free to use - 16 coding agents - 60 sec install

Secure code.
Every time.

Salt Code gives your AI coding assistant deep security expertise from OWASP to MCP security to LLM risks. Out of the box. Secure code from the first prompt. No workflow changes.

Your Coding Agent: Cursor
Design me a "delete user API" for an MCP
tool, where userid and auth token in query string
Checking against Salt Code policies...
// Security Issues Found
OWASP API1, Could result in BOLA vulnerability
OWASP API2, Auth token in query string.
OWASP API3, User ID in query string leaks PII.
MCP, Tool inputs must be validated.
// Your request violates security policies. Instead let's do this:
Bearer token in Authorization header
User ID in request body with authz check
Secure MCP tool definition generated.
// Works with the coding assistants you already use
Claude Code Cursor VS Code Copilot CLI Windsurf Kiro Codex Gemini CLI Antigravity OpenCode JetBrains Grok Lovable Cline Bolt Any MCP Client
// Who it's for

Used by developers, AppSec, and DevSecOps.
Loved by all.

Developer

Code securely out of the gate. Never hear from security again.

Your AI assistant already writes most of your code. Salt Code makes sure it writes secure code, catching OWASP violations, bad auth patterns, and insecure API designs before they ever reach a PR review.

No workflow changes, works inside your existing editor and CLI tools
Security issues caught at prompt time, not code review time
Ship faster, fewer security-related rework cycles, less noice from the pipeline
DevSecOps

Every PR. Every pipeline agent. Every policy. Automatically.

Connect Salt Code to your code review agents and every pull request gets checked against your security policies before it merges. No manual reviews, no scanner backlogs. The coding agent knows the rules, the pipeline agent enforces them, and your team ships faster.

Connect to code review agents in your existing pipeline
Every PR automatically checked against 40 security policies
Fewer SAST findings with issues caught before they're written or merged
AppSec

True shift left. Push your policies to the developer desktop.

Break down silos by pushing security policies directly into the developer's coding agent and DevSecOps code review agent. No more back-and-forth. No more rework. Security enforced wherever AI interacts with code.

40 OWASP, MCP, LLM, and OpenAPI policies enforced by default
Enterprise: bring your own corporate policies into every agent
Developers stay in flow, security happens without the friction
// How it works

Three steps to security superpowers.

Step 1 of 3

Get your free token

Fill out the form below. Your personal access token arrives by email. It is your key to connecting Salt Code to any AI coding assistant.

Step 2 of 3

Connect your assistant

Configure your assistant to connect to Salt Code MCP. Works with Cursor, Claude Code, VS Code, Windsurf, Kiro, and many more. Setup in under 60 seconds.

Step 3 of 3

Start coding securely

From your next prompt, Salt Code enforces 40 security policies in real time. API security, agentic security, LLM security, and OpenAPI compliance.

Get your
free token.

60 seconds. Your personal access token arrives by email, paste it once and Salt Code enforces security on every prompt from that moment on.

40 security policies active from your first prompt, API, agentic, LLM, and OpenAPI compliance
Works with 16+ assistants, Cursor, Claude Code, VS Code, Windsurf, and more
No workflow changes, configure once, runs silently on every coding session
Free to use, no credit card, no trial period, no catch
Get your free token
Paste it into your editor config. Your AI writes secure code from the next prompt. Takes 60 seconds.
free to use · no credit card · 40 policies active
// What you get

40 policies.
Four packs. All free.

Turn on the packs that match what you're building. OWASP standards for APIs. New security standards for MCP integrations and LLM systems. OpenAPI correctness for API contracts. Your AI now knows all of it.

01 / OWASP

API Security Top 10

Broken auth, excessive data exposure, security misconfiguration, the 10 most common API vulnerabilities. Your AI now knows how to avoid all of them.

» 10 policies
02 / MCP

MCP Security Top 10

MCP integrations are a new attack surface with almost no tooling around them. This pack exists because nothing else does this yet.

» 10 policies
03 / LLM

LLM Security Top 10

Prompt injection, insecure output handling, excessive agency, your AI understands these risks and avoids them when building LLM-powered systems.

» 10 policies
04 / SPEC

OpenAPI Compliance

Auth schemes, schema definitions, versioning, response structure, your API contracts correct from the first draft, not the last bitter run.

» 10+ policies
// From people that have used Salt Code

Things people
actually said.

AJ
Alex J.
senior backend eng

I just stopped thinking about it. Salt Code runs, my Cursor generates compliant code, I ship. I haven seen a dramatic decreas in security kickbacks from our pipeline.

July 2026
SR
Sofia R.
partner eng

SAST noise dropped significantly. Not because we changed our scanner, because the stuff it was finding just stopped being written. Problems never made it into the codebase.

July 2026
MK
Marcus K.
lead developer

We're vibe coding a lot of internal tooling with Copilot. Salt Code means the security team stopped asking us to slow down. Compliant by default is a way better conversation.

July 2026
// FAQ

Things people
actually ask.

Actually free. No credit card. All four packs, all 40 policies, every supported editor. We want developers, AppSec, and DevSecOps teams to use it. If you want more features, try the full Salt Security Platform.