Blog
Blog
Güvenlik ve uyum dökümanlarıSecurity & compliance docs
İş dilinde rehberler ve özellik dökümanları — risk, öncelik, aksiyon.
Business guides and feature docs — risk, priority, action.
-
How Guardbee works: add a brand, scan, and report
Define a brand, choose security modules, run scans, and use BeeAI for business-language reporting. Getting-started guide with live…
-
Website security scanning: what Guardbee checks
HTTPS, SSL, security headers, cookies, sensitive paths, forms, and more. A business-friendly guide to Guardbee website security scanning.
-
BeeAI security copilot: explain findings in business language
BeeAI explains Guardbee findings with business impact, priority, and action language. Product guide for the security copilot.
-
Subdomain takeover risk: dangling DNS and claimable hosting
Dangling CNAMEs and abandoned hosting records create brand-spoofing risk. Documentation for Guardbee subdomain takeover checks.
-
Discovery Surface: robots.txt, sitemap.xml, security.txt, and Technology Fingerprinting
Discovery surface analysis: robots.txt, sitemap.xml, security.txt, and technology fingerprinting. Guardbee reports the same passive signals an attacker can…
-
Third-Party Scripts and JavaScript Supply Chain Security
Explore third-party JavaScript, CDN, npm, SRI, and CSP risks. Learn how JavaScript supply chain attacks work and how…
-
Form security and open redirects: CSRF, autocomplete, and redirect risk
CSRF, autocomplete, and open redirects: how Guardbee’s form security scanning works and why these risks should be evaluated…
-
API security scanning: CORS, JWT, GraphQL, and response leaks
CORS, JWT, GraphQL, and API response leakage: how Guardbee’s API security scanning works, how it maps to OWASP…
-
KVKK and privacy scanning: notices, cookie consent, and VERBİS signals
Privacy notices, cookie consent, tracker disclosure, VERBİS, cross-border transfer, and form consent. Comprehensive documentation for Guardbee KVKK modules.
-
AI security scanning: inventory, prompt injection, and data leakage
AI chat widgets, model endpoints, prompt-injection signals, and LLM data leakage. Detailed documentation for Guardbee AI security features.
-
Network and infrastructure security: ports, WAF/CDN, cloud exposure
Open-port signals, WAF/CDN detection, cloud storage exposure, and Firebase config. A business guide to Guardbee network and infrastructure…
-
Why AI security is now a board-level topic
AI assistants embedded on your site create a new attack and data-leakage surface.
-
DNS and Email Security: Your First Line of Defense Against Brand Spoofing
How SPF, DKIM, DMARC and related DNS records protect your brand from spoofing — and what Guardbee checks.
-
Exposed .env and .git: quiet data disasters
Misconfigured servers can expose source code or secrets to the internet — often unnoticed.
-
Cookie security and privacy: trust meets compliance
Insecure cookies enable session risk; transparent consent reduces legal and reputation exposure.
-
Security headers: invisible risks with real cost
Headers like CSP, HSTS, and X-Frame-Options reduce clickjacking and script injection risk.
-
HTTPS and SSL: the first layer of customer trust
Encryption is not just a technical detail — it is a business requirement for trust and conversion.
-
MCP Agent Graph Auditor: multi-agent transitive agency
Find transitive excessive agency in LangGraph, CrewAI, and AutoGen graphs with @guardbee/mcp-agent-graph-auditor — agents that reach dangerous tools…
-
MCP Prompt Leak Scanner: stop PII/credentials in outbound prompts
Catch API keys, national IDs, cards, and IBANs in outbound LLM prompts with @guardbee/mcp-prompt-leak-scanner — MCP scans or…
-
MCP Vector Store Scanner: find open RAG databases
Probe Weaviate, Qdrant, Chroma, Elasticsearch, Redis, and Postgres/pgvector for unauthenticated exposure with @guardbee/mcp-vector-store-scanner.
-
MCP Model Scanner: ML checkpoint supply-chain scanning
Scan PyTorch, pickle, safetensors, Keras/H5, and ONNX files for malicious pickle gadgets, disguised headers, and path traversal with…
-
MCP LLM Red Team: test live chatbot guardrails
Test an LLM or chatbot you own with 12 canary probes using @guardbee/mcp-llm-redteam: jailbreak, extraction, obfuscation, and refusal…
-
GuardBee VS Code extension: see findings while coding, fix before you push
Catch secret and AI-security findings in the editor; fix them during development with Quick Fix, suppress comments, and…
-
MCP Prompt Injection Scanner: defend RAG and content
Scan RAG chunks, scraped pages, and docs for indirect prompt injection with @guardbee/mcp-prompt-injection-scanner: overrides, role spoof, hidden text,…
-
MCP Server Auditor: audit MCP tool definitions
Audit other MCP servers’ tool definitions with @guardbee/mcp-server-auditor: excessive agency, SSRF/SQL/shell sinks, loose schemas, secrets, CORS. npm +…
-
MCP Security Suite: four security tools in one package
Use secret scanning, OSV CVEs, SSL, and DNS in one MCP/CLI with @guardbee/security-suite. Claude Desktop serve + GitHub…
-
MCP AI Code Scanner: insecure LLM integration patterns
Scan code for insecure AI/LLM patterns with @guardbee/mcp-ai-code-scanner: client API keys, eval(output), excessive agency, PII. npm + SARIF.
-
MCP DNS Intelligence: SPF, DMARC, DKIM, and dangling subdomains
Enumerate DNS, email auth, and dangling subdomains from Claude with @guardbee/mcp-dns-intelligence. npm setup and prompts.
-
MCP SSL Inspector: TLS certificates, ciphers, and HSTS
Inspect domain TLS from Claude with @guardbee/mcp-ssl-inspector: expiry, weak ciphers, HSTS. npm setup and examples.