Products and boundaries
Three product lines, with explicit availability.
CodeRiskTools has exactly three main product lines: the public MIT Secret Scanner Engine 3.1.1, the proprietary MCPwatch Scanner + Report Pack v0.5.2, and the separate proprietary AI Change Firewall.
Developer Safety Kit and MCPwatch Exposure Ledger Professional/Agency have been withdrawn from public sale. Existing buyers retain access; no record or entitlement is deleted.
Current catalog
Public MIT — available
Secret Scanner Engine 3.1.1
Public MIT-licensed engine with 299 native detectors for local secret and configuration-change review. Version 3.1.1 adds local SBOM vulnerability scanning against a real, signed OSV starter database with 243,381 CVE/OSV records from the first scan. The database can grow toward the full OSV source count, currently 813,101 records. Verified smoke: a CycloneDX SBOM produced 3 local findings against the active starter DB. Pre-commit and GitHub Action workflows included.
Observatory integration is available in coderisktools-observatory: observatory vuln-sbom records the Scanner 3.1.1 SBOM result as exact-SHA, review-gated evidence for public repository reports.
Proprietary — available
MCPwatch Scanner + Report Pack v0.5.2
Local GNU/Linux x86_64 scanner and report workflow for authorized MCP surface review. Professional is $99 for one organization; Agency is $249 for authorized client engagements. Both editions include the same complete product capabilities.
Proprietary — available
AI Change Firewall
Professional is available for $19 and Agency for $30 as one-time purchases. The public MIT Secret Scanner Engine remains separately available.
Limitations
Release evidence is scoped.
These pages describe release facts and product boundaries. They do not claim security guarantees, broad superiority, production efficacy, or that any scanner replaces human review, SAST, SCA, dependency review, or operational security controls.