SAST engine reaches OWASP Benchmark 0.994
100% precision, 99.4% recall on the public OWASP Benchmark - the false-positive discrimination bar that keeps findings trustworthy enough to gate on.
Release notes for a platform that runs in your environment. Filter by discipline or change type; subscribe by RSS. Semantic versioning, one bump per change, an audit trail on every ship.
Most changelogs are marketing. This one is change management: versioned, attributable and verifiable, because your auditors will ask.
The version running in your environment is always visible in-product. No silent changes.
Every release ties into your evidence pack - what shipped, and when - so change management has a paper trail.
An Ed25519-signed license and images you pull and run. You upgrade on your schedule; nothing auto-updates behind your back.
Enterprise customers get an advisory feed for issues that affect a self-hosted deployment, ahead of the public notes.
100% precision, 99.4% recall on the public OWASP Benchmark - the false-positive discrimination bar that keeps findings trustworthy enough to gate on.
Let's Encrypt termination with auto-renew on the self-hosted ingress - no manual cert rotation.
Hard CPU / memory limits so AI analysis can never stall the host it runs on.
Live host resource metrics surfaced on the admin Health page for self-hosted operators.
New dynamic detectors held to the reachable-vs-confirmed severity discipline, so a probe is never over-claimed as an exploit.
Assign an owner and track the remediation SLA clock per finding, from first-seen.
More evidence and reachability context attached to each finding to speed triage.
Sensitive values are masked in every export, report and evidence bundle by default.
Protects the API and downstream scanners under multi-team load.
A first-class Helm chart for running the platform on your own cluster.
Consistent depth across the /code disciplines so posture is comparable app-to-app.
A control-to-sub-control hierarchy that maps one remediation to every framework it satisfies.
Export a signed evidence pack recording who attested what, and when - built for auditors.
Flags known-malicious and end-of-life dependencies alongside known CVEs.
Export the enforcement policy as OPA / Rego to run it anywhere in your pipeline.
A formal review-and-sign path for governance teams, with rule-to-compliance mapping, scope filters and search.
The full CI/CD gate reaches general availability - proven on a real repo, not a demo.
One agent (test / monitor / upload / container) that auto-detects GitHub, GitLab and Jenkins.
PRs gate on new-vs-default-branch only; each microservice repo maps to its own application in one posture.
A commit status check plus an update-or-create PR / MR comment, wired for required-check branch protection.
Two-factor authentication for local accounts, with recoverable backup codes.
Personal and service tokens with least-privilege scopes and full revocation.
Role-based access control and a secure onboarding flow, safe by default.
Because the platform is self-hosted, a security fix only helps once you upgrade. Enterprise customers get a private advisory feed - affected versions, severity and the exact remediation step - so you can act on your own maintenance window, not ours.
In-product, the running version and its release notes are always one click away on the admin page - so operators never guess what they are on.
From discovery to a proven attack chain. A PoC in your own environment.