The verified audit

Every finding scanner-grounded and adversarially verified

Granska found a live GCP admin key in a real audit — and every high-severity finding it reports has already survived an agent trying to refute it. One command turns any target into a report you can trust for remediation and compliance evidence.

claude plugin install granska@granska

How it works

  1. 01

    Ground truth

    A real scanner battery (semgrep, gitleaks, trivy, osv-scanner and more) runs first — deterministic findings, not hallucinated ones.

  2. 02

    Multi-lane review

    Independent LLM review lanes hunt what scanners miss, each constrained to a schema-validated output.

  3. 03

    Adversarial verify

    Every high-severity finding survives an agent actively trying to refute it before it's reported.

  4. 04

    Evidence

    What ships is mapped to OWASP, CWE, SOC 2, NIST, ISO and GDPR — trustworthy enough for remediation and compliance evidence.

Open-core, honest pricing

The full detection, verification and fixing pipeline is free and open — Apache-2.0, run it locally or in CI, no paywalled findings. Paid tiers unlock evidence packs, attestation badges, and engagements.

View pricing