diff --git a/Gemfile b/Gemfile
index 47e6fe95f346c69e6bb6e66e0b396a50bc9f0712..01c02b5c8dbbf6d5ec183f69f4e15cc5783a213e 100644
--- a/Gemfile
+++ b/Gemfile
@@ -199,6 +199,7 @@ gem "virtus"
 gem 'addressable'
 
 group :development do
+  gem 'brakeman', require: false
   gem "annotate", "~> 2.6.0.beta2"
   gem "letter_opener"
   gem 'quiet_assets', '~> 1.0.1'
diff --git a/Gemfile.lock b/Gemfile.lock
index 37880c45a29f747913cc455432163c8523d05234..102d1a2887561cfa91741b4e9bfb6ba19cf2b788 100644
--- a/Gemfile.lock
+++ b/Gemfile.lock
@@ -63,6 +63,16 @@ GEM
     bootstrap-sass (3.3.3)
       autoprefixer-rails (>= 5.0.0.1)
       sass (>= 3.2.19)
+    brakeman (3.0.1)
+      erubis (~> 2.6)
+      fastercsv (~> 1.5)
+      haml (>= 3.0, < 5.0)
+      highline (~> 1.6.20)
+      multi_json (~> 1.2)
+      ruby2ruby (~> 2.1.1)
+      ruby_parser (~> 3.5.0)
+      sass (~> 3.0)
+      terminal-table (~> 1.4)
     browser (0.7.2)
     builder (3.2.2)
     byebug (3.2.0)
@@ -154,6 +164,7 @@ GEM
       multipart-post (~> 1.2.0)
     faraday_middleware (0.9.0)
       faraday (>= 0.7.4, < 0.9)
+    fastercsv (1.5.5)
     ffaker (1.22.1)
     ffi (1.9.3)
     fog (1.21.0)
@@ -258,6 +269,7 @@ GEM
       haml (>= 3.1, < 5.0)
       railties (>= 4.0.1)
     hashie (2.1.2)
+    highline (1.6.21)
     hike (1.2.3)
     hipchat (1.4.0)
       httparty
@@ -496,6 +508,11 @@ GEM
       rainbow (>= 1.99.1, < 3.0)
       ruby-progressbar (~> 1.4)
     ruby-progressbar (1.7.1)
+    ruby2ruby (2.1.3)
+      ruby_parser (~> 3.1)
+      sexp_processor (~> 4.0)
+    ruby_parser (3.5.0)
+      sexp_processor (~> 4.1)
     rubyntlm (0.4.0)
     rubypants (0.2.0)
     rugged (0.21.4)
@@ -521,6 +538,7 @@ GEM
     select2-rails (3.5.2)
       thor (~> 0.14)
     settingslogic (2.0.9)
+    sexp_processor (4.4.5)
     shoulda-matchers (2.7.0)
       activesupport (>= 3.0.0)
     sidekiq (3.3.0)
@@ -572,6 +590,7 @@ GEM
     temple (0.6.7)
     term-ansicolor (1.2.2)
       tins (~> 0.8)
+    terminal-table (1.4.5)
     test_after_commit (0.2.2)
     therubyracer (0.12.0)
       libv8 (~> 3.16.14.0)
@@ -651,6 +670,7 @@ DEPENDENCIES
   better_errors
   binding_of_caller
   bootstrap-sass (~> 3.0)
+  brakeman
   browser
   byebug
   cal-heatmap-rails (~> 0.0.1)