Home / Services / Security Inspect / SAST

Security Inspect / Source code assessment

Only the code vulnerabilities
you actually need to review.

SAST is a service that finds vulnerabilities by statically analyzing source code. Starting from rule-based detection with Semgrep, AI reads the relevant code, traces where input comes from and where it ends up, and determines whether it is truly exploitable. It also actively looks for authorization gaps and business logic flaws that patterns can't find.

Challenges

Sound familiar?

Too many false positives

You introduced a static analysis tool, but there are so many false positives that nobody looks at the results anymore.

Flaws that patterns can't find

Missing permission checks and business logic flaws can't be found by rule-based analysis alone.

Quality of outsourced code

There's no way to quickly check the security of code delivered by contractors.

Features

SAST key features

01Rule-based first-pass detection

Semgrep security rules deterministically detect issues such as injection and the use of dangerous functions. Style findings are excluded.

02AI traces the data flow

AI reads the code around each finding and its call relationships, follows whether input reaches a dangerous operation without sanitization, and determines whether it is exploitable.

03Three verdicts with evidence

Each finding is judged “Vulnerable”, “Secure (false positive)” or “Uncertain”, with the reasoning shown alongside the relevant code.

04Hunts authorization gaps and business logic flaws

Follows a checklist to look for problems that patterns can't catch, such as IDOR, missing permission checks, authentication bypass and business logic flaws.

05Sensitive data and dangerous operations

Also finds hardcoded credentials and private keys, insecure deserialization, cryptographic misuse and more.

06Easy import

Just upload a zip file or specify a Git repository URL. Private repositories connect through a read-only deploy key.

07Full and quick assessments

Choose a full assessment, which reviews every finding and then actively explores, or a quick assessment, which focuses on critical types to deliver results fast.

08Results as soon as they're found

Findings appear in the console in the order they are found. When the assessment is complete, you can export a PDF report that includes remediation guidance.

AI triage

Not a count of detections,
but the vulnerabilities to fix

Rule-based static analysis misses little, but it also produces many false positives. In SAST, AI reviews every first-pass detection one by one, checking where the input comes from, whether it is sanitized and whether it is reachable before reaching a verdict.

VULNERABLE

Vulnerable

Attacker-controllable input reaches a dangerous operation without being neutralized, with real impact. Included in the report.

SECURE

Secure (false positive)

Already neutralized, unreachable, defended by the framework, test code, and so on. Excluded from the report.

UNCERTAIN

Uncertain

Depends on external configuration or runtime conditions and can't be determined from the code alone. Kept, with the reason noted.

Languages & frameworks

Tailored to widely used languages
and frameworks

First-pass detection rules are provided per language and per framework. Rules that understand how each framework is written detect the issues, and AI factors in that framework's defense mechanisms when judging them.

PYTHON

Python

Detects issues with rules that support Django, Flask, FastAPI, SQLAlchemy, Jinja2, boto3 and more.

JS / TS

JavaScript / TypeScript

Detects issues with rules that support Express, React, Angular, NestJS, Sequelize, AWS CDK, JWT libraries and more.

Please note: Java and PHP are covered by AI-driven active exploration and code analysis (first-pass detection rules focus on Python, JavaScript and TypeScript).

Specifications

Scope and delivery

Languages
  • Primarily Python / JavaScript / TypeScript
  • Java / PHP via AI code analysis
Import
  • Zip upload
  • Git repository (read-only deploy key for private repositories)
Assessment types
  • Full assessment (review of all findings + active exploration)
  • Quick assessment (review focused on critical types)
Output
  • Verdict, evidence and remediation guidance per finding
  • PDF report
Pricing
  • Monthly fee based on the number of lines of code monitored

Please note: Automated GitHub integration, such as commenting on pull requests, is not currently supported. Vulnerabilities in the libraries your code depends on can be checked with SCA.

Getting started

Getting started

  1. Register your code

    Upload a zip, or connect a repository and register a deploy key.

  2. Run an assessment

    Choose a full or quick assessment and run it. Findings appear in the order they are found.

  3. Review the results

    Review the findings and evidence examined by AI, and move on to fixes.

FAQ

FAQ

Is my code stored?

It is imported into the CyberForces execution environment for the assessment. Please contact us for details on how it is handled.

How is it different from SCA?

SAST finds vulnerabilities in the code you write yourself; SCA finds known vulnerabilities in the OSS and libraries you use. Combining both gives broad coverage of your application's weaknesses.

Works well with

SAST — details and demo requests

Our team will explain deployment options and pricing for your environment.