Clira is a static code analysis tool that scans public GitHub repositories for security patterns. It attempts automated fixes for detected issues and verifies those fixes against the repository's own test suite. The output is a GO / HARDEN / STOP verdict and an optional dated, signed badge.
Clira is not a penetration test, security audit, or exploit assessment. It performs static analysis only — no runtime testing, no taint analysis, no logic-bug detection. It does not guarantee your code is secure. 67 patterns is not exhaustive. A "GO" verdict means "no open hits on our 67 rules on this date," not "this code is safe."
The "Cleared by Clira" badge is a dated record that on a specific date, your repository passed our pattern scan and any auto-fixes preserved your test suite. It is not a warranty, certification, or insurance. It does not attest to security — only to the scan result on that date. Tomorrow's CVEs are not covered.
Launch Clearance is $149 per repository, one-time. If we cannot deliver a report, you receive a full refund or a free re-scan at your option. The free preview (3 findings, no fixes) costs nothing.
Clira is provided "as is" without warranty of any kind. We are not liable for security incidents, data breaches, or any damages arising from use of or reliance on Clira's reports or badges. If you need liability coverage, hire a penetration testing firm.
You may only scan repositories you own or have permission to scan. You may not use Clira to scan repositories you do not have rights to access. Abuse of the free tier (automated bulk scanning, rate-limit evasion) may result in access restrictions.
We may update these terms. Material changes will be noted on this page with an updated date.
Questions? Email peter@clira.dev.
← Back to Clira