Inspiration

We've lived it: staring at a pile of code to review, knowing some of it could hide a critical bug, and not knowing where to start. Now AI coding agents ship code in hours, and security review can't keep up. Veracode's 2026 report found that nearly half of AI-generated code still fails security tests. Small teams don't have a security department. They have a few busy developers and a growing backlog of unchecked code. We wanted to build the extra set of hands those teams can't afford to hire.

What it does

Tourniquet is an AI security reviewer for fast-shipping teams. It reviews every code change with two AI agents that work against each other:

  • The Paranoid reads the code like an attacker and flags every possible vulnerability, because missing a real one costs far more than checking a harmless one.
  • The Skeptic tries to disprove each finding by checking whether the code is reachable, whether the input is validated elsewhere, and what data would be exposed.

The result is one short, ranked summary (for example, "3 critical, 8 medium, 41 low") with a plain-language explanation and fix plan for each issue. Nothing is hidden, but developers know where to look first.

For critical findings, Tourniquet can also act like a tourniquet. It checks what would break if the risky function were switched off, then asks a human to approve a temporary guard (Watch, Restrict or Block). The guard contains the problem while the team works on the real fix, and it can be rolled back instantly and removes itself once the fix ships. A dashboard connects to a team's repositories and shows their security health, active guards and pending approvals.

Tourniquet never fixes code on its own and never declares code "safe." It alerts, a human decides, and the real repair stays with the developers.

Challenges we ran into

  • How to ensure that Tourniquet doesn't miss anything, and how to rely on the trustworthiness of its scans
  • How to let an AI contain a threat without risking a wrong call that breaks the app. Our answer was human approval on every guard, a preview of the impact, and instant rollback.
  • How to keep a "paranoid" scanner from flooding developers with alerts. The Skeptic and the ranking exist to solve this.

What's next for Tourniquet

  • Creating the software, starting with a GitHub app that scans pull requests and posts the ranked summary
  • Training a model exclusive to scanning security breaches and patching
  • Getting cybersecurity-certificate-accurate results with Tourniquet
  • Embellishing the business plan: a free tier for solo developers, paid tiers for teams and growing SaaS companies, and enterprise features like audit trails, self-hosting and compliance reports

Built With

Share this project:

Updates

Submission history