Your first GitHub repository audit is free.No card. Every finding included.
aster

TRUST & SCOPE / YOUR CODE, YOUR CONTROL

Know what
you’re sharing.

Before Aster takes a second look, you should know what it reads, what it checks, and where its limits are.

Small permissions.
Open explanations.
01 / YOU CHOOSE

Your GitHub repository

Selected repositories only. Contents and metadata access are read-only.

02 / ASTER CHECKS

A bounded source review

Files are read into server memory and checked. No code execution or AI model transfer.

03 / YOU REVIEW

A report you can keep

File locations, findings, and coverage. Your latest report is saved to your account. Download a copy whenever you need it.

A defined scope.
A useful starting point.

Aster runs static rules against a snapshot of your default branch. The report explains the files that were checked and the files that were skipped.

80text files per audit
2 MBtotal source budget
128 KBmaximum per file
JS / TSsyntax & pattern checks
01 / CREDENTIAL PATTERNS

Potential secrets in source.

Recognizable GitHub, Stripe, and OpenAI token formats, private-key markers, and potentially sensitive environment settings. Matched values are redacted from findings. A pattern match does not establish whether a credential is valid.

02 / SELECTED CODE PATTERNS

Risky settings and operations.

Disabled TLS checks, dynamic evaluation, unsafe raw queries, selected permissive CORS and JWT settings, dynamic HTML, and disabled TypeScript build-error checks. These are review candidates; runtime exploitability is not reproduced.

03 / SOURCE STRUCTURE

Syntax and client/server imports.

JavaScript, JSX, TypeScript, and TSX syntax checks. The client/server check follows scanned relative imports from a “use client” file. It does not resolve package aliases, dynamic imports, or bundler transformations.

Supported non-JS/TS text files receive credential-pattern checks only. Generated and dependency folders, lockfiles, symbolic links, unsupported formats, and oversized files are skipped. This first audit reads the current commit, not Git history.

Choose access on GitHub.

The Aster Code Audit App requests Contents: read and Metadata: read. It has no write permissions and cannot merge changes. Only repositories shared with the App and accessible to your account appear.

Source is processed in memory.

The audit server reads selected files without saving a source archive, installing dependencies, or executing repository code. Source audits do not send code to an AI model. AI-assisted fixes use your selected provider in a separate review workflow.

Your session has an expiry.

The GitHub access token is encrypted in an HttpOnly cookie for up to eight hours. Hosted HTTPS sessions use Secure cookies. The token is not exposed in browser JavaScript or localStorage.

The report is yours to save.

Your profile and latest free report are saved to your account. Profile details and reports are encrypted at rest. Sign out to end access from this browser; signing out does not delete the saved report. Download a copy whenever you need it. Pro includes 30-day history, and Team includes 90-day history. Downloads contain repository and file names, commit details, findings, and scan limits; treat them as project information.

Leave whenever you need.

Sign out to clear the browser session. Revoke or uninstall the App in GitHub settings to remove its authorization. A Stop audit button cancels the active request.

Analytics has a boundary, too.

Hosted marketing pages use Vercel Web Analytics. Signup and all dashboard pages are excluded. Repository source, findings, and report downloads are not submitted as analytics events.

UNDERSTAND YOUR AUDIT’S SCOPE

A second look.
Not the last word.

A scan with no matches is not a security clearance. High-impact systems still need review appropriate to their risks.

YOUR NEXT STEP

Ready for a closer look?

Choose the repository. Review what comes back.

Connect GitHub