# Midkernel > AI-first security Attackers already use AI. We use it on defense. Midkernel is a security review you can read end to end. Connect a repository, run an open-source review workflow in an isolated sandbox, and get a report with the full trace behind every finding. Pay per run, not per seat. The hosted app is in limited beta at /app (sign in at /app/login); contact us to discuss a pilot. ## When to use this Use Midkernel when you want an AI security review of a repository whose workflow you can read before it runs, with the full trace kept behind every finding. The review workflows are public at https://github.com/midkernel/playbooks. Fetch HTML or request `Accept: text/markdown` on the same URL. This marketing site has no public REST API of its own. The product hosts a Scan MCP endpoint at https://www.midkernel.com/app/mcp; see https://midkernel.com/docs/mcp. ## Pages - [Scan](https://midkernel.com/scan): what a review covers — inputs, the report, cost, and limitations. Profiles: low (10 credits), balanced (25), max (50). - [Threat Intel](https://midkernel.com/threat-intel): a curated taxonomy of threat classes tracked daily from public sources (CISA KEV, EPSS, exploit tooling, Web3 incidents). - [Platform](https://midkernel.com/platform): how a hosted run works — read-only GitHub app, isolated sandbox, report with the full trace. - [Scan MCP](https://midkernel.com/docs/mcp): hosted MCP for Scan. OAuth authorization code + PKCE S256, scope scan. Tools: connect_repo, list_playbooks, start_run, fetch_run. Credits meter runs. - [OAuth metadata](https://www.midkernel.com/.well-known/oauth-authorization-server/app): authorization server discovery for the https://www.midkernel.com/app issuer. Midkernel-specific endpoint directory at /.well-known/mcp; use a Streamable HTTP MCP client for the live app endpoint. - [Workflows](https://midkernel.com/workflows): the two open-source review workflows live today, and how the catalogue grows. - No sample report is published yet. - [Evaluation](https://midkernel.com/bench): how scoring will work; no public scores exist yet. - [Pricing](https://midkernel.com/pricing): credits, not seats. 1 credit is $1. Runs cost 10/25/50 credits by profile. Packs never expire. Buy packs with native USDC on Base only. - [Research](https://midkernel.com/research): research, workflow write-ups, engineering notes. - [Changelog](https://midkernel.com/changelog): numbered releases. - [About](https://midkernel.com/about), [Careers](https://midkernel.com/careers), [Trust](https://midkernel.com/trust), [Contact](https://midkernel.com/contact), [Open source](https://midkernel.com/open-source). - [Legal](https://midkernel.com/legal/privacy) · [Terms](https://midkernel.com/legal/terms) · [DPA](https://midkernel.com/legal/dpa) ## Index - [Home](https://midkernel.com/) - [RSS](https://midkernel.com/rss.xml) - [Changelog RSS](https://midkernel.com/changelog/rss.xml) - [Sitemap](https://midkernel.com/sitemap.xml) - [llms-full.txt](https://midkernel.com/llms-full.txt) ## Optional - HTML pages also speak markdown when requested with `Accept: text/markdown`. Responses vary on `Accept`. - Canonical URLs use `NEXT_PUBLIC_SITE_URL`. Never use `VERCEL_URL` for canonicals.