I built a Mac AppSec tool where the AI never sees your whole repo A developer built InsurStaq, a local-first AppSec auditor for macOS (Apple silicon) that runs deterministic scanners and attack-path tracing before feeding only a bounded evidence packet to a local LLM, so the model never receives the full repository as context. The tool bundles a llama.cpp sidecar or connects to a user's own Ollama/LM Studio instance on loopback, and includes an air-gapped mode, encrypted local storage, and approval-gated patch application with rescan verification. It is a product of KarmSakha Limited and is offered in early access, with the developer noting uneven framework coverage. Most AppSec pipelines assume one thing first: upload the repo. That breaks for NDA client code, regulated workloads, or a policy that source does not leave the building. SaaS scanners want the tree. On-prem enterprise gear assumes you have a security department. A lot of solo founders and small teams sit in the gap. I built InsurStaq — a local-first security auditor for macOS Apple silicon to sit in that gap. The order of operations matters The product is deliberately not LLM over the repo.” The loop is: 1. Parse and map the application routes, auth, frameworks via tree-sitter adapters . 2. Run deterministic scanners — first-party SAST, secrets including git history , IaC / container / CI checks, offline OSV CVEs, SBOM export. 3. Build a code + security graph and trace source→sink attack paths inter-procedural taint , not only rule hits. 4. Only then feed a local model an evidence packet — explain, triage, draft a minimal patch. 5. You approve → atomic apply → rescan to verify. The model never gets the whole repository as context. Scanners find; the model reasons over a bounded packet with schema-validated output. That keeps it grounded and small enough for a laptop bundled llama.cpp sidecar, or your own Ollama / LM Studio on loopback . Privacy is structural, not a checkbox - One allowlisted outbound gateway with a ledger; request types that must not carry repo content do not. - Air-Gapped Mode turns networking off. - Encrypted local store + Keychain. - Read-only Git via vendored libgit2 no hooks/filters, no fetch/push . What it is / is not - Is: local SAST-style coverage + attack-path tracing + approval-gated remediation + compliance readiness mapping OWASP / ASVS / CWE / SOC 2 / ISO 27001 / PCI / GDPR / HIPAA as evidence states, not badges . - Is not: a penetration test. Not a certification. Early access: licence + download by email. Framework coverage is uneven — I’d rather hear what you need than overclaim. Reports: PDF, HTML, Markdown, JSON, SARIF, CSV. CLI can fail CI on critical findings. Links If you care about the taint engine, air-gap design, or where coverage still misses, ask in the comments — happy to go deep. Not affiliated with the former InsurStaq.ai business that ceased operations in 2024. InsurStaq is a product of KarmSakha Limited England & Wales .