
AI-Powered Code Audit
Built for OSS Maintainers
Takumi blends AI dynamic + static analysis with a world-class OSS record—including contributions to Next.js and Vim—to find logic bugs and broken auth with industry-low false positives.
We’re committed to supporting OSS maintainers, as we’ve always done.
RESEARCH ACHIEVEMENTS
Over 10 Zero-Days Discovered
in Just One Week
- CVE-2025-29768
potential data loss with zip.vim and special crafted zip files
vim/vim
- CVE-2025-30218
x-middleware-subrequest-id may be leaked to external hosts
vercel/next.js
- CVE-2025-31483
Stored XSS in Miniflux Media Proxy due to improper Content-Security-Policy configuration
miniflux/v2
- CVE-2025-32391
XSS possibility through malicious SVG uploads
hedgedoc/hedgedoc
- CVE-2025-58746
A malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions
VolkovLabs/business-links
- CVE-2025-59152
X-Forwarded-For Header Spoofing Bypasses Litestar Rate Limiting
litestar-org/litestar
- CVE-2025-11001
ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
7-Zip
- CVE-2025-11002
ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
7-Zip
- ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
7-Zip
- ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
7-Zip
- X-Forwarded-For Header Spoofing Bypasses Litestar Rate Limiting
litestar-org/litestar
- A malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions
VolkovLabs/business-links
- XSS possibility through malicious SVG uploads
hedgedoc/hedgedoc
- Stored XSS in Miniflux Media Proxy due to improper Content-Security-Policy configuration
miniflux/v2
- x-middleware-subrequest-id may be leaked to external hosts
vercel/next.js
- potential data loss with zip.vim and special crafted zip files
vim/vim
In our internal research preview, three human researchers — with Takumi as their assistant — discovered over 10 zero-day vulnerabilities in just one week.
Born to Find Code Vulnerabilities At Scale
Logical Vulnerabilities Demystified
Takumi uncovers code vulnerabilities your SAST tools miss.
Powered by the latest AI models (like Claude Sonnet), it understands both business logic and code semantics.
Our internal research using real customer applications has identified logical bugs, including improper access controls.





Takumi works without you.
That's why you scale.
Takumi can operate 24/7 based on a schedule. You can schedule regularly occurring security reviews to stay up to date and one shot tasks for the after-hours.
COMPARISON
Why a Security-Focused Agent?
Takumi doesn't provide instant answers. By thinking autonomously for longer than other AI agents, it achieves both a remarkably high detection rate and a low false-positive rate.


For detailed results and our full competitive analysis, please see the benchmark report.
Takumi Cloned Our Human Researchers with 100+ Public CVEs.
Our team has improved global software security by reporting vulnerabilities in widely used applications. These real-world experiences helped shape Takumi into a practical, production-ready cybersecurity AI agent.
Meet the Experts
RyotaK is a security researcher known for his various groundbreaking cybersecurity research. His series of work has revealed critical vulnerabilities of cloud service providers including GitHub, Cloudflare, and other essential engineering platforms such as Homebrew and PyPI. He’s also known for participating in various live hacking events, winning multiple awards, and reporting vulnerabilities to many leading companies such as Google, Cloudflare, GitHub, Salesforce, and Microsoft.
Ryota Shiga is a well-versed security expert. He has revealed 15 critical vulnerabilities for the Linux Kernel and VMM (KVM/VirtualBox) during the 18 months of his research at GMO Flatt Security, all while directing over 100 web penetration testing projects, proving not only his extensive security knowledge but his leadership skills as well. He has also won a prize in Pwn2Own 2021 for reporting a privilege escalation in Ubuntu.
Takashi Yoneuchi is one of the leaders of the cloud and application security industry in Japan with over 7 years of experience educating and motivating people on this topic. He is the author of "Web Browser Security" published in 2021, and more, with thousands of Japanese readers. He led Team Asia at the International Cybersecurity Challenge 2023 as Head Captain. He is also a member of the review board for CODE BLUE, the largest cybersecurity conference in Japan.
Shuta Ide is an offensive security specialist focusing on web applications, who has proven his elite skills by securing numerous first-place victories in CTF competitions, including SECCON CTF (domestic) in 2022 and 2024, the Japan Ministry of Defense CTF in 2021 and 2025, pbctf 2020, and IERAE CTF 2024.
PRICING
Choose a plan that's right for you
For OSS Projects
OSS
We’re committed to supporting OSS maintainers, as we’ve always done.
Free
Some in Team, plus:
Usage
●
Unlimited seats
●
Monthly ACUs
Additional Condition
●
Takumi Badge in README.md
●
Evaluation based on your project docs
We can only support a limited number of projects. Priority will be given to those with supply chain security impact.
For Teams
Team
Like hiring an awesome teammate with security expertise.
$500
/ month*
Includes:
Core capabilities of Takumi:
●
Talk in your Slack workspace
●
Code review via GitHub App
Usage
●
Unlimited seats
●
Monthly ACUs
*Billed by JPY; $500 is the approx value, given the recent rate
For More Powerful Teams
Enterprise
Like hiring a more scalable and trusted team — not just one engineer.
Custom pricing
Everything in Team, plus:
Extended capabilities of Takumi:
●
Priority for newer AI models
●
More tool integration for Takumi
Security & support
●
Dedicated account team
●
Custom terms (if necessary)
Coming Late September 2025
Fully-Autonomous
Blackbox & Graybox
Web Pentesting
Takumi will deliver human-level blackbox/graybox pentesting.
High-quality assessments with just a URL, no source code required.
With source code, unlock even higher detection rates and lower noise.
FAQs
Does Takumi use source codes for AI model training?
No. Takumi does not use any connected source code to train AI models.
Your code is never used to improve the model. We are committed to keeping customer data private and isolated.
Is Takumi only for security engineers?
Not at all. Takumi is designed to support developers and product teams as well, especially when a dedicated security team is not in place.
What kind of tasks can Takumi actually handle?
Takumi can review code for logical vulnerabilities, assess risks from recent changes, summarize findings, and help with security design discussions — all within your Slack or GitHub workflow.
Can Takumi run in an air-gapped or self-hosted environment?
Not at this time. Early access is offered as a managed SaaS service.
Can multiple team members use Takumi at once?
Yes. All plans include unlimited seats, so your entire team can interact with Takumi.
Does Takumi integrate with Jira, Teams, or other tools?
Early access supports Slack and GitHub. Other integrations are planned.
I'm an OSS maintainer — how do I apply for the OSS plan?
Just let us know in the waitlist form, and include a link and short description of your project.
How do you set up Takumi for Slack?
Please take a look at our user guide:
https://shisho.dev/docs/g/getting-started/takumi-the-ai-engineer/
Are there any concerns regarding the responses given by Takumi?
Information outputted by an LLM may be incomplete or inaccurate, which may cause misunderstandings to the user. When making decisions based on the LLM output, ensure that you utilize your best judgement.
Let's start by talking with Takumi.