1. Home
  2. Products
  3. DSO

Enterprise Products · Closed source

DSO

Scheduled code scans, AI pentests, and fixes you approve.

scanners and AI agents on one platform
8
to first code-scan results
~5 min
line cap on every AI fix, re-scanned before review
400
seats and repositories on every plan
Unlimited

Overview

DSO is a continuous application security platform. It scans your repositories with SAST, SCA, IaC and secret scanners on a schedule you set, attacks your running apps with agentic pentests once you have proven you own them, uses AI to decide which findings are actually exploitable, and proposes fixes as pull requests. A person approves every AI verdict and every fix. Delivered as SaaS, or on-premises under a subscription or perpetual licence.

How it works

From setup to enforcement

  1. Step 01

    Find

    SAST, SCA, IaC and secret scanners run on your schedule, per repository or team, in your timezone. Scans run outside your CI, so they never block a merge, and unchanged commits are skipped.

  2. Step 02

    Triage

    AI decides whether each finding is exploitable, shows the reachable input and the missing control, and gives a confidence score. A person approves or rejects every verdict.

  3. Step 03

    Fix

    An AI patch must pass a re-scan by the scanner that found the issue, then waits for you as a pull request or diff. Patches that add a secret or change more than 400 lines are refused.

  4. Step 04

    Pentest the running app

    Add a domain or IP, prove you own it with a DNS TXT record or a file, and an agent runs recon, fuzzing and injection tests. Every finding comes with a proof of concept, traced to its source line when you connect code.

Features

Key features

01

SAST

Risky patterns in your source code. Free plan.

02

SCA with reachability

Vulnerable open-source packages, and which of them your code actually calls, with CVEs ranked by exploitability. Free plan.

03

IaC scanning

Misconfigurations in Terraform, Kubernetes and more. Free plan.

04

Secret scanning

Leaked credentials in your repositories. Free plan.

05

Agentic SAST

AI code review for the issues rules miss. Team plan.

06

Agentic pentest, black-box

Attacks your running app from outside, including signed-in pages with test accounts. Team plan.

07

Agentic pentest, white-box

Traces each exploit to the source line that causes it. Team plan.

08

Absence alerts

No scan in 7 days on a repository? You hear about it by email, Matrix or webhook.

09

Audit evidence

Weekly digests, package inventory and SBOM export, with evidence mapped to PCI DSS, SOC 2, ISO 27001 and DORA.

Who it's for

Built for how teams actually work

Continuous scanning without CI friction

Every repository is scanned on a schedule and nothing waits on a pipeline, so engineers keep shipping while coverage stays complete.

Pentests without booking a consultancy

Test staging or production on demand, with proof of concept for every finding, instead of waiting weeks for an annual engagement.

Less noise, more fixes

Exploitability verdicts and reachability cut the backlog to what matters, and approved AI fixes arrive as ready-to-review pull requests.

Evidence for auditors

Findings, verdicts, fixes, inventory and the audit log export cleanly for PCI DSS, SOC 2, ISO 27001 and DORA reviews.

Technical details

Works with your stack

Source control
GitHub and GitHub Enterprise Server
Scanners
SAST, SCA with reachability, IaC, secrets; agentic SAST and black-box and white-box pentests on Team
Scanner isolation
Deterministic scanners run in containers with no network access; code is deleted after each scan
Credentials
GitHub App tokens live 1 hour; stored tokens are encrypted with AES-256-GCM; the AI never receives your clone credential
Pentest scope
Only hosts you have verified by DNS TXT record or /.well-known file, valid 90 days; staging recommended
Tenant isolation
Own subdomain and portal database per organisation
Identity
OIDC single sign-on, TOTP two-factor, roles, API tokens, audit log
Notifications
Email, Matrix, webhooks
Data export
Findings, verdicts, fixes, package inventory, audit log, SBOM (CycloneDX or CSV)
Deployment
SaaS, or on-premises under a subscription or perpetual licence

Pricing

Plans

Free plan with unlimited seats and repositories, no card required. Team and Business add AI verdicts, code review, pentests and fixes, priced with you. On-premises available under a subscription or perpetual licence.

Free

$0 no card

Code, dependency, secret and IaC scanning.

  • SAST, SCA with reachability, IaC and secret scanning
  • 50 scans a day, 10 at once
  • Unlimited seats and repositories

Team

Popular
Custom priced with you

Adds AI verdicts, code review, pentests and fixes.

  • 4 pentests a month
  • 1,000 AI verdicts a month
  • 40 AI fixes a month
  • 10 AI code reviews a month
  • 500 scans a day

Business

Custom priced with you

Higher limits for larger programmes.

  • 20 pentests a month
  • 5,000 AI verdicts a month
  • 200 AI fixes a month
  • 50 AI code reviews a month
  • 3,000 scans a day

FAQ

Questions teams ask

Will it slow down or block our CI?

No. It runs on its own schedule, outside your pipeline, and never blocks a merge. Unchanged commits are skipped.

Does my code go to an AI model?

Not on Free. On Team, verdicts, code review and fixes send only what each task needs, through one model gateway. The white-box pentest also reads your code.

Can the AI close findings or merge code on its own?

No. A person approves every verdict and fix, and your team merges every pull request.

Is it safe to pentest production?

Use staging if you can. Production gets read-only rules, but some checks can still leave traces.

Can we run it on our own infrastructure?

Yes. DSO is available on-premises under a subscription or a perpetual licence. Talk to us about your environment.

Products

More from Cyphlon

See all products →

Book a call

Book a 30-minute call

Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.

Logo

Cyphlon

1:1 Consultation Call

30 min Google Meet

An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.

Logo Cyphlon

Research and tool releases by email

Unsubscribe any time. Privacy Policy

About Us

Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.

[email protected]

© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016

Privacy Policy Terms of Use