Terms of use · Privacy policy