Decision support for IT & GRC teams

Can this software run in your environment?

Turn hours of SOC 2 review and source code analysis into a defensible decision in minutes. Can I Run That? (CIRT) gives IT and GRC teams a consistent, structured way to evaluate software before approving it for use in your environment.

Built for IT & GRC teams Thousands of assessments behind the framework Bring your own key option

What Can I Run That? does

CIRT is a decision-making tool, not a developer vulnerability scanner. It helps IT and GRC teams evaluate third-party software before approving it for use in a corporate environment. Two complementary review tracks support that process.

Commercial software & SaaS

SOC 2 & vendor security review

Upload SOC 2 reports, penetration test summaries, security questionnaires, or trust center exports. CIRT performs an AI-assisted review that identifies covered controls, flags gaps and missing information, and surfaces risk signals. Hours of manual review become minutes.

Open source & extensions

Automated source code security review

Submit a Git repository, browser extension, or package. CIRT analyzes the source code for malicious patterns, credential exposure, supply chain risk indicators, and license status. The result is a scored risk report you can act on.

Decision-ready output

A report built for approvals, not developers

Every review produces a structured report with an overall grade, risk score, findings by severity, executive summary, and license status. Approve, reject, or conditionally approve software with documented, defensible reasoning.

Who it's for

Can I Run That? is built for the people who have to make the call on software approvals. If your role involves deciding what software is allowed to run in your environment or your clients' environments, this was built for you.

IT & GRC teams

Make defensible software approval decisions

Evaluating third-party software currently means hours of manual review: reading SOC 2 reports, assessing open source projects, reviewing browser extensions. CIRT structures and accelerates that work. The output is a documented, consistent review you can stand behind.

MSPs

Standardize reviews across every client

Managing software approvals across multiple client environments means doing the same review work repeatedly with inconsistent results. Can I Run That? brings consistency, co-branded reporting, and a repeatable process to every engagement.

Compliance-focused organizations

Document due diligence for auditors and clients

Whether you're meeting SOC 2, ISO 27001, NIST CSF, or client-driven requirements, CIRT produces structured reports. These serve as evidence of a documented, consistent third-party software review process.

How it works

Can I Run That? performs a structured review of either code or security documentation. The result is a report designed to support deployment decisions.

1) Submit software or documentation Paste a Git repo URL, browser extension, or package. You can also upload SOC 2 reports, pentest summaries, and vendor security documents.
2) AI-assisted expert review The platform applies the same review framework used by experienced security professionals across thousands of assessments. It is automated, structured, and consistent.
3) Get a deployment decision report Receive a structured report with risk score, grade, findings by severity, executive summary, and license status. Approve, reject, or escalate with documented reasoning.

What you get back

Every review produces a single, structured report designed to support an approval decision, not a raw scan dump.

Risk grade and score

An overall letter grade (A–F) and numeric risk score give you a single anchor for the approval decision. Calibrated to the signals that matter for business deployment, not developer sprint velocity.

Severity-rated findings

Findings organized by severity (Critical, High, Medium, Low) with enough context to support an approval, conditional approval, or rejection. Documented evidence you can attach to a ticket or audit file.

Executive summary

A plain-language summary of the review you can share with stakeholders, include in a change request, or keep on file as evidence of due diligence.

What it checks

Every review focuses on the signals that matter for deployment decisions. Not raw vulnerability counts, but the indicators that determine whether software or a service is appropriate to run in or connect to a business environment.

Software provenance

Whether the software's origin, release process, and packaging are consistent and trustworthy. A flag here is grounds to pause deployment pending further investigation.

Organizational exposure risk

Patterns in source code that would expose your organization upon installation or use, including credentials, authentication bypass opportunities, and data handling concerns.

Undisclosed behavior

Signs that software may be doing more than what its documentation describes. These findings give you documented grounds for a rejection or escalation decision.

Security risk rating

Identified security weakness patterns rated by severity (Critical to Low). Each finding is documented with enough context to support a conditional approval, rejection, or formal risk acceptance.

License compliance

Whether the license permits commercial and business use, and what obligations apply, such as attribution requirements, copyleft conditions, or usage restrictions.

Vendor controls & gaps

For commercial software and SaaS, CIRT performs an AI-assisted review of SOC 2 reports, penetration tests, and security questionnaires. It surfaces what controls are documented, what is missing, and where the vendor's answers fall short.

Built by a practitioner

Can I Run That? was built by Brian Semrau. He is an information security consultant, digital forensics expert, and expert witness with over 20 years in the industry.

Throughout a career spanning thousands of security assessments, the bottleneck was always the same: the review process was manual, time-consuming, and hard to make consistent. Those assessments included reviewing vendor SOC 2 packages, penetration test reports, and security questionnaires for clients, as well as deep code and forensic reviews on open source tools and browser extensions.

The same risk signals kept appearing. The same framework questions needed answering. The same gaps showed up in vendor documentation. Can I Run That? is the result of applying AI to that repeatable, expert-driven process. It makes the depth of a hands-on practitioner review accessible at scale, without the hours.

Brian Semrau

Sr. Digital Forensic Investigator / Expert Witness

20+ years in information security

Consulting for organizations ranging from sole proprietorships to global enterprises. Services include security programs, breach remediation, digital forensic incident response, and expert witness engagements in civil and criminal cases.

M.S. Cyber Forensics & Security, IIT (4.0 GPA)

Master's degree from Illinois Institute of Technology, also holding a B.S. in Information Technology Administration and Management from IIT (cum laude).

Multiple digital forensics certifications

Board-certified across multiple digital forensics disciplines. Adjunct Faculty teaching Vulnerability Analysis & Ethical Hacking, Computer Forensics, and Advanced Forensics at Triton College.

SANS CTF Winner & Published Researcher

Winner of SANS SEC642 (Advanced Web App Penetration Testing) and SANS SEC540 (DevSecOps) CTF competitions. Published privacy evaluations of browser extensions and endpoint security guides. Guest lecturer at University of Washington.

Pricing

Early access starts at $50/mo (Bring Your Own Key) or $99/mo (all-inclusive). Every plan uses the same AI-powered pipeline and produces the same report output.

See full pricing details

Tier 1

$99 / month

For small teams getting consistent about approvals.

  • 10 repo assessments / month
  • 2 vendor reviews / month
  • Repo size cap (200k LOC*)
  • Standard risk configuration
  • Standard reporting (HTML + PDF)

Tier 3

$799 / month

For MSP-style multi-client use and larger volume.

  • 100 repo assessments / month
  • 50 vendor reviews / month
  • No practical repo size limit (2M LOC*)
  • Multi-client organization support
  • Fully white-label reports
  • API access

Overages

Additional repo assessments or vendor reviews (billed per assessment/review):

  • $10

*Very large repos (LOC = lines of code)

Surcharges apply when a repository substantially exceeds your plan’s LOC (lines of code) cap. Purchased LOC do not expire, and any remaining LOC after the repo's maximum LOC has been exceeded can be used on future scans.

  • 200k additional LOC: $15
  • 500k additional LOC: $37.50
  • 1M additional LOC: $75
  • >2M additional LOC: contact us

Fair use is meant to keep the service healthy for everyone. If you consistently scan very large repos or run heavy scheduled scans across many clients, we'll help you pick the right plan.

Vendor reviews are counted per vendor (not per document). Multiple files can be included in a single review. Re-reviews count toward usage.

FAQ

Quick answers for IT and GRC teams evaluating whether third-party software is appropriate to approve for their environment.

How is Can I Run That? different from Snyk, Dependabot, or other security scanners?

Snyk and Dependabot are built to find CVEs in code your team writes and ships, integrated into CI/CD pipelines. CIRT addresses a different workflow: evaluating whether someone else's software or service should be approved to run in your environment. The question being answered is different: can we deploy or adopt this? The output is different: a risk report with a grade and severity findings. The process fits into a security review or vendor assessment workflow rather than a development pipeline. The two tools serve different steps in the software lifecycle and work well alongside each other.

What types of software can CIRT review?

There are two review tracks. For source-accessible software such as open source repositories, browser extensions, and npm/PyPI packages, CIRT performs an automated code review identifying security findings, malicious patterns, credential exposure, supply chain risk, and license status. For commercial software and SaaS where source isn't available, you can upload vendor security documentation, including SOC 2 reports, penetration test summaries, security questionnaires, and trust center exports. CIRT then returns an AI-assisted analysis of controls, gaps, and unanswered questions.

How does this fit into a SOC 2 or vendor security review process?

CIRT is designed to fit directly into the vendor review step of your existing process. Instead of manually reading through SOC 2 Type II reports and security questionnaires to identify gaps, you upload the documents and receive a structured summary of what's covered, what's missing, and what requires follow-up. That output serves as evidence of a documented, consistent review process, supporting your own SOC 2 compliance, ISO 27001, or client-facing due diligence requirements. It reduces hours of manual review to minutes without replacing human judgment on the final decision.

Who is CIRT built for?

The primary audience is anyone responsible for making software approval decisions. That includes in-house IT and GRC teams doing third-party software and vendor reviews, MSPs managing approvals across multiple client environments, compliance professionals documenting due diligence for auditors, and security consultants performing vendor assessments. If your role involves deciding whether software can be used in a corporate environment, CIRT gives you a structured, documented way to do that.

What does Bring Your Own Key mean?

Bring Your Own Key (BYOK) means you provide your own Anthropic Claude API key. You keep control of usage and spend while still getting the same workflow, scoring, and report output.

Request early access

Can I Run That? was built by a practitioner who has performed thousands of security reviews and knows exactly how much time gets lost to manual, inconsistent processes. If you're an IT or GRC team, MSP, or compliance-focused organization that needs a structured, defensible way to evaluate third-party software before approving it for your environment, we'd love to get you access. Early access is limited so your feedback shapes the product directly.