TrustDyne is a compliance-first ASPM: continuously assess the code your AI tools write, plus your cloud, web, and, if you ship one, mobile or embedded asset. Catch hallucinated dependencies, insecure patterns, and compliance gaps before they ship, and get a Security Evidence Pack mapped to 23 frameworks, EU AI Act, SOC 2, DORA and PCI-DSS for FinTech, HIPAA and NHS DTAC for HealthTech, ISO 27001 for everyone else, in minutes, not weeks.
Enter your details and we'll scan your site for security gaps, then email you a professional PDF report — free.
Mapping vulnerability telemetry directly to global legislation
GenAI-Powered, Compliance-Native ASPM
AI coding assistants write a growing share of production code. We check it continuously so you can ship with confidence.
Import SARIF from GitHub Advanced Security, CodeQL, or Semgrep, or a Snyk export. Every ingested finding gets normalized, deduped, and mapped against the same 23 compliance frameworks as a native scan, no extra tooling required.
AI coding assistants sometimes reference packages that do not exist. We check every dependency in your SBOM against the real PyPI, npm, and crates.io registries and flag the ones that could be squatted by an attacker.
Findings map directly to EU AI Act, ISO 42001, NIST AI RMF, and SOC 2, alongside the frameworks you already track, so your evidence pack is ready for the vendor security review before it is requested.
Drop the GitHub Action or GitLab pipeline step in and every build gets scanned automatically. A structured pass or fail verdict, tied to the commit and branch, blocks a regression before it merges.
Most ASPM tools show you posture as it looks right now. TrustDyne records an immutable, timestamped entry every time a framework's status actually changes, so a buyer or auditor sees "ISO 42001: compliant since 12 June, not 3-11 June" instead of a single snapshot. It is the difference between a report and evidence.
GenAI-generated code rarely fails alone: it ships into a cloud account, gets exposed to the public internet, and gets bought by a customer who wants proof it is safe. TrustDyne covers that whole surface from one subscription and one login.
Connect AWS, Azure, or GCP and TrustDyne continuously audits posture against CIS benchmarks and the same compliance frameworks as your code, so a misconfigured bucket and a vulnerable dependency show up in the same place.
The same connected cloud account that feeds your posture scan also feeds a spend analysis, so an over-permissioned, idle, or oversized resource turns into both a security finding and a savings recommendation.
A managed public inbox lets outside researchers report real-world issues responsibly. Every report is triaged and lands in the same product-registry pipeline as your automated scans, not a separate spreadsheet.
A public, buyer-facing page shows your live compliance posture and Continuous Assurance Ledger, so a customer's security review starts with a link you control instead of a questionnaire you fill out from scratch.
Most ASPM tools stop at source code, containers, and web surfaces. If your product includes a companion mobile app, a Windows or macOS desktop client, or an embedded device, upload the build and get the same Security Evidence Pack, SBOM, prioritised vulnerabilities, AI-guided remediation, and multi-framework compliance mapping (EU CRA, UK PSTI, IEC 62443, FDA), in the same subscription, not a separate tool.
Proprietary code never leaves your boundary. Binaries are immediately and permanently purged from the isolated cloud environment after the automated audit completes.
Standard scanners go blind on embedded systems. Our proprietary engine extracts hidden OpenWrt SBOMs, analyzes Android Manifests, and identifies hardcoded shadow passwords.
Stop manually writing executive reports. We map highly technical CVEs directly to specific corporate compliance matrices, providing immediate remediation guidance.
Paste a public GitHub URL and TrustDyne runs the same SAST, secrets, and dependency-CVE pipeline your own code gets, before a third-party or open-source dependency ever touches your machine. No installation, no fork required, and no need for the repo owner's cooperation, you don't need to administer it to check it.
Paste a URL, pick a branch, done. Works on any repo you can see on github.com, whether or not you or its owner have ever installed a TrustDyne integration.
Extraction and static analysis only. Install scripts, build steps, and the repo's own code never run, so a malicious target can't compromise the scan that's checking it.
Full SBOM, prioritised CVEs, AI-generated remediation, and compliance mapping, exportable as a PDF. Every scanned repo persists as its own asset with full history, not a one-off check you forget about.
Every plan is public, right here on this page. No sales call required to see a number.
Free
£0
See what TrustDyne finds, at no cost
Starter
£99/mo
£990/yr, two months free. For your first security review
Growth
£299/mo
£2,990/yr, two months free. The full platform
Enterprise
Custom
For regulated and multi-entity businesses
Prefer to talk it through first? Email hello@trustdyne.com →
The short version of what TrustDyne is and what you get. Full detail is in the .
TrustDyne is the UK's first GenAI-powered Application Security Posture Management (ASPM) platform. It continuously audits the code your AI tools write, plus your firmware, mobile apps, desktop apps, web apps, and cloud infrastructure, and maps every finding to 23 compliance frameworks.
Six asset types from one platform: firmware and embedded binaries, mobile apps (APK/IPA), desktop applications (Windows .exe/.dll/.msi and macOS .app/.pkg/.dmg), web applications, source code (via SBOM extraction or SARIF import), and cloud infrastructure (AWS, Azure, GCP). Most ASPM tools only reach source code repositories; TrustDyne also inspects compiled firmware, mobile, and desktop binaries directly.
Two things most competitors don't do. First, asset coverage: platforms built around source-code scanning generally can't inspect compiled firmware, mobile, or desktop binaries; TrustDyne reaches all of those directly, alongside code, web, and cloud. Second, remediation is verified, not just suggested: every AI-proposed fix runs through a verify-and-retry pipeline, checked by real compilers and parsers, before it's shown to you, instead of being handed over as an unverified suggestion.
A Security Evidence Pack: a single document containing your SBOM, prioritized vulnerabilities, AI-generated remediation guidance, and a compliance pass/fail mapping against the frameworks relevant to your product, generated automatically instead of assembled by hand for each vendor security review.
Both. Every proposed fix runs through a verify-and-retry pipeline: real per-language compilers and parsers, plus a deterministic vulnerability-pattern-removal check, confirm the fix actually works before it's returned, and a failed attempt is automatically retried rather than shown to you broken.
Yes. Hallucinated Package Detection checks every dependency in your SBOM against the real PyPI, npm, and crates.io registries to catch packages an AI coding assistant referenced that don't actually exist, a documented risk known as slopsquatting. Findings are also mapped to the EU AI Act, ISO 42001, and NIST AI RMF alongside your other frameworks.
23 frameworks across software, AI, cloud, mobile, industrial, medical, and financial services, from ISO 27001 and SOC 2 to the EU AI Act, UK PSTI Act, and HIPAA. Each finding cites the specific article or clause it triggers rather than a generic framework name.
No. Under Zero-Retention Analysis, uploaded binaries and code are analyzed inside an isolated cloud environment and immediately, permanently purged once the automated audit completes.
Free is £0/month for light testing, with 5 scans a month. Starter is £99/month for your first full security review. Growth is £299/month for continuous, multi-asset scanning. Enterprise is custom-priced for multi-cloud, multi-framework organizations.
Yes, via the CI/CD Security Gate. Drop in the GitHub Action or GitLab pipeline step and every build is scanned automatically, with a structured pass/fail verdict tied to the specific commit and branch, so a regression is blocked before it merges.