Getting started with Epherem
How to scan your app, read the report and scan again after a change. Written for people who build with AI tools and don’t read much code.
How Epherem works
Epherem reads a copy of your app’s source code and looks for common security mistakes. It never runs your app, visits your live site or logs in to your database. You give it the code in one of two ways: upload a ZIP, or connect GitHub and choose a repository. A scan takes from a few seconds to a few minutes, and stops at 5 minutes.
The scan uses 55 rules written for the mistakes AI-built apps tend to make: who can see and change data, keys and passwords left in the code, how the app handles what people type in, and settings. It also checks packages with exact versions (from a lockfile) against OSV, a public database of known security problems. Without a lockfile, the report says which ones it couldn’t check. No AI reads your code.
Epherem is free, and each account can run 5 scans a day.
1. Create an account
Click Scan your app free or Sign in. Continue with Google, or enter your email address and type in the one-time code sent to it. There is no password to remember.
Epherem needs a confirmed email address before you can scan. Signing in with Google or with the emailed code confirms yours. When you create your account, you’ll be asked to read and accept the Terms of Service and the Privacy Policy.
2. Give Epherem your code
Option 1: upload a ZIP. Compress your project folder:
- Mac: right-click your project folder → Compress.
- Windows: right-click your project folder → Send to → Compressed (zipped) folder.
Include the whole project. The backend, settings files, database rules and the supabase/ folder matter as much as the screens people see: several of the most serious problems live in exactly those files. Include your lockfile too (for example package-lock.json), because it tells Epherem the exact package versions to check.
You can leave node_modules in. The page leaves it out before uploading, along with build output and other folders Epherem skips. One catch: every folder named build or dist is skipped, so source code kept in a folder with one of those names is not read. The page checks the ZIP before uploading it, so a file that would be refused fails quickly, with a reason.
Upload limits
A ZIP can be up to 100 MB, hold up to 20,000 entries and 5,000 files, and unpack to no more than 1 GB. Files over 1 MB are skipped, and listed in the report (lockfiles can be up to 10 MB, because real ones are big). A scan stops at 5 minutes. You can leave node_modules in. The page leaves it out before uploading, along with build output and other folders Epherem skips.
Option 2: connect GitHub. Click Connect GitHub. GitHub asks you to install Epherem’s GitHub app and to choose which repositories it can see; pick only the ones you want scanned. Epherem can read the code in those repositories. It can’t change it. Then choose a repository and start the scan. Personal GitHub accounts only for now. For an organisation’s repository, upload a ZIP.
3. Your apps
Every scan belongs to an app, and Epherem creates the app for you:
- From GitHub: every scan of the same repository goes into the same app.
- From a ZIP: choose the ZIP, then name the app. Epherem suggests a name from the file. To scan a new version, open the app and click New scan.
Your scans list is grouped by app. Each GitHub repository gets one app. If you already have a ZIP app with the same name, Epherem offers to add the repository to it, and its earlier scans stay in its history. Otherwise ZIP apps and GitHub apps stay separate. An app split across two repositories (say, a separate frontend and backend) shows up as two apps for now.
4. The scan
A scan takes from a few seconds to a few minutes. It stops at 5 minutes; if it runs out of time, the report says which checks didn’t finish and the scan is marked incomplete. One scan runs at a time on each account.
Each account can run 5 scans a day, whether from a ZIP or from GitHub. The count resets at midnight UTC.
5. Read your report
The report shows everything the rules and the package check found. It opens with how your app is doing, in one line, and up to three findings to start with. Then it has three parts.
It counts findings, for example “37 findings”, and says under the count how many places they’re in. A finding is one problem to fix. It can show up in more than one place in your code: a check that matched in three files is one finding in three places. Each package with an advisory is its own finding in each lockfile it’s in.
Likely issues, and what needs checking. These are in your own code. A check matched something, but Epherem reads your code without running your app, so it can’t confirm the problem for you. They come in two groups:
- Likely issues. The scanner saw the risky code itself. Start here.
- Needs checking. The scanner looked for a protection and didn’t see it, or the match depends on context it can’t see. The protection may exist somewhere the scan couldn’t see, so look before you change anything.
Known issues. Packages your app uses that have a published security advisory for the version you have, with the advisory named. Packages with exact versions (from a lockfile) are checked against published advisories. Without a lockfile, the report says which ones it couldn’t check. These are the only findings shown as known problems, because they come from a public advisory rather than a pattern in your code.
What we couldn’t check. The report names what the scan did not cover, and nothing on this list is reported as clean:
- Languages and files that weren’t analysed. Coverage is strong for JavaScript and TypeScript and partial for Python; other languages are not analysed. Vue, Svelte and Astro component files are not read yet, so an app that has them is marked incomplete.
- Files skipped for size, and checks that didn’t finish.
- Things outside your code, such as the settings in your Supabase dashboard or your live site.
Each finding shows:
- a title and one line in plain words, with its technical name under them;
- what someone could do with it;
- a suggested fix, and a prompt to paste into your AI tool;
- each place it was found: the file and the line;
- a short excerpt of the code, with anything that looks like a key or password masked.
Epherem also looks at what’s in the ZIP or repository itself: private keys, credential files, database dumps and infrastructure state files are flagged by name.
6. Export your report
Click Export scan to copy every finding for your AI tool, or to download the report as Markdown, a spreadsheet (CSV), a PDF or JSON. The spreadsheet has one row per place, numbered by the finding it belongs to. Export is free.
7. Fix, then scan again
Most people fix findings the same way they built the app: by asking their AI tool. Fix one thing at a time, and ask the tool to check each finding against your code before it changes anything, since some findings turn out to be safe. The From finding to fix guide walks through it.
When you’re ready, scan again (it counts towards your 5 a day). Each scan is a new report of your code as it is now; Epherem doesn’t compare it with the last one. A finding missing from the new report is not proof it’s fixed: the code may have moved or been reworded so the rule no longer matches, while the problem is still there. Check the change yourself.
Read your reports from Claude Desktop
If you use Claude Desktop, you can install the Epherem extension and ask Claude about your reports. It can list your apps and scans and read a report. It can’t start a scan or change your code. How to set it up is on the AI Integration page.
Delete reports, apps or your account
Your reports stay in your account until you delete them. You can delete a single report, an app with all of its reports, or your whole account. Deleting your account deletes your reports, your apps and the usage records tied to your account. The Privacy Policy lists what is kept and for how long.
What happens to your code
Your code is deleted after the scan
Uploaded code is used only to run the scan and is deleted afterwards; anything left behind is deleted by a storage rule, usually within two days. Your report is kept until you delete it, and it contains file paths, line numbers and short code excerpts with secrets masked. No code is sent to an AI provider. Package names and versions are sent to OSV.dev to look up advisories.
Privacy policyWhat Epherem does not do
Worth being plain about, because a scanner that overstates itself is part of the problem Epherem exists to fix:
- Epherem reads source code. It does not visit your deployed site, test your live database or run your app, so problems that only exist in your live settings are out of its sight.
- It doesn’t change your code, and it doesn’t watch your app or scan again by itself. A scan happens when you start one.
- A report with few findings doesn’t mean your app is secure. Epherem misses things, and it tells you what it couldn’t check. For apps that handle payments, health data or other sensitive information, have a person review the code too.
Troubleshooting
- “My scan is marked incomplete.” Part of your code wasn’t read, or a check didn’t finish. Common causes: Vue, Svelte or Astro component files; a language Epherem doesn’t analyse; files over 1 MB; or the 5-minute limit. What we couldn’t check lists which. Everything the scan did find is still in the report.
- “A file I care about wasn’t analysed.” Check What we couldn’t check. The usual reasons: it’s in a language Epherem doesn’t analyse, it’s over 1 MB, it sits in a folder named
buildordist, or the project has more than 5,000 source files. Source files over 1 MB are usually generated code; if a real one is that large, splitting it helps more than just the scan. - “My upload was refused for size.” The ZIP is over one of the limits above, or isn’t a valid ZIP. Zip the project folder itself (not a folder holding another ZIP) and leave out
node_modulesand build output. - “I’ve reached the daily limit.” Each account can run 5 scans a day. The count resets at midnight UTC. Your earlier reports stay in your account in the meantime.
Ready to run your first scan?
Free during early access, 5 scans a day. Upload a ZIP or connect GitHub.
Scan your app freeContact
Questions, feedback or a problem with a report: support@epherem.com.