This product was not featured by Product Hunt yet. It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).
Ocherfort scans repositories, maps findings to standards, evaluates ship/no-ship gates, and uses AI only to explain evidence. Ocherfort is a local-first security CLI for repositories. It scans code, workflows, release pipelines, and agent configs, maps findings to standards like CWE, OWASP, and NIST, and answers the question teams actually care about.It also includes evidence-based AI for explanation and prioritization, without letting AI invent findings or override policy. Join the beta.
Hi Everyone! I built Ocherfort because most security tools gave me fragments, not decisions.
One tool found secrets. Another found dependency issues. Another checked CI. Another helped explain risk. But none of them gave a clean, local-first workflow that answered: what is wrong, what matters, what maps to standards, and are we actually safe to ship?
That was the idea behind Ocherfort.
I wanted a tool that works directly on a repo, keeps evidence local, stores every run, maps findings to frameworks like CWE, OWASP, and NIST, and adds real ship/no-ship gates instead of just dumping alerts into the terminal.
A big design choice was separating deterministic scanning from AI. The AI in Ocherfort can explain, coach, and prioritize, but it cannot invent findings or silently change the result. That boundary mattered a lot while building it.
As the project evolved, it expanded beyond normal code scanning into workflows, release safety, supply chain risks, and even agentic surfaces like prompts, skills, and MCP configs. Modern repos are bigger than app code, so the scanner had to reflect that reality.
This launch is the start of that vision. If you try it, I’d love feedback on the CLI experience, the gates, the standards coverage, and what security surfaces you want Ocherfort to understand next.
No comment highlights available yet. Please check back later!
About Ocherfort on Product Hunt
“Ship secure code with evidence, not guesswork”
Ocherfort was submitted on Product Hunt and earned 0 upvotes and 1 comments, placing #115 on the daily leaderboard. Ocherfort scans repositories, maps findings to standards, evaluates ship/no-ship gates, and uses AI only to explain evidence. Ocherfort is a local-first security CLI for repositories. It scans code, workflows, release pipelines, and agent configs, maps findings to standards like CWE, OWASP, and NIST, and answers the question teams actually care about.It also includes evidence-based AI for explanation and prioritization, without letting AI invent findings or override policy. Join the beta.
Ocherfort was featured in Open Source (68.8k followers), Developer Tools (519k followers) and Security (2.9k followers) on Product Hunt. Together, these topics include over 104k products, making this a competitive space to launch in.
Who hunted Ocherfort?
Ocherfort was hunted by Abdul Sami. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
Want to see how Ocherfort stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.