The full security engine running locally on your machine. Scan internal networks, GitHub repos, and on-prem services that the cloud scanner can't reach. Download and run in under 60 seconds. Free.
No install, no account. The free scanner checks TLS, security headers, exposed files, DNS/email auth, and more — instantly.
🌐 Run the free scan now — no installThe web scanner checks your site from the outside. To scan the machine itself — running processes, persistence (LaunchAgents/Daemons), browser forensics, malware signatures (ClamAV/YARA), boot-volume integrity — you need the local desktop app. It runs 100% on your device; nothing leaves your machine.
brew install yara clamav for signature scanning.The web scanner sees public-internet endpoints. The desktop app sees your private network, your authenticated apps, and the code on your laptop. Same engine — wider field of view.
Log into the apps you actually run — Slack, GitHub, Google Workspace, Okta — and let Crucible Security inspect what only an authenticated user can see.
Scan RFC1918 ranges, on-prem services, and dev/staging environments behind your VPN. Findings stay local, hashes upload to Forensics.
Point the app at any local checkout for full code-quality analysis — secrets, dead links, broken imports, missing CSP headers in shipped builds.
No round-trip to our servers. Scans complete in seconds, not minutes. Results sync to your Auto-Response dashboard so the team sees them too.
Drop honeypots and canary tokens onto your own machines — the desktop app handles the install, registration, and live monitoring end-to-end.
Generate signed PDF + JSON reports without an internet connection. Pass to auditors, regulators, or insurance brokers as-is.
Builds are signed with the CRUCiBLE CAPiTAL SYSTEMS LLC Apple Developer ID and an EV code-signing certificate on Windows. SHA-256 hashes published at releases page for verification.
We email you the moment macOS, Windows, and Linux builds are signed and posted. No marketing blasts in between.