Inspiration
AI security tools are everywhere now, but almost all of them are closed, cloud-only services — you hand over your source code and your findings, and they leave your control. For privacy-conscious teams that's a dealbreaker. I wanted the opposite: an open, self-hosted security assistant that reviews your code, explains what it finds and how to fix it, and keeps everything inside your own environment.
What it does
Helios is a self-hosted, agentic security review platform. You point it at a public web target or a GitHub repository, and a team of AI agents takes over: it profiles the target, runs the relevant open-source analysis tools, interprets the raw output with a local LLM, reasons about how the findings relate to one another, and produces a clean report with a concrete fix attached to every finding — all streamed live. Because it runs on infrastructure you control, your code never leaves your machine.
How I built it
A Next.js frontend (deployed on Vercel) for the live UI, a FastAPI + LangGraph backend (deployed on Render in Docker) for the agent pipeline, and an OpenAI-compatible model layer so the intelligence is swappable — I ran DeepSeek on Exea Labs' AMD GPUs for the hosted demo, and it also runs fully local with Ollama. Progress streams to the browser over SSE, with automatic fallback to polling if the connection drops.
Challenges I ran into
Deploying a heavy, tool-dependent backend on free-tier hosting was the real fight: cold starts, health-check misconfigurations, a serverless-proxy timeout that couldn't handle long live streams, and memory limits on the biggest analysis step. I solved the streaming problem by having the browser talk to the backend directly with CORS instead of proxying, and worked within the memory ceiling for the demo.
Accomplishments that I'm proud of
A full working pipeline, live and shareable, built and deployed solo in a day — and a model that gives calibrated, honest output. When it can't confirm something, it says "unknown" instead of inventing a vulnerability, which is exactly the behavior you want from a security tool.
What I learned
How to orchestrate a multi-agent pipeline with LangGraph, how to keep an LLM honest with confidence-calibrated prompting, and a lot about the real-world gap between "it works locally" and "it's deployed and reachable."
What's next for Helios
A one-command self-hosted deploy, a CI/PR integration so it runs before you ship, and a purpose-trained model for the interpretation step. The bigger vision: the open, self-hosted layer underneath a compliance platform — continuous security evidence without your code ever leaving your environment.
Built With
- amd
- bandit
- deepseek
- docker
- fastapi
- framer-motion
- langchain
- langgraph
- next.js
- nmap
- ollama
- python
- react
- render
- semgrep
- sqlmap
- sse
- tailwindcss
- trufflehog
- typescript
- vercel
Log in or sign up for Devpost to join the conversation.