Netherite
Netherite is a code security scanner that identifies exploitable vulnerabilities in repositories and code snippets, then generates fix prompts ready for coding agents. It connects to GitHub repositories via OAuth, performs triage-level and deep-review scans, and produces findings with file-line references and exploit-chain analysis. The tool includes a security advisor chat for answering design questions and supports private repository scanning with encrypted connections and no code retention. Developers paste fix prompts directly into Claude Code or Cursor; project managers export structured vulnerability reports for client deliverables or internal documentation.
Netherite is a code security scanner, priced at $10 a month on the Basic plan, integrating with GitHub, Claude Code and Cursor. InnovaAI rates it 4.8 of 10 for agency adoption, best for Developer, Project Manager and Founder roles.
Agency Audit
Netherite scans repositories and code snippets to identify exploitable vulnerabilities, then generates fix prompts ready for coding agents like Claude Code and Cursor. Development agencies shipping AI-generated code, teams offering security assessments as a deliverable, or small shops without dedicated security staff benefit most. The tool integrates with GitHub and produces structured reports with file-line references and exploit-chain analysis, compressing security review from manual code inspection into automated triage and agent-ready remediation.
5recommended
20/mo
$1,490/mo
Low
Illustrative scenario. Not a guarantee. Net capacity is the value of reclaimed time at $75/hr, less the lowest verified paid base plan (flat plan cost is shared). Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.
- Developer handling pre-merge security review
- Project Manager handling AI-generated code remediation
- Founder handling client security-assessment deliverables
- Your codebase is primarily legacy or non-AI-generated code with infrequent deployments. The scanning limits on lower-tier plans (10-30 repository scans per month) may not justify seat cost if you scan fewer than twice per week.
- Your team already employs a full-time security engineer or contracts with a dedicated AppSec firm. Netherite duplicates that expertise and adds no operational lift.
- Your repositories are closed-source and you cannot grant Netherite GitHub access due to compliance or policy constraints. The tool requires direct repository connection or code-snippet upload; there is no air-gapped scanning mode.
Internal Adoption Path
$10/mo
$10/mo flat plan
20 hr/mo
5 seats × 4 hr each
$1,500/mo
modeled at $75/hr labor rate
$1,490/mo
value − subscription cost
In this model, 5 seats reclaim 20 hours of team time each month. Valued at $75/hr that is $1,500/mo, and after the $10/mo subscription it leaves $1,490/mo of capacity for billable client work.
Illustrative scenario. Not a guarantee. Uses the lowest verified paid base plan. Implementation, taxes, and unprovided usage charges are excluded.
Platform Features
Core capabilities of Netherite
Repository scanning with file-line triage
Connects to GitHub repositories and identifies exploitable vulnerabilities with exact file and line references. Developers and project managers use this to prioritize remediation without manual code inspection.
Agent-ready fix prompts
Generates scoped prompts for Claude Code and Cursor that include constraints and file context. Developers paste prompts directly into their agent instead of manually translating findings into remediation steps.
Exploit-chain analysis
Confirms whether vulnerabilities are actually exploitable by modeling realistic attack paths. Reduces false-positive triage burden for teams shipping to production.
Structured, exportable vulnerability reports
Produces machine-readable reports with severity triage and remediation guidance. Project managers and account executives use these to document client deliverables or internal audit trails.
Code-snippet analysis
Accepts isolated code snippets for stack-specific misconfiguration checks without requiring full repository access. Useful for reviewing third-party libraries or client-submitted code samples.
Security advisor chat
Answers security questions via conversational interface without requiring external review. Junior developers use this to unblock themselves on security design decisions.
What Makes Netherite Different
Unique advantages vs similar tools in this niche
Stack-specific scanning for Supabase and Next.js misconfigurations
vs Generic OWASP scanners like Snyk or SonarQubeChecks for missing RLS policies, exposed keys, and insecure auth flows specific to modern AI-assisted app stacks.
Agent-native fix prompts scoped to one file
vs Manual remediation from raw vulnerability reportsFormats fixes as prompts ready to hand to Claude Code, Cursor, or other coding agents, with constraints already stated.
Chat advisor grounded in real vulnerability analysis
vs Static documentation or generic security adviceAllows developers to ask questions and paste code to get straight answers based on actual analysis, not vague generalities.
Value Equation
Outcome-likelihood-time-effort assessment for Netherite
Limited agency channel
Netherite scored below the agency-resellability threshold (agency_fit_score < 50). The Value Equation projects agency-side outcomes, which don't apply to tools without a clear resell pathway.
Contact NetheritePricing
Netherite platform cost to your agency
Starts at $10/mo (Basic), scales to $119/mo (Max)
Basic
- 600 advisor messages / month
- 100 snippet analyses / month
- 10 repository scans / month
- Findings with ready-to-use fixes
Pro
- 800 advisor messages / month
- 200 snippet analyses / month
- 30 repository scans / month
- Structured, exportable vulnerability reports
Max
- 2,500 advisor messages / month
- 500 snippet analyses / month
- 100 repository scans / month
- Structured, exportable vulnerability reports
No verified white-label program for Netherite: client-facing delivery runs under the platform's native branding.
Market Intelligence
Offer + scale economics for Netherite
Limited agency channel
Netherite scored below the agency-resellability threshold (agency_fit_score < 50). It's a useful tool but not designed for white-labeled or retainer-based reselling, so we don't publish productized offer economics for it.
Contact NetheriteInvestment Decision Framework
Strategic vetting analysis for Netherite
Situational Fit
Fit depends on your client mix
Buy If
4Your development team ships AI-generated code weekly and currently relies on manual code review to catch security gaps. Netherite reduces review time by automating vulnerability triage and generating scoped fix prompts for your coding agents.
You offer security assessments or code-audit deliverables to clients and want to standardize findings with structured, exportable reports. The tool produces exploit-chain analysis and file-line references that strengthen client-facing documentation.
Your team lacks a dedicated security engineer but maintains multiple repositories in production. Netherite's advisor chat and deep-review models let junior developers ask security questions without blocking on external review.
Your developers use Cursor or Claude Code as primary coding agents and need to close security findings without context-switching to separate tools. Fix prompts integrate directly into your agent workflow.
Skip If
4Your developers rarely use coding agents and prefer manual code writing. The tool's primary value is agent-ready fix prompts; without agent adoption, you lose the compression benefit.
Your codebase is primarily legacy or non-AI-generated code with infrequent deployments. The scanning limits on lower-tier plans (10-30 repository scans per month) may not justify seat cost if you scan fewer than twice per week.
Your team already employs a full-time security engineer or contracts with a dedicated AppSec firm. Netherite duplicates that expertise and adds no operational lift.
Your repositories are closed-source and you cannot grant Netherite GitHub access due to compliance or policy constraints. The tool requires direct repository connection or code-snippet upload; there is no air-gapped scanning mode.
Bottom Line
Netherite scans repositories and code snippets to identify exploitable vulnerabilities, then generates fix prompts ready for coding agents like Claude Code and Cursor. Development agencies shipping AI-generated code, teams offering security assessments as a deliverable, or small shops without dedicated security staff benefit most. The tool integrates with GitHub and produces structured reports with file-line references and exploit-chain analysis, compressing security review from manual code inspection into automated triage and agent-ready remediation.
Reality Check
Adoption requires developers to adopt a new scanning habit into their CI/CD or pre-commit workflow. The tool's value scales with codebase size and scan frequency; teams shipping infrequently or maintaining legacy monoliths see lower ROI per seat.
Low effort: self-service setup with guided onboarding
Academy for Netherite
Work through it in order: the course for this service first, then the modules behind it.
Course for this service
Netherite Agency Implementation, Security Audits as a Retainer Service
Learn how to deliver ongoing code security audits to clients using Netherite's repository scanning and exploit-chain analysis. This course teaches agencies how to structure retainer packages around monthly repository scans, generate client-ready vulnerability reports, and scale security advisory services without hiring dedicated security engineers.
Open the courseNo Academy modules are published for this service yet. Browse the full Academy
Why this category matters
The commercial case before the tooling.
Core concepts
The mental model you need to price and scope the work.
- Liability Ceiling FrameworkConcept
Every security retainer carries an implicit liability ceiling: the gap between what an agency promises and what an attack surface can actually guarantee. Agencies that sell "we will keep you secure" absorb unlimited downside; agencies that sell defined detection, response, and remediation scopes cap their exposure while still charging recurring fees. The framework asks three questions before signing: what specific asset is protected, what detection window is promised, and who owns the residual risk when a novel attack path emerges. Cogent's VR-1 model maps attack paths across enterprise infrastructure, which reframes the deliverable from "prevention" to "path visibility," a bounded promise. Sentrint grades repository security and generates fix prompts, giving clients a measurable artifact rather than an assurance. Vaultak monitors and rolls back AI agent actions in production, another bounded scope. California SB 813 and AB 1405, signed September 9, 2026, formalize third-party AI audit expectations, which pushes agencies toward documented, auditable scopes instead of blanket guarantees.
- Blast Radius BudgetingConcept
Blast Radius Budgeting treats security scope as a function of how much damage a single compromised asset can cause, not how many assets exist. An agency protecting a 40-person client with one shared drive has a smaller blast radius than a 12-person client whose AI agents hold production database credentials. The framework asks three questions per engagement: what can be reached from the weakest credential, how fast can it be revoked, and who eats the loss if it is not. That third question is the pricing lever. Runtime governance layers such as Vaultak intercept agent actions and roll them back automatically, which shrinks the radius and justifies a lower liability premium; frontier reasoning models like Cogent map attack paths across the same infrastructure, which expands the billable discovery phase. California SB 813 and AB 1405, signed September 9, 2026, now formalize third-party audit expectations, so documented radius estimates become client-facing evidence rather than internal notes.
- Trust Premium StackConcept
The Trust Premium Stack treats security capability as a pricing lever rather than a cost center. Each layer an agency can credibly demonstrate (device policy enforcement, code scanning, runtime agent governance, incident response) raises the ceiling on what a client will pay for the same deliverable, because the buyer is pricing risk transfer, not hours. The stack only works when every layer is evidenced: a claim without a scan report or a policy dashboard is a discount waiting to happen. Consider the governance gap now opening around AI agents. Vaultak intercepts and can roll back agent actions in production, which gives an agency a concrete artifact to show a client whose automation touches customer data. Pair that with a repository scanner such as Sentrint producing a graded report, and the retainer conversation shifts from rate card to risk coverage. The ceiling is real but finite: no layer justifies promising absolute security.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- Security Tools Rule: Price the Liability Before You Price the RetainerEvaluation Rule
Scope every security engagement as detection, evidence, and response support, and never contract for absolute protection.
- When Client AI Agents Touch Production Systems, Gate Every Action Before You ShipEvaluation Rule
Buy the enforcement layer before the detection layer whenever an agent holds write access to a client system.
- The Absolute-Security Trap: Why Security Tools Collapse Under Agency Retainer PromisesFailure Pattern
- The Scan-Only Trap: Why Security Tools Stall in Agency Delivery After the First ReportFailure Pattern
8 modules selected for Netherite
Frequently Asked Questions
Answers about pricing, setup, reliability
Netherite scans GitHub repositories or code snippets to identify exploitable vulnerabilities with file and line references. It generates fix prompts ready for coding agents like Claude Code and Cursor, performs exploit-chain analysis to confirm real risk, and produces structured vulnerability reports. The tool includes a security advisor chat for answering design questions and supports private repository scanning.
Basic plan is $10 USD per month (600 advisor messages, 100 snippet analyses, 10 repository scans). Pro plan is $35 USD per month (800 advisor messages, 200 snippet analyses, 30 repository scans, structured reports, exploit-chain analysis, private repository scanning). Max plan is $119 USD per month (2,500 advisor messages, 500 snippet analyses, 100 repository scans, direct support channel). Limits reset monthly.
Developers compress security review time by using agent-ready fix prompts instead of manual remediation. Project managers use structured reports to document security findings for client deliverables or internal audits. Founders of development agencies offering security assessments gain a standardized tool to scale that service. Operations teams reduce security review bottlenecks by automating triage and exploit confirmation.
A developer shipping AI-generated code 2-3 times per week saves approximately 3-5 hours per month on security review and fix-prompt generation. The savings scale with scan frequency and codebase size. Teams with infrequent deployments or legacy codebases see lower per-seat ROI.
No. Netherite reads your repository over an encrypted connection and deletes all code once the report is generated. Your code is not retained, logged, or used for model training or any other purpose beyond your own findings.
Netherite integrates with GitHub via OAuth or personal access token. You grant repository access during setup, and the tool scans over an encrypted connection. Private repositories are supported. You can revoke access at any time.
Fix prompts are scoped to specific files and include vulnerability context and constraints. They are designed for use with coding agents like Claude Code and Cursor, not as standalone patches. Your development team should review agent-generated fixes before merging, as with any AI-assisted code.
All scans and reports are deleted upon cancellation. Netherite does not retain historical data or backups after your account is closed. You can export reports before canceling if you need to retain audit trails.