Enterprise security operating system/Native engine. One graph.

Every finding, traced
from commit to runtime.

SecurityVault runs a native application-security engine and the right open-source scanners for each language, automatically. Results land in one security ontology that links the repository, the commit, the build, the image and the workload, so you fix what is actually reachable in production.

Hostile scanners. Signed decisions. Fail closed by default.
12 languages, native taint analysis45+ scanner adaptersScan in your environment, results to us
app.securityvault.io/operations/command
prod · us-east-1
Security posture · Production
tenant_acme · region_us-east-1 · severity ≥ medium · 24h
live24h
Critical Open
23
−4 · 24h
High Open
194
+12 · 24h
SLA Met
98.4%
target 95
Evidence Sealed
14,206
+842 · 24h
Findings rate · last 24h
events / minute
CRITSSRF in /api/v2/proxysemgrep · prod-edge-72m
HIGHPrivileged container w/o limitstrivy · prod-cluster11m
MEDUnrotated key · stripe-prodgitleaks · history38m
Scanners · active
142 / 156
appsec-unified
monorepo · 12 langs
42s
trivy
prod-cluster · 84/120
1m
semgrep
monorepo · complete
12m
checkov
terraform · 1,204 res
19m
grype
queued · sbom from syft
Lineage · live
observed · derived
14:02:18 · affects sha256:9f2a…c41e · CVE-2026-1041 3 workloads · 1 ingress
14:02:11 · derived sha256:c08b…7a1d · commit 4a9c1ef build #812 · image
14:01:54 · observed sha256:21be…f309 · scan.complete 1,402 → 318 logical

A scanner result is not a finding. It becomes one when you know which commitintroduced it, which image carries it and which workload exposes it. That chain is what SecurityVault computes, and what most tools never build.

i.

One ontology, not six lists.

52 entity types and 32 relationship verbs, frozen and versioned. A finding is a node with edges to packages, images, workloads, identities and controls.

ii.

Native engine plus the best tools.

Our own taint, SCA, IaC, secrets, API, DAST and supply-chain kernels run beside Semgrep, Trivy, Grype, Checkov and the per-language tools, launched automatically.

iii.

Scanners are hostile.

Every tool, including ours, runs in an ephemeral Job with no database, cache, vault or storage credentials. Results enter through one authenticated, signed callback.

iv.

Fail closed. Sign the rest.

A policy error is a deny. Dispositions are human-only with a reason code. Decisions are Ed25519-signed and the audit log is hash-chained.

Engineering principlesArchitecture brief →
The platform

Six modules. One graph.

One platform, one ontology, one trust model. Every module reads and writes the same entities, so a cloud misconfiguration and a vulnerable dependency meet on the same attack path.

01

Scanner orchestration

Point it at a repository or image. The tool plan builds itself from the detected languages and every tool runs in an isolated Kubernetes Job with a per-tool deadline.

45+ adaptersAuto language plan
02

Native AppSec engine

Taint analysis in 12 languages, SCA with reachability, IaC, secrets with history, API discovery, gated DAST and supply-chain checks. Typed evidence on every finding.

appsec-unified7 kernels
03

Finding ontology & lineage

Repository → Commit → Build → Image → Registry → Workload → Ingress. Provenance on every edge, honest gaps, bounded blast radius and computed attack paths.

52 entity types32 verbs
04

Cloud & runtime

CSPM, CIEM, Kubernetes inventory and admission, an eBPF sensor, registry watchers and Image 360. Register your own cluster and scanners run there; only results come back.

AWS · Azure · GCPYour cluster or ours
05

Policy & evidence

Open Policy Agent Rego, authored directly or through a visual builder. Fail-closed evaluation, Ed25519-signed decisions, HMAC-chained audit log, human-only dispositions.

OPA · RegoSigned decisions
06

Remediation & integrations

PR gates and comments, two-way tickets, chat and on-call, SIEM export, SCIM identity. Control mappings for SOC 2, ISO 27001, NIST, PCI DSS, HIPAA, GDPR, NIS2 and DORA.

30+ connectorsBuilt in
Security-first architecture

One operating system. Three trust zones.

Untrusted tools run in a sealed scan band. Results cross into the control plane through one signed callback. Outputs leave through audited connectors. No path bypasses the boundary.

Zone 1 · Scan band

Untrusted
  • Per-scan Kubernetes Jobephemeral
  • Native engine + toolsno platform creds
  • Target credentials onlysplit secret
  • Result adaptertoken + HMAC

Zone 2 · Control plane

SecurityVault
  • Callback ingestionsole write path
  • Finding ontologycode → runtime
  • Policy engineOPA · fail closed
  • Audit ledgerHMAC chain

Zone 3 · Outputs

Enforcement & export
  • PR gates & commentsrate-limited
  • K8s admissioncosign
  • Tickets & chat2-way · HMAC
  • SIEM & auditor portalsigned
Default · fail closed.  A callback without a valid scan token and body signature is rejected. A policy error is a deny.ENFORCED · EVERY SCAN
Early access

Bring a repo and a cluster. Watch the graph connect.

A 30-minute session with a SecurityVault engineer: one scan on your code, one lineage view from commit to workload, one attack path.

Hostile scanners. Signed decisions. Fail closed by default.