Skip to main content
Security scan gives your project a full security checkup before launch: multiple checks, AI triage to confirm real risk, optional automatic fixes, and an audit report anyone can understand.
Security scan is a paid capability billed in credits: each run has a 10-credit start fee plus usage-based charges; when remediation is needed, security fixes applied automatically are also billed by usage.

What it does

  • Multi-dimensional checks: Code security, secret leakage, dependency vulnerabilities, database configuration, and data permissions.
  • AI triage: Validates each finding, filters false positives, keeps real risk, and decides if fixes are needed.
  • Automatic fixes: When needed, superun applies fixes in chat from the remediation plan — no manual patching required.
  • Readable audit report: Plain language, no security background required; PDF download supported.

Check types

Before starting, choose which checks to run (all selected by default): Database security scan and data permission checks require database capabilities to be enabled on the project.

How to use it

1

Start a scan

On the Build tab, open Security scan, select checks, and click Start security scan. Each run has a 10-credit start fee plus usage-based billing.
2

Wait for checks and triage

The scan runs in the background; follow per-check progress and triage results in the panel and conversation stream.
3

Auto-fix (when needed)

If triage says fixes are required, superun completes security fixes in chat. Fixes are billed by usage.
4

View the audit report

When done, click View audit report and download PDF if needed.
Security scan unlocks after architecture sign-off in the project; wait if a conversation is in progress or a security fix release is still publishing before starting another scan.

Audit report

  • Overview: Overall conclusion for this scan.
  • Issue stats: Counts by critical, high, medium, and low severity.
  • Issue list: Type, severity, root cause, and fix status per issue, sorted by severity.
If no issues are found, the report shows a No security issues found badge. Past scans are kept in Security scan history at the bottom of the panel with outcomes (no risk, fix needed, handled, expired) for later review.

Common situations

  • Rescan: After meaningful code changes, older reports may be marked expired — run a new scan.
  • Invalid scan: If security fixes were not completed or were interrupted, results are invalid — start a full scan again.
  • Report generation failed: Use Retry report generation without rescanning or re-fixing.
  • Cancel scan: You can cancel while in progress; after the audit report succeeds, cancellation is not available.

superun website

Visit the superun website for more features and examples.