What we publish, what we sponsor, who we work with.
Sebastion AI is free for public repos. We sponsor a handful of OSS projects we depend on, and we publish security findings upstream wherever the maintainers will have us.
Where Sebastion is shipping.
Merged pull requests from Sebastion, our OSS code reviewer, joined with the issues it has identified in those repos.
Sebastion AI is free on public repos. Forever.
Install Sebastion on any public GitHub repository and get inline security review on every PR at no cost. We do this because we'd rather catch the next Log4Shell early than add another signup wall.
- 50 audits per repo per month, no credit card.
- CWE-tagged findings + OSV.dev cross-checks.
- Powered by a fast frontier model.
Bugs we find. Patches we ship.
When Sebastion finds a vulnerability in an open-source dependency, we report it upstream through coordinated disclosure. Patches are submitted under our individual names where the project allows it; CVE credit lands on the reporter, not on Foundation Machines.
See our published research at /cves.