Salt Code gives your AI coding assistant deep security expertise from OWASP to MCP security to LLM risks. Out of the box. Secure code from the first prompt. No workflow changes.
Your AI assistant already writes most of your code. Salt Code makes sure it writes secure code, catching OWASP violations, bad auth patterns, and insecure API designs before they ever reach a PR review.
Connect Salt Code to your code review agents and every pull request gets checked against your security policies before it merges. No manual reviews, no scanner backlogs. The coding agent knows the rules, the pipeline agent enforces them, and your team ships faster.
Break down silos by pushing security policies directly into the developer's coding agent and DevSecOps code review agent. No more back-and-forth. No more rework. Security enforced wherever AI interacts with code.
Fill out the form below. Your personal access token arrives by email. It is your key to connecting Salt Code to any AI coding assistant.
Configure your assistant to connect to Salt Code MCP. Works with Cursor, Claude Code, VS Code, Windsurf, Kiro, and many more. Setup in under 60 seconds.
From your next prompt, Salt Code enforces 40 security policies in real time. API security, agentic security, LLM security, and OpenAPI compliance.
60 seconds. Your personal access token arrives by email, paste it once and Salt Code enforces security on every prompt from that moment on.
Turn on the packs that match what you're building. OWASP standards for APIs. New security standards for MCP integrations and LLM systems. OpenAPI correctness for API contracts. Your AI now knows all of it.
Broken auth, excessive data exposure, security misconfiguration, the 10 most common API vulnerabilities. Your AI now knows how to avoid all of them.
MCP integrations are a new attack surface with almost no tooling around them. This pack exists because nothing else does this yet.
Prompt injection, insecure output handling, excessive agency, your AI understands these risks and avoids them when building LLM-powered systems.
Auth schemes, schema definitions, versioning, response structure, your API contracts correct from the first draft, not the last bitter run.
I just stopped thinking about it. Salt Code runs, my Cursor generates compliant code, I ship. I haven seen a dramatic decreas in security kickbacks from our pipeline.
SAST noise dropped significantly. Not because we changed our scanner, because the stuff it was finding just stopped being written. Problems never made it into the codebase.
We're vibe coding a lot of internal tooling with Copilot. Salt Code means the security team stopped asking us to slow down. Compliant by default is a way better conversation.
Actually free. No credit card. All four packs, all 40 policies, every supported editor. We want developers, AppSec, and DevSecOps teams to use it. If you want more features, try the full Salt Security Platform.
No. Salt Code is a remote MCP server that provides security policy context to your AI assistant. Your code never leaves your machine or your AI provider's infrastructure. Salt only sees the MCP tool calls, not your code.
No noticeable impact. Salt Code is a lightweight remote MCP server. Your AI assistant calls it when it needs security context, not on every keystroke. Most developers report zero change to their workflow speed.
Nothing happens after the fact, because there is no after the fact. Your coding assistant knows what secure code looks like before it writes a single line. It understands OWASP, MCP security, LLM risks, and OpenAPI compliance the same way a senior security engineer does. The result is secure code from prompt to generation. No scanning. No flagging. No rework. Just code that was right the first time.
Custom policies are available on the enterprise plan. You can bring your own corporate security standards into Salt Code and enforce them across every AI coding assistant in your organization. Contact us to learn more →
No. Salt Code is a standalone free product. You don't need a Salt Security account, contract, or existing relationship. Sign up above and you're done.
No. Salt Code is built for developers, AppSec, and DevSecOps teams. Developers get secure code out of the gate without changing how they work. AppSec teams get true shift left, pushing security policies directly into the coding agent where code is actually written, breaking down silos and eliminating back-and-forth. DevSecOps teams see fewer SAST and DAST findings because the vulnerabilities stop being written before they ever reach the pipeline. Everyone wins.
Salt Code for the Enterprise is part of the Salt Security Agentic Security Platform, built for organizations that need broader coverage, custom policies, and enterprise-grade identity controls.