# Legit Security > AI-native Application Security Posture Management (ASPM). Legit discovers everything being built across the software factory — SCM, CI/CD, artifact registries, cloud and AI coding assistants — then correlates, prioritizes and helps remediate application security findings from one place. Products span code security (SAST/SCA), enterprise secrets detection, software supply chain security, code change management, and continuous compliance/SBOM, plus an agent-facing layer: the Legit MCP Server and the VibeGuard AI Guard plugin for Claude Code. Generated by the API Evangelist enrichment pipeline on 2026-07-19 from public sources. Legit Security publishes no llms.txt of its own and no public OpenAPI; platform API documentation sits behind the authenticated customer portal. ## Company - [Website](https://www.legitsecurity.com/): Company home and product overview - [ASPM platform](https://www.legitsecurity.com/platform/aspm): The core platform - [About](https://www.legitsecurity.com/about-us): Company background - [Contact / sales](https://www.legitsecurity.com/contact-us): Pricing is quote-based via sales - [Request a demo](https://info.legitsecurity.com/request-a-demo) - [Log in](https://www.legitsecurity.co/app/login) ## Products - [Unified vulnerability management](https://www.legitsecurity.com/vulnerability-management) - [Enterprise secrets scanning](https://www.legitsecurity.com/enterprise-secret-scanning) - [Software supply chain security](https://www.legitsecurity.com/software-supply-chain-security) - [AI visibility](https://www.legitsecurity.com/ai-visibility) - [AI-powered remediation](https://www.legitsecurity.com/ai-powered-remediation-fix-appsec-issues-faster-with-legit) - [VibeGuard — security governance for AI-generated code](https://www.legitsecurity.com/security-governance-for-ai-generated-code-legit-vibeguard) - [Continuous compliance and SBOM](https://www.legitsecurity.com/continuous-compliance-sbom) ## Agent-facing surfaces - [Legit MCP Server](https://www.legitsecurity.com/legit-mcp-server-ai-native-security-intelligence-for-developers): Security intelligence inside Cursor, GitHub Copilot, Claude Code and Windsurf. Endpoint and transport are documented for account holders only. - [AI Guard plugin for Claude Code](https://github.com/Legit-Labs/claude-marketplace): `/plugin marketplace add Legit-Labs/claude-marketplace` then `/plugin install vibeguard@legit-labs-claude-marketplace`, then `legit auth`. ## Tooling - [legitify](https://github.com/Legit-Labs/legitify): Apache-2.0 GitHub/GitLab misconfiguration scanner. `brew install legitify`; `SCM_TOKEN= legitify analyze`. - [gh-legitify](https://github.com/Legit-Labs/gh-legitify): GitHub CLI extension. - [legit CLI](https://github.com/Legit-Labs/homebrew-legit-labs/blob/main/legit.rb): First-party scanning CLI. `brew install Legit-Labs/legit-labs/legit`. - [GitHub organization](https://github.com/Legit-Labs) ## Integrations - [Integration catalog](https://www.legitsecurity.com/integrations): 100+ integrations across AppSec scanners, artifact registries, cloud platforms, cloud security, CI, identity, SCM, ticketing/alerting (including generic outbound Webhook), knowledge management, API security, developer education and bug bounty. ## Trust and legal - [Trust center](https://trust.legitsecurity.com/) (Scytale-hosted) - [Privacy policy](https://www.legitsecurity.com/privacy-policy) - [Terms of use](https://www.legitsecurity.com/terms-of-use) ## Learn - [Blog](https://www.legitsecurity.com/blog) ([RSS](https://www.legitsecurity.com/blog/rss.xml)) - [ASPM knowledge base](https://www.legitsecurity.com/aspm-knowledge-base) - [Resource library](https://www.legitsecurity.com/resource-library) ## Not published No public OpenAPI, AsyncAPI, GraphQL schema, .proto, /llms.txt, /.well-known/ documents, status page, public changelog, sandbox, or Postman collection was found on any Legit Security host as of 2026-07-19. ## Support support@legitsecurity.com