Home / Services / Security Inspect / SAST
Security Inspect / Source code assessmentOnly the code vulnerabilities
you actually need to review.
SAST is a service that finds vulnerabilities by statically analyzing source code. Starting from rule-based detection with Semgrep, AI reads the relevant code, traces where input comes from and where it ends up, and determines whether it is truly exploitable. It also actively looks for authorization gaps and business logic flaws that patterns can't find.
Challenges
Sound familiar?
Too many false positives
You introduced a static analysis tool, but there are so many false positives that nobody looks at the results anymore.
Flaws that patterns can't find
Missing permission checks and business logic flaws can't be found by rule-based analysis alone.
Quality of outsourced code
There's no way to quickly check the security of code delivered by contractors.
Features
SAST key features
01Rule-based first-pass detection
Semgrep security rules deterministically detect issues such as injection and the use of dangerous functions. Style findings are excluded.
02AI traces the data flow
AI reads the code around each finding and its call relationships, follows whether input reaches a dangerous operation without sanitization, and determines whether it is exploitable.
03Three verdicts with evidence
Each finding is judged “Vulnerable”, “Secure (false positive)” or “Uncertain”, with the reasoning shown alongside the relevant code.
04Hunts authorization gaps and business logic flaws
Follows a checklist to look for problems that patterns can't catch, such as IDOR, missing permission checks, authentication bypass and business logic flaws.
05Sensitive data and dangerous operations
Also finds hardcoded credentials and private keys, insecure deserialization, cryptographic misuse and more.
06Easy import
Just upload a zip file or specify a Git repository URL. Private repositories connect through a read-only deploy key.
07Full and quick assessments
Choose a full assessment, which reviews every finding and then actively explores, or a quick assessment, which focuses on critical types to deliver results fast.
08Results as soon as they're found
Findings appear in the console in the order they are found. When the assessment is complete, you can export a PDF report that includes remediation guidance.
AI triage
Not a count of detections,
but the vulnerabilities to fix
Rule-based static analysis misses little, but it also produces many false positives. In SAST, AI reviews every first-pass detection one by one, checking where the input comes from, whether it is sanitized and whether it is reachable before reaching a verdict.
Vulnerable
Attacker-controllable input reaches a dangerous operation without being neutralized, with real impact. Included in the report.
Secure (false positive)
Already neutralized, unreachable, defended by the framework, test code, and so on. Excluded from the report.
Uncertain
Depends on external configuration or runtime conditions and can't be determined from the code alone. Kept, with the reason noted.
Languages & frameworks
Tailored to widely used languages
and frameworks
First-pass detection rules are provided per language and per framework. Rules that understand how each framework is written detect the issues, and AI factors in that framework's defense mechanisms when judging them.
Python
Detects issues with rules that support Django, Flask, FastAPI, SQLAlchemy, Jinja2, boto3 and more.
JavaScript / TypeScript
Detects issues with rules that support Express, React, Angular, NestJS, Sequelize, AWS CDK, JWT libraries and more.
Please note: Java and PHP are covered by AI-driven active exploration and code analysis (first-pass detection rules focus on Python, JavaScript and TypeScript).
Specifications
Scope and delivery
| Languages |
|
|---|---|
| Import |
|
| Assessment types |
|
| Output |
|
| Pricing |
|
Please note: Automated GitHub integration, such as commenting on pull requests, is not currently supported. Vulnerabilities in the libraries your code depends on can be checked with SCA.
Getting started
Getting started
Register your code
Upload a zip, or connect a repository and register a deploy key.
Run an assessment
Choose a full or quick assessment and run it. Findings appear in the order they are found.
Review the results
Review the findings and evidence examined by AI, and move on to fixes.
FAQ
FAQ
Is my code stored?
It is imported into the CyberForces execution environment for the assessment. Please contact us for details on how it is handled.
How is it different from SCA?
SAST finds vulnerabilities in the code you write yourself; SCA finds known vulnerabilities in the OSS and libraries you use. Combining both gives broad coverage of your application's weaknesses.
Works well with
SAST — details and demo requests
Our team will explain deployment options and pricing for your environment.