What is Hi AUDIT?
Hi AUDIT connects security analysis to an AI development workflow through the Model Context Protocol (MCP). Developers can request analysis, inspect the context of findings, and review suggested fixes in a connected editor. A finding is a review input; a qualified person still decides whether it applies and whether a change is safe to ship.
- Product
- Hi AUDIT
- Organization
- TECHFUND Inc.
- Category
- Security analysis for AI development workflows
- Integration
- MCP server connected to a compatible client or editor
- Code families described in the documentation
- Web applications, EVM smart contracts, and Solana programs. Confirm language and framework coverage for your project before adopting.
- Public documentation
- Setup guidance, analysis tool names, playbooks, and security review guides on hiaudit.io
- Account workspace
- app.hiaudit.io — account registration, Projects, Audits, and the account installation guide
How a team gets started
- Create or sign in to an account and open Projects.
- Open the installation guide in the account and use the settings supplied for your workspace and MCP client. Keep credentials outside public repositories and shared transcripts.
- Start with a repository you are authorized to analyze. Confirm the target, branch or commit, language, and relevant configuration.
- Review each finding in context, choose an owner, check the proposed change, and validate it in the team’s normal test and review process.
What a scan can establish
An analysis result describes the tool’s findings for its input and configuration. It does not prove that the entire application is secure, replace an independent audit, or establish that every theoretical issue is reachable in production. Review authorization rules, dependencies, deployment settings, and application requirements alongside the result. The public WebMCP demo uses synthetic sample data to illustrate triage; it is not a scan of your repository.
Before connecting sensitive code
Ask the team to confirm which code and metadata are transferred, where they are processed, retention and deletion options, workspace permissions, and the contractual terms that apply to your account. Obtain these answers before sending confidential repositories or regulated data. The security documentation and contact page provide the starting point for that review.
Security and data questions