# Legit Security

**Canonical:** https://apis.io/providers/legit-security/  
**Website:** https://www.legitsecurity.com/  
**APIs profiled:** 0

Legit Security is an AI-native Application Security Posture Management (ASPM) platform that gives security and engineering teams a unified view of everything being built across the software factory — source code management, CI/CD pipelines, artifact registries, cloud platforms and AI coding assistants — then discovers, correlates, prioritizes and helps remediate application security findings from that one place. The platform spans code security (SAST and SCA), enterprise secrets detection and prevention, software supply chain security, advanced code change management, and continuous compliance and SBOM. Legit also ships an agent-facing surface: the Legit MCP Server, which delivers security intelligence into AI code assistants such as Cursor, GitHub Copilot, Claude Code and Windsurf, and VibeGuard / AI Guard, a Claude Code plugin that blocks secrets leakage, prompt injection, hidden characters and disallowed MCP tools in real time. The company also maintains the open source legitify scanner for GitHub and GitLab misconfiguration detection. Legit Security integrates with more than 100 AppSec, SCM, CI, registry, cloud, identity and ticketing tools, including outbound webhook notifications for custom integrations. Backed by Bessemer Venture Partners and CRV.

## Kin Score — 32.9 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 32.9).

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 45.1 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 35.5 |
| Access Clarity | 35.5 |

## Agent readiness — 28.9 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## MCP servers (1)

- **Legit MCP Server**

## Security (2)

- **Legit Security Domain Security** — TLSv1.3 · HSTS · DMARC
- **Legit Security Trust Center** — trust center published

## Tags

Company, Cybersecurity, Application Security, ASPM, DevSecOps, Software Supply Chain Security, Secrets Detection, SAST, SCA, Compliance, AI Security, MCP

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/legit-security/). Scores are computed from the provider's own public artifacts under a published rubric.
