Every finding, traced
from commit to runtime.
SecurityVault runs a native application-security engine and the right open-source scanners for each language, automatically. Results land in one security ontology that links the repository, the commit, the build, the image and the workload, so you fix what is actually reachable in production.
A scanner result is not a finding. It becomes one when you know which commitintroduced it, which image carries it and which workload exposes it. That chain is what SecurityVault computes, and what most tools never build.
One ontology, not six lists.
52 entity types and 32 relationship verbs, frozen and versioned. A finding is a node with edges to packages, images, workloads, identities and controls.
Native engine plus the best tools.
Our own taint, SCA, IaC, secrets, API, DAST and supply-chain kernels run beside Semgrep, Trivy, Grype, Checkov and the per-language tools, launched automatically.
Scanners are hostile.
Every tool, including ours, runs in an ephemeral Job with no database, cache, vault or storage credentials. Results enter through one authenticated, signed callback.
Fail closed. Sign the rest.
A policy error is a deny. Dispositions are human-only with a reason code. Decisions are Ed25519-signed and the audit log is hash-chained.
Six modules. One graph.
One platform, one ontology, one trust model. Every module reads and writes the same entities, so a cloud misconfiguration and a vulnerable dependency meet on the same attack path.
Scanner orchestration
Point it at a repository or image. The tool plan builds itself from the detected languages and every tool runs in an isolated Kubernetes Job with a per-tool deadline.
Native AppSec engine
Taint analysis in 12 languages, SCA with reachability, IaC, secrets with history, API discovery, gated DAST and supply-chain checks. Typed evidence on every finding.
Finding ontology & lineage
Repository → Commit → Build → Image → Registry → Workload → Ingress. Provenance on every edge, honest gaps, bounded blast radius and computed attack paths.
Cloud & runtime
CSPM, CIEM, Kubernetes inventory and admission, an eBPF sensor, registry watchers and Image 360. Register your own cluster and scanners run there; only results come back.
Policy & evidence
Open Policy Agent Rego, authored directly or through a visual builder. Fail-closed evaluation, Ed25519-signed decisions, HMAC-chained audit log, human-only dispositions.
Remediation & integrations
PR gates and comments, two-way tickets, chat and on-call, SIEM export, SCIM identity. Control mappings for SOC 2, ISO 27001, NIST, PCI DSS, HIPAA, GDPR, NIS2 and DORA.
One operating system. Three trust zones.
Untrusted tools run in a sealed scan band. Results cross into the control plane through one signed callback. Outputs leave through audited connectors. No path bypasses the boundary.
Zone 1 · Scan band
- Per-scan Kubernetes Jobephemeral
- Native engine + toolsno platform creds
- Target credentials onlysplit secret
- Result adaptertoken + HMAC
Zone 2 · Control plane
- Callback ingestionsole write path
- Finding ontologycode → runtime
- Policy engineOPA · fail closed
- Audit ledgerHMAC chain
Zone 3 · Outputs
- PR gates & commentsrate-limited
- K8s admissioncosign
- Tickets & chat2-way · HMAC
- SIEM & auditor portalsigned
Bring a repo and a cluster. Watch the graph connect.
A 30-minute session with a SecurityVault engineer: one scan on your code, one lineage view from commit to workload, one attack path.