Backed and supported by





Rijksoverheid
Why now
Ops, finance, and marketing are already building with AI.
Your people are already building with AI, and apps reach production before you, security, or compliance know they exist. The answer is not to slow anyone down. It is to see the whole landscape, know which apps actually carry risk, and put guardrails only where they earn their place.

Overview first
Portfolio insights across every app in your organization

NEKOD - Portfolio Overview
Portfolio overview
87 apps · 6 teams
- Coverage
- 96%
- In prod
- 72/87
- Waiting
- 12
Scope
Status, owner, and data
- 72Auto-deployed in productionIn production
- 12Waiting approvalWaiting approval
- 3Information requiredInfo required
In scope
4 apps
| Status | App | Owner | Data |
|---|---|---|---|
| Waiting approval | Refunds consoleWaiting approval | Owned by Maya Chen | Sensitive · Payment data |
| Info required | Partner portalInfo required | Owned by Luis Ortega | Sensitive · Personal data |
| In production | Expense botIn production | Owned by Priya Shah | Internal only |
| Info required | Onboarding kitInfo required | Owned by Tom Hale | Sensitive · Employee PII |
Cost of blind spots
More visibility in production. Less time chasing shadow apps
Without governance
Apps reach production one at a time, and nobody holds the whole picture.

With NEKOD
One view of the whole portfolio, sorted by real risk, and kept current on its own.
What you get
Outcomes leadership can measure.
- One view of every AI-built app in production
- Apps sorted by real risk, so most of the portfolio runs light
- Guardrails and reviews that attach automatically
- Evidence you can hand to risk, audit, or the board
How engagements work
Enable, Discover, Govern, Monitor
In that order. Governance lands when your builders are already on side, so enablement comes first and oversight follows the work rather than blocking it.


See where your organization stands. Free.
NEKOD - Maturity Score
Org maturity score
Recognized
You see the apps. Rules and ownership are catching up.
18
/ 36 pts
Levels
12 Q · 0–3 pts each
- 1Experimental0–11
- 2Recognized12–23You are here
- 3Innovating24–36
How to reach Innovating
- Governance. Name an owner for every AI-built app.
- Training. Onboard builders on secure patterns.
- Data security. Classify data each app touches.
Backed and supported by





Rijksoverheid
Trusted by organizations
Used by top teams worldwide
I got hacked. That's a good thing. At Megathon, a team chained 50+ AI skills on Kali Linux and attacked every startup in the hackathon. They found serious exploits, even at companies positioning themselves as cybersecurity. They found nothing on DoneThat. Running NEKOD to continuously scan my code was enough to withstand this one.
Christoph Hartmann
Founder, DoneThat

Student founders ship fast with AI, but demo day is not when you want to discover security gaps. NEKOD gives them a clear readiness check and a fix list they can act on. I recommend every startup in our network run it before they launch.
Bram Kuijken
Founder of Master Challenge

If you're building with AI tools, spend 10 minutes on NEKOD before your next launch. It's more thorough than a checklist, with practical fixes for every finding. We shipped upgrades on Shareloc straight from the scan.
Umut Aykut Celik
Co-Founder, Shareloc


PRICING
Clear tiers. Continuous cover.
Community lets builders start free. Solopreneurs and Startups deepen control. Startups begins with a Tech Audit so we only take on stacks we can stand behind.
Community
Solopreneurs
For solo builders running one AI-built app: scan, regress, and release with control.
- 1 user · 1 app included
- Expanded controls beyond Community
- Repo scanning & prioritized fixes
- Continuous release testing
- Functional regression testing
- Additional app €49 / mo
Startups
Premium team governance: multi-app release control after we know your stack.
- Multiple users · up to 5 apps
- Everything in Solopreneurs, for the team
- Continuous release testing across apps
- Engineering support
- Additional app €99 / mo

Enterprise
For regulated organisations governing internal AI-built apps at scale
- Unlimited apps · portfolio governance
- Everything in Startups, at org scale
- Portfolio continuous release testing
- Policy-driven release management
- 200+ controls & custom controls
- SSO & audit trails for regulators
- On-prem / separate DB options
- Dedicated engineering support
Good to know
Frequently Asked Questions
NEKOD is the governance layer for AI-built and agentic apps, not a commodity dev tool. You connect your stack, run readiness checks across security, data, access, and compliance, then get a clear findings report with what to fix next. Community lets builders start with 10 basic controls. Solopreneurs and Startups deepen control as you scale.
Community is €0 forever: 1 app, repo connected, 10 basic controls, and a full findings report. Solopreneurs is €129/month for 1 user and 1 app included, with additional apps at €49/month. Startups is €499 per app per month for multiple users, up to 5 apps, with additional apps at €99/month, and requires a Tech Audit first. Enterprise is custom for regulated organisations. Talk to sales for Enterprise.
Startups is premium team governance. We need a senior engineer baseline of your code, infrastructure, and environments before continuous coverage, so we only commit to what we can stand behind. Book a Tech Audit first; then we unlock Startups for the audited scope.
Stay on Community while you explore findings with 10 basic controls. Move to Solopreneurs (€129/mo) when you are the sole builder on one app and need a deeper control set and a clearer fix path beyond the Community baseline.
You review prioritized findings and remediation guidance in the app. Apply fixes yourself, re-run readiness checks, or engage NEKOD for hands-on support on Startups and Enterprise. Continuous governance keeps the assessment current as you keep building.
We check for GDPR readiness, EU AI Act classification, and alignment with ISO 27001. For regulated industries we also cover DORA (financial services), PCI-DSS (payments), and NIS2. Each run includes a compliance map showing where your app stands.
Yes. MVPs often handle real user data from day one, so governance applies immediately. Catching access gaps, hard-coded secrets, and missing policies before launch is cheaper than fixing them in production. Start on Community at no cost.
Neither. Pen testing simulates external attacks. Monitoring watches runtime health. NEKOD sits in application security and governance: who can release, what must be true before each release, and how builders fix issues themselves. For AI-built apps, that day-to-day governance is what most teams actually need.
No. We keep assessment outputs (findings, scores, scope, metadata). The full repo lives on disk only temporarily during a run.
Yes. You choose "Only select repositories" at install time.
Not during a normal readiness check. Fix PRs or hands-on remediation are separate, opt-in engagements.
Only your account, and your organisation if you are on a team, Startups, or Enterprise plan. We treat findings as confidential.
Primarily EU (Netherlands). Some subprocessors may process in the US with appropriate safeguards. See our Privacy Policy and subprocessors list.
Revoke the NEKOD GitHub App from GitHub, or remove specific repos from the installation.
Leadership visibility
Enable speed. Keep control. Prove the ROI.
See every AI-built app across the org. Sort by real risk. Steer without slowing builders down.


