Enterprise Products · Closed source
DSO
Scheduled code scans, AI pentests, and fixes you approve.
- scanners and AI agents on one platform
- 8
- to first code-scan results
- ~5 min
- line cap on every AI fix, re-scanned before review
- 400
- seats and repositories on every plan
- Unlimited
Overview
DSO is a continuous application security platform. It scans your repositories with SAST, SCA, IaC and secret scanners on a schedule you set, attacks your running apps with agentic pentests once you have proven you own them, uses AI to decide which findings are actually exploitable, and proposes fixes as pull requests. A person approves every AI verdict and every fix. Delivered as SaaS, or on-premises under a subscription or perpetual licence.
How it works
From setup to enforcement
- Step 01
Find
SAST, SCA, IaC and secret scanners run on your schedule, per repository or team, in your timezone. Scans run outside your CI, so they never block a merge, and unchanged commits are skipped.
- Step 02
Triage
AI decides whether each finding is exploitable, shows the reachable input and the missing control, and gives a confidence score. A person approves or rejects every verdict.
- Step 03
Fix
An AI patch must pass a re-scan by the scanner that found the issue, then waits for you as a pull request or diff. Patches that add a secret or change more than 400 lines are refused.
- Step 04
Pentest the running app
Add a domain or IP, prove you own it with a DNS TXT record or a file, and an agent runs recon, fuzzing and injection tests. Every finding comes with a proof of concept, traced to its source line when you connect code.
Features
Key features
SAST
Risky patterns in your source code. Free plan.
SCA with reachability
Vulnerable open-source packages, and which of them your code actually calls, with CVEs ranked by exploitability. Free plan.
IaC scanning
Misconfigurations in Terraform, Kubernetes and more. Free plan.
Secret scanning
Leaked credentials in your repositories. Free plan.
Agentic SAST
AI code review for the issues rules miss. Team plan.
Agentic pentest, black-box
Attacks your running app from outside, including signed-in pages with test accounts. Team plan.
Agentic pentest, white-box
Traces each exploit to the source line that causes it. Team plan.
Absence alerts
No scan in 7 days on a repository? You hear about it by email, Matrix or webhook.
Audit evidence
Weekly digests, package inventory and SBOM export, with evidence mapped to PCI DSS, SOC 2, ISO 27001 and DORA.
Who it's for
Built for how teams actually work
Continuous scanning without CI friction
Every repository is scanned on a schedule and nothing waits on a pipeline, so engineers keep shipping while coverage stays complete.
Pentests without booking a consultancy
Test staging or production on demand, with proof of concept for every finding, instead of waiting weeks for an annual engagement.
Less noise, more fixes
Exploitability verdicts and reachability cut the backlog to what matters, and approved AI fixes arrive as ready-to-review pull requests.
Evidence for auditors
Findings, verdicts, fixes, inventory and the audit log export cleanly for PCI DSS, SOC 2, ISO 27001 and DORA reviews.
Technical details
Works with your stack
- Source control
- GitHub and GitHub Enterprise Server
- Scanners
- SAST, SCA with reachability, IaC, secrets; agentic SAST and black-box and white-box pentests on Team
- Scanner isolation
- Deterministic scanners run in containers with no network access; code is deleted after each scan
- Credentials
- GitHub App tokens live 1 hour; stored tokens are encrypted with AES-256-GCM; the AI never receives your clone credential
- Pentest scope
- Only hosts you have verified by DNS TXT record or /.well-known file, valid 90 days; staging recommended
- Tenant isolation
- Own subdomain and portal database per organisation
- Identity
- OIDC single sign-on, TOTP two-factor, roles, API tokens, audit log
- Notifications
- Email, Matrix, webhooks
- Data export
- Findings, verdicts, fixes, package inventory, audit log, SBOM (CycloneDX or CSV)
- Deployment
- SaaS, or on-premises under a subscription or perpetual licence
Pricing
Plans
Free plan with unlimited seats and repositories, no card required. Team and Business add AI verdicts, code review, pentests and fixes, priced with you. On-premises available under a subscription or perpetual licence.
Free
Code, dependency, secret and IaC scanning.
- SAST, SCA with reachability, IaC and secret scanning
- 50 scans a day, 10 at once
- Unlimited seats and repositories
Team
PopularAdds AI verdicts, code review, pentests and fixes.
- 4 pentests a month
- 1,000 AI verdicts a month
- 40 AI fixes a month
- 10 AI code reviews a month
- 500 scans a day
Business
Higher limits for larger programmes.
- 20 pentests a month
- 5,000 AI verdicts a month
- 200 AI fixes a month
- 50 AI code reviews a month
- 3,000 scans a day
FAQ
Questions teams ask
Will it slow down or block our CI?
No. It runs on its own schedule, outside your pipeline, and never blocks a merge. Unchanged commits are skipped.
Does my code go to an AI model?
Not on Free. On Team, verdicts, code review and fixes send only what each task needs, through one model gateway. The white-box pentest also reads your code.
Can the AI close findings or merge code on its own?
No. A person approves every verdict and fix, and your team merges every pull request.
Is it safe to pentest production?
Use staging if you can. Production gets read-only rules, but some checks can still leave traces.
Can we run it on our own infrastructure?
Yes. DSO is available on-premises under a subscription or a perpetual licence. Talk to us about your environment.
Products
More from Cyphlon
Chainsaw
Block malicious packages before they download.
Acksess
Replace the VPN with access that checks every device.
SHD Investigation Platform
AI-enabled data fusion and investigation for signals intelligence.