πŸ”’ Free Security Scanner βœ… Privacy-First ⚑ Instant Results

Is Your Automation
Leaking Credentials?

Free security scanner for n8n, Make & Zapier workflows. Detect hardcoded API keys, passwords, and authentication vulnerabilities in seconds.

10+ Vulnerability Types
100% Browser-Based
0 Data Sent to Servers

The Hidden Compliance Risk

Most companies don't realize their automation workflows are creating compliance vulnerabilities

79%
of companies fail their first PCI DSS audit

Source: Verizon PCI Compliance Report

89%
of HIPAA entities fail to document adequate compliance

Source: HHS-OCR 2016-2017 Audit Report

$75K
average cost of first SOC 2 certification for fintech

Most failures due to exposed credentials

⚠️ Your automation workflows may contain:

  • ❌ Hardcoded AWS keys exposing your entire infrastructure
  • ❌ Stripe API keys allowing unauthorized payment processing
  • ❌ Unauthenticated webhooks anyone can trigger
  • ❌ Database credentials in plaintext
  • ❌ OAuth tokens that never expire

And auditors WILL find them. WorkflowGuard finds them first.

Instant Security Scanning

Upload your workflow JSON. Get a comprehensive security report in seconds.

πŸ”

Pattern Detection

Scans for 10+ credential types including AWS keys, Stripe tokens, OpenAI keys, GitHub tokens, and more.

⚑

Platform-Specific Checks

Detects n8n unauthenticated webhooks, Make exposed connections, and Zapier plaintext auth.

πŸ”’

100% Private

Everything runs in your browser. Your workflow data never leaves your computer. No servers, no tracking.

πŸ“Š

Security Score

Get a 0-100 security score with severity ratings (Critical, High, Medium) for each finding.

πŸ’‘

Remediation Guidance

Every vulnerability includes specific instructions on how to fix it properly.

πŸ“₯

Downloadable Reports

Export scan results as text files for documentation, team review, or compliance evidence.

What WorkflowGuard Detects

Our pattern-based detection engine scans for the most common security vulnerabilities found in automation workflows.

  • πŸ”‘
    AWS Access & Secret Keys
    Detects AKIA* access keys and 40-character secret keys
  • πŸ’³
    Stripe API Keys
    Both live and test keys (sk_live_*, sk_test_*)
  • πŸ€–
    OpenAI API Keys
    ChatGPT/GPT-4 keys (sk-*) that could incur charges
  • πŸ™
    GitHub Tokens
    Personal access tokens (ghp_*) for repository access
  • πŸ’¬
    Slack Tokens
    Bot, user, and webhook tokens (xox*)
  • πŸ”
    Generic API Keys & Passwords
    Hardcoded credentials in any format
  • 🌐
    Unauthenticated Webhooks
    n8n webhooks with no authentication configured
  • πŸ”“
    Private Cryptographic Keys
    RSA/DSA private keys in workflow code
⚠️ CRITICAL - AWS Access Key Detected
Found: AKIA...
Location: Code Node #3
Severity: Critical

Remediation:
Move AWS credentials to
environment variables or use
n8n credential management.
0/100
Security Score
3
Critical
2
High
1
Medium

Example scan results showing detected vulnerabilities

Built by a Security Professional

WorkflowGuard is built by Radu Pisano, a federal cybersecurity expert with 16+ years of experience

πŸŽ“
CISSP
Certified Information Systems Security Professional
πŸ”
CFE
Certified Fraud Examiner
πŸ›‘οΈ
CAISP
Certified Artificial Intelligence Security Professional

Professional Background

πŸ›οΈ Federal Investigator

16+ years investigating healthcare fraud, digital forensics, and computer forensics

Privacy First: No data collection. No tracking. No servers.
All scanning happens locally in your browser.

Ready to Scan Your Workflows?

Start with the free scanner. Get notified when WorkflowGuard Pro launches with continuous monitoring, team collaboration, and compliance reports.

Try Free Scanner Now β†’
βœ… No spam, ever
βœ… Unsubscribe anytime
βœ… Early adopter discount

Frequently Asked Questions

Is my workflow data safe?

Absolutely. WorkflowGuard runs 100% in your browser using JavaScript. Your workflow JSON file never leaves your computer. We don't have servers, databases, or any way to collect your data. You can even use it offline.

What platforms does it support?

WorkflowGuard currently supports n8n, Make (Integromat), and Zapier. Simply export your workflow as a JSON file from any of these platforms and upload it to the scanner.

How accurate is the detection?

The free POC uses pattern-based detection with regex patterns for known credential formats (AWS keys, Stripe keys, etc.). It's highly accurate for these specific patterns. WorkflowGuard Pro will add AI-powered deep analysis for contextual vulnerabilities.

Will this work with self-hosted n8n?

Yes! WorkflowGuard scans the JSON file format, which is the same whether you're using n8n Cloud or self-hosted. Export your workflow, upload the JSON file, and scan.

What's the difference between the free POC and WorkflowGuard Pro?

The free POC provides pattern-based scanning and security scores. WorkflowGuard Pro (launching soon) will add:

  • βœ… AI-powered deep analysis for contextual vulnerabilities
  • βœ… Continuous monitoring via webhooks
  • βœ… Scan history and team dashboards
  • βœ… Compliance reports (SOC 2, ISO 27001, PCI DSS, HIPAA)
  • βœ… GitHub integration for automated scanning
  • βœ… Custom rules and white-label reports

Can this replace a SOC 2 audit?

No. WorkflowGuard is a pre-audit tool that helps you find and fix workflow security issues before auditors arrive. It generates evidence and gap analysis but does not certify compliance. You'll still need an independent auditor for SOC 2 certification.

Who built this and why?

WorkflowGuard was built by Radu Pisano, a federal cybersecurity investigator with CISSP, CFE, and CAISP certifications. After 16+ years investigating digital crimes, I saw companies repeatedly fail audits due to exposed credentials in automation workflowsβ€”a gap that existing security tools don't address.