Skip to content

Latest commit

 

History

277 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

TopFlow: Secure AI Workflow Builder

Try the Scanner GitHub Stars License

A visual builder for AI workflows, built by a former CISO to show security designed in, not bolted on.

Open the builder • Dependency scanner • Docs • Blog


Flagship Example: GitHub Dependency Scanner

A TopFlow workflow that checks a repository's dependencies against the OSV.dev vulnerability database and explains what to upgrade.

Checks Doesn't check
Known vulnerabilities in npm, PyPI, Go and Rust dependencies, with CVE (or advisory) ID, severity and fixed version Your own source code (no injection, XSS or authentication analysis)
Whether the repo has a SECURITY.md and a Dependabot config Compliance (GDPR, SOC 2, HIPAA)
A 0–100 score from a fixed formula Test coverage, CI setup or code quality
  • Findings come from OSV.dev and the score is computed in code (lib/osv/scanner.ts). An LLM, using your own key, only writes the explanation, and it can't change the findings (why).
  • Runs show sample results by default. Turn on Run a real scan in the run dialog for live data. Public repos work without a key; a GitHub token raises GitHub's rate limit and allows private repos.
  • No AI spending unless you ask. The report is built from the scan data. An LLM report (your own key and quota) runs only when you switch on Write the report with my AI key for that run; saved keys never turn it on.

Scan a repo →


Security You Can Trust

The scanner runs on TopFlow — a privacy-first AI workflow platform built with enterprise-grade security architecture.

Zero server-side storage Workflows and API keys are stored only in your browser. When you run a workflow, it's sent over HTTPS to our server, used in memory for that request, and never stored or logged.
BYOK model Bring your own AI provider keys, or use demo mode without any keys at all.
5-layer defense Input sanitization → HTTPS/HSTS → rate limiting → SSRF prevention → restricted code execution (built-in template code only; isolate planned)
Open source MIT licensed. Audit the code, fork it, own it.

How TopFlow compares:

TopFlow Other platforms
Data storage None (localStorage only) Cloud databases
API keys Your own (BYOK) Platform-managed
Code export Production TypeScript JSON/config only
Vendor lock-in None Proprietary formats
Cost Free Monthly subscriptions
Built by Former CISO SaaS companies

9 Pre-Built Security Templates

The dependency scanner is one of nine ready-to-run security workflows (plus four general-purpose ones):

🔍
GitHub Dependency Scanner
OSV.dev vulnerability check
🛡️
GDPR Data Access Request
Article 15 requests, end to end
🔐
PII Detection & Redaction
Privacy-preserving pipeline
🚨
Security Incident Response
Triage and severity (NIST)
📋
SOC 2 Control Evidence
Control evidence collection
🏥
HIPAA Patient Access
Right of Access requests
⚖️
EU AI Act Assessment
High-risk classification (Annex III)
📊
ISO 27001 Risk Assessment
Annex A risk scoring
🏭
Critical Infrastructure Defense
IT/OT threat monitoring

All templates include demo mode, TypeScript export, and a visual workflow editor.


Quick Start

Try instantly (no install):

https://www.topflow.dev/builder?template=github-security-scanner&repo=YOUR_USERNAME/YOUR_REPO

Run locally:

git clone https://github.com/csupenn/topflow.git
cd topflow && pnpm install && pnpm dev
# Open http://localhost:3000

Tech Stack

Next.js 15 · React 19 · TypeScript · TailwindCSS v4 · ReactFlow · Vercel AI SDK v5 · shadcn/ui · Zustand

AI providers: OpenAI · Anthropic · Google · Groq


Documentation


Contributing

Security improvements, compliance workflows, new node types, and test coverage are especially welcome. See CONTRIBUTING.md.

Found a vulnerability? Please report it privately; see SECURITY.md.

License: MIT — use, modify, fork, and distribute freely.


Built by Charlie Su · Former CISO · AI Security Advocate
📧 charlie@charliesu.com · 💼 LinkedIn · Issues · Discussions

About

A visual builder for AI workflows with security designed in: SSRF-guarded requests, rate limiting and encrypted BYOK keys. Includes an OSV.dev dependency scanner whose AI report can't change its findings. MIT licensed.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

14 stars

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages