Gomes Security · Fix engine

Try it on your own scan.

Checked. Cited. Fixes drafted. Nothing applied without your approval.

In your browser · your file stays here · OWASP Top 10:2021

Drop a scanner export and the fix engine's own parsers read it here, in your browser. Every finding is mapped to its OWASP Top 10 category, given the fix the engine can draft, and named the fix technique the engine has validated for its weakness class.

Your file is not uploaded. The page reads it here, in your browser. After it runs, the page sends us one short line: which scanner made the file, how many findings it had, and how many the engine could draft for. Nothing else — not the file, not a finding, not your name. You can watch that one request in your browser's developer tools.

Accepted: Trivy JSON · Grype JSON · ZAP JSON/XML · SARIF JSON · Snyk JSON · OSV-Scanner JSON · Nuclei JSON/JSONL · Burp XML · Qualys XML · Nessus XML. Files up to 25 MB and 20,000 findings.

This page ships with a Content-Security-Policy that allows exactly one network destination: our run counter. Your file stays on your machine.

Network requests since your file was read: 0 — the one allowed is the run-count line.

Real Trivy 0.72.0 scan of nginx:1.19.10 (nginx@sha256:df13abe416e37eb3db4722840dd479b00ba193ac6606e7902331dcea50f4f1f2) on 2026-09-15T17:47:02.380026577Z. Reproduce: docker run --rm aquasec/trivy:0.72.0 image --format json --output nginx-1.19.10.trivy.json nginx:1.19.10 Fields the page does not read (descriptions, references, CVSS vectors, timestamps) were removed to fit the page; every remaining value is the scanner's own, unchanged. The untouched report is identified by originalSha256.

Get the full report

For the full engine run — cited fix steps for every finding, precedent data and a recorded validation — we run it for you. Ask, and we send a private, single-use report link.

Opens your email app. The request carries only the counts above, never your findings.