Legit Security
Legit Security is an AI-native Application Security Posture Management (ASPM) platform that gives security and engineering teams a unified view of everything being built across the software factory — source code management, CI/CD pipelines, artifact registries, cloud platforms and AI coding assistants — then discovers, correlates, prioritizes and helps remediate application security findings from that one place. The platform spans code security (SAST and SCA), enterprise secrets detection and prevention, software supply chain security, advanced code change management, and continuous compliance and SBOM. Legit also ships an agent-facing surface: the Legit MCP Server, which delivers security intelligence into AI code assistants such as Cursor, GitHub Copilot, Claude Code and Windsurf, and VibeGuard / AI Guard, a Claude Code plugin that blocks secrets leakage, prompt injection, hidden characters and disallowed MCP tools in real time. The company also maintains the open source legitify scanner for GitHub and GitLab misconfiguration detection. Legit Security integrates with more than 100 AppSec, SCM, CI, registry, cloud, identity and ticketing tools, including outbound webhook notifications for custom integrations. Backed by Bessemer Venture Partners and CRV.
Legit Security is profiled on the APIs.io network. Tagged areas include Company, Cybersecurity, Application Security, ASPM, and DevSecOps.
The Legit Security catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Legit Security’s developer surface includes engineering blog, support, CLI, changelog, and 17 more developer resources.
Kin Score
MCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
legit-security-mcp.yml
MCP SERVEREvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Legit Security Webhooks
ASYNCAPISecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 2
Portal, sign-up, and the first successful call
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 1
Pagination, idempotency, versioning, errors, and events
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 2
Properties that don't map to a standard resource type