Deepsec

AI bug hunter promises big wins, but the comments went straight to side-eye

TLDR: Deepsec is a new AI-powered security scanner that promises to find old, hard-to-spot software flaws, but it may cost a fortune on large projects. Commenters instantly turned the launch into a drama fest over the confusing name, the eye-watering price, and whether cheaper alternatives can do the same job.

A new tool called deepsec is pitching itself as the heavyweight detective for hidden security flaws in giant piles of code. The sales pitch is bold: run it on your own servers, let AI comb through old projects, and maybe uncover the kind of nasty problems that have been quietly sitting there for years. The catch? Those scans can reportedly cost thousands, even tens of thousands of dollars for big projects. That alone was enough to make the comment section lean in with raised eyebrows.

And oh, the community did not disappoint. One of the first reactions was immediate confusion: is this connected to CapitalOne VulnHunter? Another person jumped in with a public-service announcement that it should not be confused with the long-running DeepSec security conference, which is the kind of naming chaos internet commenters live for. Then came the driest mic-drop of the thread: after reading that normal AI subscriptions aren't enough and that "for real scans" you should use Vercel's paid AI gateway, one commenter simply replied, "Okay..." That tiny word carried a thousand dollars' worth of skepticism.

Not everyone was buying the premium-AI-only vibe, either. A rival shout-out appeared almost instantly, with one commenter arguing that Swival Audit gets great results using smaller, open models instead. So the real drama wasn't just "new security scanner arrives" — it was naming confusion, sticker shock, and an under-the-comments knife fight over whether expensive AI is actually necessary at all.

Key Points

  • Deepsec is introduced as an agent-powered vulnerability scanner designed to run inside a user’s own infrastructure and review large existing codebases.
  • The tool is aimed at surfacing long-standing, hard-to-find vulnerabilities and uses high-end AI models at maximum reasoning levels, which can make scans costly for large repositories.
  • Deepsec supports parallel processing across worker machines and resumable runs that continue from the point of interruption instead of restarting from scratch.
  • The documented workflow includes initialization, agent-assisted project context preparation, scanning, optional false-positive reduction through revalidation, and export of findings.
  • For production-scale scanning, the article recommends Vercel AI Gateway and also supports direct Anthropic or OpenAI credentials, plus optional distributed execution on Vercel Sandbox microVMs.

Hottest takes

"Okay..." — nh43215rgb
"Not to confuse with the really long running IT-Security conference DeepSec" — miduil
"gives really good results even with small, open models" — jedisct1
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.