SCA · IaC · Secrets · Zero Agents SCA · IaC · Secrets · Zero Agents

DETECTA VULNS
ANTES DEL MERGE.
UN SOLO ESCANEO.
CATCH VULNS
BEFORE THEY SHIP.
ALL IN ONE SCAN.

Una sola plataforma que escanea dependencias, infraestructura como código y secretos. Tu CI bloquea los PRs riesgosos antes del merge. Te conectas con un webhook que tú controlas, y todo el procesamiento ocurre del lado de Musha. One platform that scans dependencies, infrastructure as code, and secrets. Your CI blocks risky PRs before they merge. You connect with a webhook you control, and all processing happens on Musha's side.

Start free trial Start free trial PróximamenteComing soon See demo See demo
14d Free trial · No setup fee Free trial · No setup fee
3-in-1 SCA + IaC + Secrets SCA + IaC + Secrets
100% Webhook bajo tu control Webhook under your control

Cobertura técnica Technical coverage

9Ecosistemas SCASCA ecosystems
681Reglas IaC activasActive IaC rules
15+Providers de SecretsSecrets providers
4Plataformas GitGit platforms
3-IN-1SCA · IaC · SecretsSCA · IaC · Secrets

Features Features

UN SCANNER
TRES FRENTES
ONE SCANNER
THREE FRONTS

01

SCA

Detecta vulnerabilidades en dependencias open source. 9 ecosistemas soportados: npm, PyPI, Go, Maven, NuGet, Cargo, RubyGems, Composer y más. Fix automático recomendado por CVE. Detects vulnerabilities in open source dependencies. 9 ecosystems supported: npm, PyPI, Go, Maven, NuGet, Cargo, RubyGems, Composer, and more. Auto-suggested fix per CVE.

Advisory DB actualizada · CVE + CWE Live advisory DB · CVE + CWE
02

IaC

Análisis estático de Terraform, CloudFormation, Kubernetes y Dockerfiles. 681 reglas · 35+ servicios AWS · basadas en AWS FSBP, CIS Benchmark, NSA/CISA Kubernetes Hardening y CIS Docker Benchmark. Detecta misconfigurations antes del apply. Static analysis for Terraform, CloudFormation, Kubernetes, and Dockerfiles. 681 rules · 35+ AWS services · based on AWS FSBP, CIS Benchmark, NSA/CISA Kubernetes Hardening, and CIS Docker Benchmark. Catch misconfigurations before apply.

Terraform · CloudFormation · Kubernetes Terraform · CloudFormation · Kubernetes
03

SECRETS

Detección de credenciales filtradas en código: AWS keys, GitHub tokens, Stripe, Slack, GCP, Azure y más. Catálogo de patrones conocidos combinado con análisis estadístico. Sin falsos positivos agresivos. Detection of leaked credentials in code: AWS keys, GitHub tokens, Stripe, Slack, GCP, Azure, and more. Known-pattern catalog combined with statistical analysis. No aggressive false positives.

15+ providers · Smart suppression 15+ providers · Smart suppression
Ver todas las features → See all features →

Por qué Musha Why Musha

DIFERENTE
POR DISEÑO
DIFFERENT
BY DESIGN

01

ALL-IN-ONE

Un precio cubre los tres frentes: dependencias, infra y secretos. No tienes que pagar tres SKUs distintos para tener cobertura completa. One price covers all three fronts: dependencies, infrastructure, and secrets. You don't pay three separate SKUs just to get full coverage.

02

CONEXIÓN POR WEBHOOK

Te conectas a Musha a través de un webhook estándar que tú configuras. Mantienes control total sobre qué eventos recibimos y puedes revocar el acceso en cualquier momento, sin pasar por nadie. You connect to Musha through a standard webhook that you configure. You keep full control over which events we receive and you can revoke access at any time, without going through anyone.

03

SOPORTE EN ESPAÑOL

Hablamos español de manera nativa y trabajamos en horario LatAm (UTC-5). Si tu equipo está en Bogotá, Ciudad de México o Buenos Aires, las respuestas de soporte llegan dentro del mismo día laboral. We speak Spanish natively and operate on LatAm hours (UTC-5). If your team is in Bogotá, Mexico City, or Buenos Aires, support replies arrive within the same business day.

04

PRICING PÚBLICO

$99, $299 o $799 al mes en USD (los impuestos locales se suman en el checkout según tu país) — los tres precios viven en la página de pricing. Eliges directo, sin pasos intermedios. Si necesitas algo custom, también podemos hablar. $99, $299, or $799 per month in USD (local taxes added at checkout based on your country) — all three prices live on the pricing page. You pick directly, no intermediate steps. If you need something custom, we can talk too.

05

3-IN-1 SCAN

Cada PR pasa por un solo scan que revisa tres frentes: dependencias, infraestructura y secretos. Una integración, tres tipos de coberturas, cero duplicación de webhooks. Every PR runs through one scan that checks three fronts: dependencies, infrastructure, and secrets. One integration, three types of coverage, zero duplicate webhooks.

Nosotros About

SEGURIDAD
AL RITMO DEL
DESARROLLO
SECURITY
AT THE PACE
OF SHIPPING

Nuestra misión Our mission

"Que la seguridad ayude a tu equipo a moverse rápido, no lo trabe. Que puedas hacer merge con confianza sin esperar a la auditoría anual para enterarte de que algo no estaba bien." "Security should help your team move fast, not slow them down. You should be able to merge with confidence — not wait for the annual audit to find out something was off."

Musha Security es una plataforma que escanea tu código, tu infraestructura como código y tus secretos en busca de vulnerabilidades. La hicimos pensando en equipos que quieren proteger su software sin frenar su velocidad de entrega. Musha Security is a platform that scans your code, your infrastructure-as-code, and your secrets for vulnerabilities. We built it for teams that want to protect their software without slowing down delivery.

La construimos para ofrecer una experiencia integrada de seguridad: una sola plataforma que cubre dependencias, infraestructura y secretos en un mismo lugar, con un modelo de integración por webhook que respeta el control del cliente sobre sus repos, y con precios visibles desde el primer minuto. We built it to offer an integrated security experience: one platform that covers dependencies, infrastructure, and secrets in the same place, with a webhook-based integration model that respects customer control over their repos, and with prices visible from minute one.

El nombre viene del japonés 武者: el guerrero que ha dominado su arte. Operamos desde Colombia para clientes en toda LatAm y el mundo, con soporte en español y horarios alineados a tu zona horaria. The name comes from the Japanese 武者: the warrior who has mastered their craft. We operate from Colombia for clients across LatAm and the world, with Spanish-speaking support and time zones aligned to yours.

SCA IaC Secrets Terraform CloudFormation Kubernetes npm PyPI Go Maven NuGet Cargo RubyGems Composer OWASP CIS Benchmark AWS FSBP

Explora Explore

TODO ESTÁ
EN ABIERTO
EVERYTHING IS
OUT IN THE OPEN

01

Pricing público Public pricing

4 tiers visibles en web con precios claros y una FAQ con 10 preguntas frecuentes. Eliges directo desde la página. 4 tiers visible on the web with clear prices and a FAQ with the 10 most-asked questions. You pick directly from the page.

02

Detalle técnico Technical detail

9 ecosistemas SCA, 681 reglas IaC · 35+ servicios AWS, 15+ providers de secrets. Specs completos. 9 SCA ecosystems, 681 IaC rules · 35+ AWS services, 15+ secret providers. Full specs.

03

Documentación Documentation

Getting started, integration guides por plataforma, API reference, troubleshooting. Getting started, integration guides per platform, API reference, troubleshooting.

Enterprise Enterprise

¿NECESITAS ALGO
CUSTOM?
NEED SOMETHING
CUSTOM?

Si necesitas SAML SSO, un contrato custom, DPA firmado o facturación con invoice, escríbenos. Si lo tuyo es algo más estándar, podrás arrancar un trial directo desde la app cuando abramos signups públicos. If you need SAML SSO, a custom contract, signed DPA, or invoice billing, drop us a line. If your case is more standard, you'll be able to start a trial straight from the app when we open public signups.

Email

[email protected]

Ubicación

Location

Colombia · LATAM · Remote

Tiempo de respuesta

Response time

1 business day (LatAm hours) 1 business day (LatAm hours)