Berkner Tech

Berkner Tech

Free Security Scanner

Paste a repository URL and get a scored security rubric in minutes. Everything runs in your browser: nothing is uploaded, no account is needed, and your code never leaves your machine.

what it checks

278 Rules Across 11 Categories

The scanner reads firmware, PCB schematics, mobile apps, web apps, backends, cloud and IaC, and engineering documentation from GitHub, GitLab, Bitbucket, Azure DevOps, or Gitea and Codeberg.

Scored Visual Rubric

A donut gauge, letter grades, and per-category breakdowns show exactly where a repository stands, with findings and remediation guidance for each rule.

Live CVE Scanning

Declared dependencies are checked against the live OSV.dev vulnerability database, and every known CVE comes with a verification outline you can reproduce.

SBOM Export

Export a software bill of materials in CycloneDX 1.5 or SPDX 2.3, with valid PURLs and CVE data embedded, ready for compliance paperwork.

scan scopes

Pick the Frameworks That Matter to You

One-click presets configure the rubric for your market, or choose individual frameworks. Deselected frameworks are excluded from the weighted score.

Enterprise-Grade (All)

Every framework below in one pass. The default, and the closest thing to how we scope a full product security assessment.

EU Market Readiness

Best practices and CVEs plus the EU Cyber Resilience Act, RED 3.3 / EN 18031, and the Data Act, with GDPR, NIS2, and DORA available as individual scopes.

US Federal / FIPS

Security best practices and CVEs plus FIPS 140-3 and NIST guidance for teams selling into US federal environments.

Essentials

Just security best practices and known CVEs. A fast first look for any repository, plus MISRA C/C++ as an add-on for safety-critical code.

open source

Client-Side, Transparent, and Free

No AI, no server, no cost to run. The only network calls are to your hosting provider (to fetch the repository) and to OSV.dev for live CVE data. The full source is on GitHub, so you can read every rule we check, open an issue, or run the scanner yourself. It is an automated first pass, not a substitute for a hands-on review.

Want a Deeper Assessment?

The scanner is where we start, not where we stop. When you are ready, we go hands-on with your hardware, firmware, and the cloud services behind them.