Purchasing Guides / Security Finding Triage & Fixes

Security Finding Triage & Fixes

A guide to buying an AI workflow that checks security scanner findings and drafts tested code fixes for your engineers to review.

Yearly running cost

Assuming 2,400 findings a year

By hand
$90K / year
1,200 hours of work
Subscription
$11.8K+ / year
This workflow
$288 / year
Machine usage only; setup, hosting and review are extra.
What should the workflow do with scanner findings?

Fix issues in your code, or also handle vulnerable packages and issue tracking.

Your engineers merge fixes and your security team closes findings. It never merges code, never closes a finding without a recorded verdict and never changes scanner rules.

What is included

Import findings from your code scanner, check each against the surrounding code, record whether it is real, not reachable or a false alarm with the reason, and open a fix pull request with a test for real findings.

Start with the scanners you already run, the repositories in scope, your rules for what must be fixed and a set of past findings your security engineers have already judged. The wider option adds vulnerable package upgrades with a check of what the upgrade changes, issue tracker tickets and recorded reasons for findings that are set aside.

How reliable should verdicts and fixes be?

Set targets for identifying real vulnerabilities and producing fixes your engineers can accept.

How these standards are measured

Test on held-out past findings your security engineers have labelled and on vulnerabilities planted in a copy of your code. A fix counts only when the rescan clears the finding and your tests pass. Calling a real planted vulnerability a false alarm counts as a critical failure.

Targets for your selected standard
What is checkedTarget
Verdicts correctFindings sorted the same way as your security engineer, as real, not reachable or a false alarm, divided by all findings in the test set. A real planted vulnerability called a false alarm is a critical failure.≥85%
Real findings fixedReal findings that get a fix which clears the scanner rescan and passes your tests, divided by all real findings in the test set.≥75%
Fixes mergedFix pull requests your engineers merge without rework, divided by all fix pull requests opened.≥60%
Verdicts with evidenceEvery verdict must cite the scanner rule, the code path and the reason.≥100%

Verdicts and fixes are proposals for your engineers and security team; they are not a security sign-off. People still merge fixes and close findings.

How quickly should a fix or verdict appear?

Choose how soon after a finding arrives the verdict and, for real findings, the fix pull request appear. Your engineers' review time is separate.

Timing details

Time from a new finding to a recorded verdict or opened fix pull request, including reading the code, model calls, running your tests and the rescan, queueing and retries. Long test suites may need agreed limits. Confirm repository size and runner capacity with your provider.

The target applies to at least 95% of agreed test runs, with 4 in progress at a time.

How much do you want to spend per finding?

Set the AI processing budget for checking and fixing each finding.

Cost details

Includes model calls, retries and a shared hosting allocation. Scanner licences, CI minutes, your engineers' time and the calling agent are separate. A finding that needs a second fix attempt is counted again.

Reference machine cost: $0.22 – 0.42 per finding at 200 findings a month. The selected cap is a target to test, not a replacement for this estimate.

Where do you want it to run?

Run it in your cloud or on your own server. Choose whether code may go to an approved AI service.

Data and access details

Runs in a cloud account you control, with access controls and logs.

Only the finding, the related code and your fix rules go to the selected external model, with secret files excluded. Agree access and retention first.

Give it read access to code and permission to open pull requests and comment only. Exclude secret files from what the model reads. Private model only keeps source code on your hardware; the workflow still connects to your own code host and scanners.

How do you want to use it?

Choose where you want to use it. You can select more than one.

Anything else your provider should know?

Optional. Your choices are included automatically.

Common questions

Do I need this if a hosted security fix service already works for us?

Not necessarily. If a hosted service may read your code and fixes your findings well enough, subscribe to it. Buy a workflow when code must stay in your environment, you need a private model or you want to keep the scanners you already run.

Does it replace our scanner?

No. It reads findings from the scanners you already run. It judges and fixes findings; it does not look for new ones.

Can it close findings on its own?

No. It records a verdict with evidence and opens fixes. Your security team closes findings and your engineers merge fixes.

What if a fix breaks something?

Each fix must pass your existing tests and a new test before the pull request opens. Package upgrades with breaking changes are flagged for an engineer instead of fixed.

Download RenX

Get the app.

Install, sign up, and start on your free plan with welcome credit included. No credit card required.

On a platform not listed? Leave your email and we'll notify you when a build is available.