The agents read every diff with full codebase context: data flows, missing auth checks, framework misconfigs. A named researcher verifies. Finding = file:line + PoC, not scanner output.
every PR
reviewed before merge, GitHub and GitLab
file:line + PoC
per finding, verified by a named researcher
+€5,000/yr
flat, part of the standing hunt
What lands as a PR comment: the file, the line, the data flow, and a PoC you can run yourself.
+export async function GET(req: Request, { id }: Props) {
+ const session = await getSession(req)
+ const order = await db.orders.find({ id })
+ return Response.json(order)
+}
session → GET /v1/orders/{id} → find({ id }): no ownership check. Any authenticated customer reads any order, items, addresses, payment references.
poc.sh: enumerates 1001–1010, all return 200
GitHub or GitLab. The agents index the code, build call graphs, read the logic.
Data flows, missing auth checks, race conditions, payment & checkout. Finding with file:line + PoC, inline in the PR.
Triage comments and rules for the parts only your team knows. Fewer false positives after every review.
business logic · injection: SQL, XSS, SSRF, XXE · prompt injection · memory safety · authn & authz · IaC · supply chain · secrets
One review covers all eight. The sample report shows a finding end to end: PoC, fix, retest.
See the sample reportPart of the standing hunt: +€5,000/yr, flat; on the deep audit: +€1,500, one-off. In writing before we start.
SAST matches known rules and lists. We check exploitability: authz flaws that map to no rule, with a data-flow trace and a PoC.
GitHub and GitLab. Findings land as PR comments, fixes as branches.
Repo access and data handling are written into the contract. Details: Trust & security.
Repo access, first reviews, then flat. Or start with the free check.