perch vs Mindgard

Side-by-side comparison of features, pricing, and ratings

Analysis reviewed Live tool data as of 2026-09-29
Cross-checked through our multi-step verification ·
Saved

At a glance

DimensionperchMindgard
CategorySemantic code linter for repo-defined rulesAutomated AI red teaming / runtime AI security platform
PricingFree; install via npm install -g @lakeday/perchContact sales (no self-serve, no published per-seat)
Core workflowperch scan / perch check against your source treeDiscover → Recon → Attack → Defend against models, agents, tools
Where rules liveYour own perch.yaml rules written with --ensure plain-language guaranteesAttack library of 150+ publicly disclosed AI vulnerabilities
IntegrationsGitHub Actions, Claude Code, Codex, CursorBurp Suite, GitHub
CI/CD gateFails CI with exit code 3; perch scan --since origin/main scans only changed filesShifts AI security into CI/CD via GitHub (best_for: AI eng teams)

These two do not compete for the same budget, so there is no head-to-head winner. If your problem is adversarial risk in production AI agents — shadow AI, guardrail bypasses, exploit-backed findings your GRC team can audit — Mindgard is built for exactly that, and you will pay a contact-sales enterprise price for it. If your problem is code-level policy enforcement inside a repo (off-by-one loops, MD5-hashed tokens, unhandled nulls, or catching what Claude Code/Codex/Cursor wrote), Perch is free, runs from your terminal or GitHub Actions, and expects you to write your own perch.yaml rules. Pick by problem, not by category: agent attack surface vs source-tree defects.

perch
perch

Perch is a semantic code linter that turns your team's review rules into committed, executable policy checks powered by Jev.

Visit Website
Mindgard
Mindgard

Automated AI red teaming that discovers and exploits vulnerabilities in production AI agents and models

Visit Website
Pricing
Free
Contact Sales
Plans
Free (MIT license); per-scan Jev analysis billed separately
—
Popularity
1 views
7.4k views
Skill Level
Intermediate
Advanced
API Available
Platforms
CLI
WebCLIAPI
Categories
🔎 Code Review & Quality🔐 Application & Code Security
🛡️ AI Governance & Guardrails🔐 Application & Code Security
Features
Run semantic scans across a source tree with `perch scan` for defects and security issues
Author custom lints in perch.yaml with plain-language guarantees via `--ensure`
Scope rules by unit with `--each method` or `--each file`
Limit rules to path globs with `--where "src/**/*.ts"`
Report each finding with rule ID, file:line, severity, confidence percentage, and method name
Filter a scan to one rule with `perch scan --filter rule=<name>`
Test a rule against a specific symbol with `perch check <file>::<method> --rules <name>`
Detect off-by-one loop errors, weak cryptography (MD5-hashed tokens), and unhandled nulls
Score findings probabilistically (e.g. 91%, 93%, 72%) rather than pass/fail
Scan only changed files with surrounding context using `perch scan --since origin/main`
Fail CI jobs on breaking findings with exit code 3
Store findings locally in the .perch directory
Apply rules to non-code files such as Markdown documentation with `--each file`
Install the Perch skill for Claude Code, Codex, or Cursor so agents check their own fixes
Report scan summaries with finding count, methods touched, and estimated cost
Automated AI red teaming with continuous attack simulation against agents and models
Agent-native reconnaissance mapping models, agents, tools, and behaviors before attack execution
AI Discovery & Recon for shadow AI detection and AI-BOM generation
Automated AI infrastructure crawling and attack surface enumeration
Runtime AI Protection & Response that identifies and reacts to attacks in real time
Offensive security model scanning for exploitable risk
Psychometric agent profiling and fingerprinting
Agent profile and guardrail busting evaluation
Automated AI agent hardening and defense audit
AI risk compliance reporting for GRC workflows
AI Agent Eval & Security Scanning
Attack library built on 150+ publicly disclosed AI vulnerabilities
CI/CD pipeline integration for continuous AI security testing
Burp Suite integration for existing security workflows
API access for embedding AI security tests in custom tooling
Integrations
GitHub Actions
Claude Code
Codex
Cursor
Burp Suite
GitHub

What real users say: perch vs Mindgard

Not marketing copy and not our opinion — a structured sweep of public discussion (reviews, forums, communities and video comments), showing what people praise and what they complain about for each tool.

perch

70 mentions across 6 sources · 14% positive — critical (weighted across 6 sources)

Reddit, Hacker News, YouTube, Product Hunt, GitHub, Lemmy

What users praise

  • • Free and globally installed via npm as @lakeday/perch — zero cost to try.
  • • Natural-language rules in perch.yaml let you encode team conventions as reviewable code.
  • • Findings include rule ID, file:line, severity, confidence percentage, and enclosing method.
  • • Per-finding confidence scoring avoids binary pass/fail and reduces false-positive fatigue.

What frustrates them

  • • Almost no independent user reviews or testimonials exist for the actual linter.
  • • Open language-filtering bug means shipped scans may flag irrelevant vulnerability classes.
  • • No listed integrations with CI/CD, editors, or Slack — everything is manual CLI wiring.
  • • Name collision with Google Perch and a board game makes community support hard to find.

Researched Sep 26, 2026

Mindgard

46 mentions across 3 sources · 48% positive — mixed (weighted across 2 sources)

Hacker News, YouTube, Lemmy

What users praise

  • • Research bench with 150+ public disclosures gives Mindgard credible real-world attack knowledge
  • • Agent-native reconnaissance that maps models, tools and data flows before firing attacks
  • • Named disclosures against Cursor, ChatGPT, Claude and Grok demonstrate practical exploit skill
  • • Burp Suite and GitHub integrations fit existing AppSec workflows rather than replacing them

What frustrates them

  • • Community threads dispute whether some Mindgard findings qualify as real vulnerabilities
  • • Almost no public reviews of the actual platform — only of its vulnerability research
  • • Pricing is entirely 'contact us', blocking any transparent cost comparison
  • • HN commenters questioned Mindgard's authority to label findings as eerie or exploitable

Researched Sep 29, 2026

Feature-by-feature

The capabilities barely overlap. Mindgard operates outside-in on AI systems: agent-native reconnaissance maps models, agents, tools and behaviors before any attack runs, then executes simulated attacks drawn from a library of 150+ publicly disclosed AI vulnerabilities. It adds AI Discovery & Recon for shadow AI and AI-BOM generation, infrastructure crawling for attack-surface enumeration, psychometric agent profiling and fingerprinting, guardrail-busting evaluation, automated agent hardening/defense audits, runtime protection that reacts to attacks in real time, and GRC-ready compliance reporting. It plugs into Burp Suite and GitHub.

Perch works inside-out on source code. You run perch scan across a tree and get findings with rule ID, file:line, severity, a confidence percentage (e.g. 91%, 78%), and the enclosing method. Rules are yours, authored in perch.yaml with plain-language --ensure guarantees, scoped by --each method or --each file and by globs like --where "src/**/*.ts". You can filter to one rule (--filter rule=<name>), test a rule against a specific symbol (perch check <file>::<method> --rules <name>), scan only changed files with --since origin/main, and fail builds with exit code 3. Documented detections include off-by-one loop errors, weak cryptography such as MD5-hashed tokens, and unhandled nulls. It integrates with GitHub Actions and the AI coding agents Claude Code, Codex, and Cursor — but it is overkill as a secret scanner and underpowered as an AI red-teaming tool. One finds exploitable AI behavior; the other finds behavioral defects in your own repository.

Pricing compared

Perch is straightforward: it is free. You install it with npm install -g @lakeday/perch, commit a perch.yaml, and store findings locally in the .perch directory. There is no hosted dashboard, no per-seat meter, and no org-wide analytics tier — meaning no vendor bill, but also no support contract, no REST API or SDK for programmatic triggering, and no multi-user policy management. The real cost is your engineers' time spent writing and maintaining rules; with no pre-built rule pack, payoff depends on your team actually authoring lints that encode project-specific behavior.

Mindgard is the opposite shape: pricing_type is contact, with no self-serve signup and no published per-seat price at checkout, and the source list explicitly flags that anyone wanting instant self-serve pricing is not a fit. You are buying an enterprise engagement — continuous red teaming, runtime protection, compliance reporting, and an offensive-AI-capable vendor relationship. Mindgard's own positioning warns off small teams on tight budgets who could run open-source Garak or PyRIT, and the August 2026 news that Mindgard raised a $30M Series A signals further platform investment and enterprise expansion rather than a cheap self-serve tier. If budget is your binding constraint, Perch costs nothing and Mindgard costs a procurement cycle; if auditable, exploit-backed AI risk evidence is the requirement, free tooling will not produce it.

Who should pick which

  • Security team defending production AI agents
    Pick: Mindgard

    Continuous recon-first red teaming, runtime response, and psychometric agent profiling target exactly the attack surface these teams own.

  • GRC / compliance lead needing AI risk evidence
    Pick: Mindgard

    AI risk compliance reporting and guardrail-busting evaluation produce auditable findings, whereas Perch reports code findings only.

  • Enterprise mapping shadow AI and AI-BOM
    Pick: Mindgard

    AI Discovery & Recon plus infrastructure crawling are purpose-built for enumerating unknown models, agents, and tools across an org.

  • Small eng team gating AI-written code in CI
    Pick: perch

    Free, GitHub Actions and exit-code-3 gating, plus Claude Code / Codex / Cursor integrations, catch repo-specific defects before merge.

  • Solo developer or tight-budget team
    Pick: perch

    Mindgard explicitly is not for buyers needing self-serve pricing or tight budgets; Perch installs via npm and costs nothing.

Frequently Asked Questions

perch vs Mindgard: which should you choose?

These two do not compete for the same budget, so there is no head-to-head winner. If your problem is adversarial risk in production AI agents — shadow AI, guardrail bypasses, exploit-backed findings your GRC team can audit — Mindgard is built for exactly that, and you will pay a contact-sales enterprise price for it. If your problem is code-level policy enforcement inside a repo (off-by-one loops, MD5-hashed tokens, unhandled nulls, or catching what Claude Code/Codex/Cursor wrote), Perch is free, runs from your terminal or GitHub Actions, and expects you to write your own perch.yaml rules. Pick by problem, not by category: agent attack surface vs source-tree defects.

Could one team eventually need both?

Yes, but as separate purchases. A company shipping AI agents might use Perch for code-level guarantees in its repository and Mindgard for adversarial testing and runtime defense of those agents — different owners, different budgets, no overlap in output.

Does Mindgard lint my source code or write rules for my repo?

No. Nothing in the data shows source-tree linting or custom rule authoring; Mindgard's outputs are attack findings, AI-BOMs, guardrail evaluations, and compliance reports. Repository policy enforcement is Perch's job, via perch.yaml.

Can Perch test my AI agent's security posture?

No. Perch scans Python and TypeScript source for defects like off-by-one loops, weak cryptography, and unhandled nulls. It has no recon, attack simulation, or runtime defense capability — that is Mindgard's domain.

How do I evaluate Mindgard's cost before talking to sales?

You cannot from public data — pricing is contact-only with no published per-seat rate and no self-serve checkout. Expect a scoping call; Mindgard's own guidance says instant signup and published pricing are not what it offers.

What does Perch cost once my team scales?

As described, nothing — it is free, findings stay local in .perch, and there is no per-seat tier. The trade-off is no hosted dashboard, no multi-user policy management, and no documented REST API or SDK.

More perch or Mindgard comparisons

Explore each tool further

Browse these categories

Still deciding? Get the weekly AI tools brief

One email a week — new tools, honest comparisons, no spam.

Last reviewed: September 26, 2026