Cybersecurity Lab

A lab for security work.
AI-native instruments that find, prove, and fix.

SecBlok builds AI-native instruments for finding and fixing real vulnerabilities. We ship tools, not dashboards. Each one is engineered to give a single operator the reach of a team.

Instruments

Products

Each instrument is built to stand alone and to give one operator the reach of a team. Designed to scale, so the next instrument is one more card.

Live · invite beta

SecDog Scanner

Autonomous AI penetration testing. It only marks a finding verified after it has executed the exploit and sealed the evidence on your machine.

Open SecDog Scanner
Live · open source

Belay

A local security layer for AI coding agents. It gates every tool call at the boundary — deterministic, sub-100ms, no LLM in the decision path — and pauses only on the calls that need a human to decide.

Open Belay
Launching next

SecDog Report Generator

Turn raw pentest findings into client-ready reports. A four-stage AI pipeline (vulnerability, attack chain, threat model, report) instead of a Word template. DOCX & Markdown, with MITRE ATT&CK and CVE context.

Get notified
In development

More in the lab

More AI-native instruments are in development.

The standard

Every instrument holds the same line.

SecBlok is a lab, so our products share more than a logo. Every instrument we ship meets the same standard: it runs on the operator’s machine, it proves what it finds, and the operator keeps their data. A new product earns its place by clearing that bar.

  • LOCAL BY DEFAULT Every SecBlok instrument runs on the operator’s machine. Target data stays with the operator, never on our servers.
  • EVIDENCE-FIRST Our tools confirm what they report. A finding stands on an executed exploit and sealed evidence.
  • ONE ACCOUNT A single SecBlok account and an Ed25519-signed license carry the operator across every instrument we ship.
Open your account

FLAGSHIP · SECDOG SCANNER

AI penetration testing that proves every vulnerability it finds.

SecDog Scanner is an autonomous AI penetration testing tool that finds web application vulnerabilities and proves them by executing the exploit and sealing the evidence. It runs locally on your own machine, and it is built for the people who do the work: independent pentesters, bug bounty hunters, red teams, consultancies, and in-house security teams.

Runs on your machine. Target data never reaches our servers.

OPEN SOURCE · BELAY

A hard boundary in front of your AI coding agents.

Belay is a local security layer that sits at the tool-call boundary of your AI coding agents. It blocks the dangerous calls — secret exfiltration, destructive commands, reverse shells — deterministically, in under 100ms, with no LLM in the decision path, and pauses only on the calls that need a human to decide. Works with Claude Code, Codex, Cursor, and more.

Runs as your user. Never phones home. Free & open source.

Lab

Built by practitioners, for practitioners.

We are a small lab that builds offensive-grade tooling. We write the instruments we wished we had as practitioners, and we hold them to a practitioner's bar.

The bar is simple: offensive-grade tooling, engineered for one operator. Each instrument should give a single person the reach of a team, and prove its findings rather than assert them.

We ship tools. We don't publish vanity metrics. The instruments stand on what they prove.