Hullproof Free
Security Standard & Pre Launch Gate for AI Assisted Builds
Ship AI assisted builds with evidence, not hope.
Hullproof is a secure software development standard for teams that build with AI coding agents. The free edition is a kit you copy into your own project. It tells your coding agent the security rules, then checks a release against those rules and records the evidence a person needs to decide whether to ship.
- Interface
- Claude Code Skill, Agent and Hook
- Primary Use
- Pre Launch Security Review
- Agent Environments
- Claude Code
How It Works
The Problem
AI coding agents write working software quickly, and that includes the parts that decide who can read your data. Authentication, authorization, secrets, database access and payments can all look finished while still being open to anyone.
Most builders have no written standard to test against, and a security review done by the same agent that wrote the code is not an independent check. The risk grows with every feature shipped faster than it can be reviewed.
Product Thesis
A security standard for AI assisted work has to do two jobs. It has to tell the coding agent what the rules are while the code is being written, and it has to give a person a way to test the finished release against the same rules.
Every requirement therefore carries an ID such as SEC-AUTH-002, a severity, a way to check it, and the evidence to keep. A result needs evidence. An agent saying the code looks fine is not a result.
What the Free Edition Contains
The free edition holds 110 requirements, which is every BLOCKER (44 of them) and every CRITICAL requirement, backed by 154 cited sources. It sits alongside a Production Security Gate and a release checklist of 110 items.
The kit includes agent instructions, a master standard, domain standards covering areas such as authentication, API, database, secrets, AI security and mobile, a short checklist a solo builder can run alone, a pre launch skill, a read only auditor agent, scoped rules that load only when the agent edits matching files, Semgrep and Gitleaks configuration, and templates for the audit report, accepted risk, threat model and breach runbook.
Safety Model
The auditor is read only by design. A hook blocks shell commands outside a short read only list while the agent runs, so the audit cannot change the project it is checking.
Every checklist item ends in one of four results: PASS, FAIL, NOT APPLICABLE or NOT ASSESSED. A NOT ASSESSED item always names the route to settle it, such as a provider dashboard export, a production build, a dynamic test or a written statement from the owner.
Honest Verdicts
A coding agent that only reads a repository cannot reach READY alone, because many BLOCKER requirements are settled by evidence that lives outside the code. The kit says so, and the first run on a real project is expected to end NOT READY. That is the checklist working.
The READY label is also scoped. READY (FREE SCOPE) says nothing about HIGH, MEDIUM or LOW requirements, and the label states that.
Sample Audit
The repository includes a sample audit report produced by running the free audit on a deliberately vulnerable demo app, built with planted flaws for this purpose. Builders can run their own audit on the demo first, then compare results with the answer key. The demo is intentionally insecure and is never meant to be deployed.
Hullproof Pro
Hullproof Pro is the paid edition. It holds 655 requirements and uses the same requirement IDs as the free edition. It is not on sale yet and will be hosted on its own landing page, separate from this site.
To hear when it launches, join the waitlist using the button below.
Licensing
Code in the kit is licensed under Apache 2.0, and the documentation is licensed under CC BY-SA 4.0. The repository includes a licensing guide that says which license covers which path, and the install steps keep the license files with the copied kit.
My Role
- Concept
- Security Requirement Model
- Severity and Release Gate Design
- Agent Workflow Design
- Skill, Agent and Hook Design
- Scanner Rule Configuration
- Audit and Evidence Templates
- Documentation and Licensing
- Open-Source Release
Product Experience
Illustrations created for this case study. They show how the standard works and are not product screenshots.


