free to use · all coding agents · 60 sec install

Secure code.
Every prompt.

Coding agents are great at functionality and syntax, but security is a different discipline. Salt Code gives your coding agent security expertise across APIs, MCP, LLM systems, and OpenAPI specs. Out of the box, no workflow changes required.

Your Coding Agent: Cursor
Design me a "delete user API" for an MCP tool, where userid and auth token in query string
Checking against Salt Code policies...
// Security Issues Found
OWASP API1, Could result in BOLA vulnerability
OWASP API2, Auth token in query string.
OWASP API3, User ID in query string leaks PII.
MCP, Tool inputs must be validated.
// Your request violates policies. Let's do this instead:
Bearer token in Authorization header
User ID in request body with authz check
Secure MCP tool definition generated.

Coding assistants
focus on functionality,
not application security.

The gap between functional code and secure code is bigger than you think, and it grows with every AI-generated commit.

// Coding Agent Reality
99.9%

Of AI-generated code is syntactically correct

44%

Of completed coding tasks introduce a security flaw

90%

Of vibe-coded apps contain major vulnerabilities, averaging 7 per application

Sources: Veracode, 2026 GenAI Code Security Report; Deng, Fan & Meng, Understanding the (In)Security of Vibe-Coded Applications, 2026.

40 policies · all free · active instantly

One install.
Instant expertise.

Add Salt Code once and your coding agent immediately becomes a security expert across API, MCP, LLM, and OpenAPI standards. No configuration. Active from your very next prompt.

API
API Security Top 10
Your AI avoids the 10 most common API vulnerabilities automatically.
MCP
MCP Security Top 10
Your AI builds MCP integrations safely. It's a new attack surface most tools ignore.
LLM
LLM Security Top 10
Prompt injection, insecure output handling, excessive agency. Your AI knows to avoid all of it.
SPEC
OpenAPI Compliance
Correct API contracts from the first draft, not the last bitter run.
developers · devsecops · appsec

Built for every team
that ships code.
Loved by all.

Whether you're writing code, reviewing PRs, or owning AppSec policy. Salt Code works where you already work.

Developer
Code securely out of the gate. Never hear from security again.
Security issues caught at prompt time, not code review time. No workflow changes required.
DevSecOps
Every PR. Every pipeline agent. Every policy. Automatically.
Every pull request checked against 40 security policies before it merges. Fewer SAST findings, no scanner backlogs.
AppSec
True shift left. Push your policies to the developer desktop.
40 OWASP, MCP, LLM, and OpenAPI policies enforced by default. Bring your own corporate policies too.
Give security expertise to the coding agents you already use.
Claude Code Cursor VS Code Copilot CLI Windsurf Kiro Codex Gemini CLI Antigravity OpenCode JetBrains Grok Lovable Cline Bolt Any MCP Client
Frequently asked questions

No catch. No credit card. All 40 policies, every supported coding agent. Free forever for individual use.

No. Salt Code injects security context into your agent's context window. Your code never leaves your machine.

No noticeable impact. Policy injection happens in the background with negligible latency.

Salt Code's purpose is to prevent insecure code from being generated in the first place. It injects security context directly into your agent's context window, so the code it writes is secure from the start — not flagged after the fact. Your coding agent can also reference Salt Code policies to review and fix existing code, making it useful for security hardening of code already written.

Yes, on the enterprise plan. Bring your own policy packs and push them to every developer's coding agent across your org.

No. Salt Code is a standalone free product. No existing account or contract needed.

No. DevSecOps teams use it in pipeline agents. AppSec teams use it to push their policies to the developer desktop.

Custom policy packs, org-wide management, prompt-time security reporting, SSO/SCIM, and dedicated support.