HOW ARKO RUNS

One engine. Everywhere your code is written.

One engine. Everywhere your code is written.

However your team ships — hand-written, AI-assisted or agent-generated — ARKO runs the same DevSecOps engine at the point the code appears, and rolls every finding into one control plane.

However your team ships — hand-written, AI-assisted or agent-generated — ARKO runs the same DevSecOps engine at the point the code appears, and rolls every finding into one control plane.

In your IDE

In your IDE

VS Code, Cursor, Windsurf and VSCodium. Findings and one-click fixes appear inline as you type — no separate scan step. Free, forever.

VS Code, Cursor, Windsurf and VSCodium. Findings and one-click fixes appear inline as you type — no separate scan step. Free, forever.

Inside your AI agents — via MCP

Inside your AI agents — via MCP

Claude Code, Cursor, Kiro and any MCP-compatible agent. One line — claude mcp add arko — and the agent scans the code it writes, validates each fix, and will not close out a task while a real risk is still open.

Claude Code, Cursor, Kiro and any MCP-compatible agent. One line — claude mcp add arko — and the agent scans the code it writes, validates each fix, and will not close out a task while a real risk is still open.

In your terminal & CI

In your terminal & CI

One command gates the files your team (and their agents) just changed and fails the build on real findings. Fail-open on your machine so it never blocks you; fail-closed in CI with --strict. Organisation-wide CI policy and roll-up come with Enterprise.

One command gates the files your team (and their agents) just changed and fails the build on real findings. Fail-open on your machine so it never blocks you; fail-closed in CI with --strict. Organisation-wide CI policy and roll-up come with Enterprise.

Across your repositories

Across your repositories

Dependency and supply-chain scans with an SBOM for every build — the risky packages behind AI-suggested imports, caught before they ship.

Dependency and supply-chain scans with an SBOM for every build — the risky packages behind AI-suggested imports, caught before they ship.

Every scan lands in one place.

Every scan lands in one place.

Wherever a scan runs, it is tagged by source — agent, IDE, terminal or CI — and rolls up to your Code Health Score and the CISO Control Plane, with auditable evidence.

Wherever a scan runs, it is tagged by source — agent, IDE, terminal or CI — and rolls up to your Code Health Score: one score across security, maintainability, cost and architectural drift.

Developers sign in once with their work email and every scan routes to your organisation’s control plane automatically — same findings, same audit trail, no per-developer setup.

Developers sign in once with their work email and every scan routes to your organisation’s control plane automatically — same findings, same audit trail, no per-developer setup.

Frequently asked questions

Frequently asked questions

What is Arko?

Arko is a security engine for AI-era development, built by DevSecAI. It scans code in real time as it is written — in VS Code, Cursor, Windsurf and AI agents via MCP — validates fixes, and rolls every finding into an auditable control plane for CISOs.

Is Arko a code scanner?

Yes — and more. The free Arko plugin runs four scanning categories (SAST, secrets, dependencies and IaC misconfigurations) as you type, with AI validation to cut false positives. Unlike a traditional scanner, Arko also validates the fix before you ship it.

Is Arko free?

The Arko IDE plugin is free for developers, forever. Enterprise teams add the Arko Control Plane — organisation-wide policy, control coverage and auditable evidence — on a paid licence.

How is Arko different from traditional SAST tools?

Traditional SAST runs in CI, after the code is written, and buries teams in unvalidated findings. Arko runs at the point the code appears — IDE, AI agent, terminal or CI — validates each finding with a second pass, and will not let an AI agent close a task while a real risk is still open.

Does Arko work with AI coding agents like Claude Code and Cursor?

Yes. One line — claude mcp add arko — connects Arko to Claude Code, Cursor, Kiro or any MCP-compatible agent. The agent scans the code it writes and validates each fix before finishing.

What does Arko mean for DevSecOps?

Arko is the DevSecOps control layer for AI-accelerated development: one engine wherever code is written, and one auditable system of record for CISOs, mapped to frameworks such as PCI DSS, SOC 2 and OWASP.

>