nowfound

Alternatives

Products that do what TrustLayer Labs does

Web & API VAPT to find vulnerabilities before hackers

  1. 1

    Discover, Scan, and Secure every API at scale

    2025

  2. 2

    An open source security scanner for Visual Studio Code

    2020

  3. 3

    Free enterprise grade security for your personal browser

    2023

  4. 4

    Fraud and theft protection for cryptocurrency

    2018

  5. 5SI

    Hey HN, TL;DR: We’ve launched a free version of our Shadow IT scanner to identify which SaaS apps are used in your company, who uses them, and if they have high-risk OAuth scopes. Philip and I went through YC with AccessOwl in 2022. We started the company because, in our previous roles, we struggled to track all the SaaS apps, users, and granted OAuth scopes. The Shadow IT scanner started as a small feature within AccessOwl, which manages SaaS vendors and user accounts centrally. But a standalone scanner would have made our lives so much easier in our previous roles. So, we thought, why not…

    2024 · accessowl.io

  6. 6

    Show your security posture with confidence

    Oct 2025

  7. 7WP
  8. 8BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com

  9. 9IA

    IPDetective collects data from about 60+ different sources such as official cloud provider endpoints and public VPN/Proxy/Tor/Bot net lists. Then aggregates this data into a fast and easy to use API that can be integrated into applications or scripts easily. IPDetective started as a hobby project for my other hobby projects :) and I decided to wrap a simple website around and offer it as a service. Let me know what your thoughts, if you find value in this service or if you have any feature requests.

    2022 · ipdetective.io

  10. 10

    Secure your web applications from the latest vulnerabilities

    2020

  11. 11

    Find your web app's vulnerabilities before attackers do

    Jul 2026 · sensagraph.com

  12. 12

    Find GDPR risks on your live site before regulators do

    Feb 2026

  13. 13

    You build. We secure. 🛡️🚀

    Apr 2026 · vaptinsights.com

  14. 14
    Vibio12

    Vibio finds security vulnerabilities in your app/codebase.

    Mar 2026

  15. 15
    ETrust2

    The trust layer for production-ready AI agents

    Feb 2026

  16. 16AP

    This is the repository for the Zero Trust VPN code run by VP.NET that allows you to verify that the servers are running the same code as the repository using Intel SGX for hardware guarantees.

    2025 · github.com

  17. 17

    Know Before You Click. Know Before You Agree.

    Jul 2026 · handsome-trust-lens-check.base44.app

  18. 18CB

    AI agents now have impressive reasoning capabilities. This raises an important question: how dangerous are these AI agents at identifying & exploiting web vulnerabilities? We created CVE-bench to find out (I'm one contributor of 16). To our knowledge CVE-bench is the first benchmark using real-world web vulnerabilities to evaluate AI agents' cyberattack capabilities. We included 40 CVEs from NIST's database, focusing on critical-severity vulnerability (CVSS > 9.0). To properly evaluate agents’ attacks, we built isolated environments with containerization and identified 8 common attack…

    2025 · github.com

  19. 19OS

    tl;dr we released openapi.security, an online tool that performs a dozen of security tests on any given openapi/swagger-based API, with no signup or email required. You can try it here: https://openapi.security My team at Escape (YC W23) is mainly focused on securing GraphQL APIs. For this, we developed a new approach called Feedback driven API Exploration. Basically, we infer the right security tests cases to run using the specification and a carefully crafted in house graph traversal algorithm. (It's a bit long to describe here but we published a more in depth explanation of…

    2023 · openapi.security

  20. 20TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev

  21. 21

    Find your app's critical vulnerabilities before attackers do

    Jun 2026 · pentestr.up.railway.app

  22. 22

    See your SaaS company the way your buyers see it.

    Feb 2026

  23. 23TR

    I'm a network engineer that likes to think about the future of the internet and this is what I've built over many nights and weekends. One reputation graph over IPs, ASNs, domains, and entities, exposed as a JSON API. Try it: curl https://api.tunnelmind.ai/v1/check/1.1.1.1 Every answer is a signed receipt with an attestation tier so you can see what was produced and how your agents can use it. The protocol is opensource. Try it out let me know what you think and yes I am still working on the radar section of the site. Also What would make this useful for you?

    Jun 2026 · tunnelmind.ai

  24. 24BX

    Hi HN, I’m the founder of https://b2v.xyz, a service that protects organizations against impersonation attacks. The problem I’m trying to solve stems from the following observation: while end-user authentication methods are becoming more advanced as cybersecurity evolves, organizations aren't experiencing the same improvements when we reverse the roles, i.e. when organizations authenticate themselves to their users. This imbalance leaves a gap in secure communications that B2V aims to close. Bad actors have countless ways to pose as trusted entities — through phishing, smishing,…

    2024 · get.b2v.xyz

Ranked by how close each launch is in meaning, then by votes. Refine with a description →