Software supply chain
Understand packages, versions, dependency relationships, vulnerability matches and license information within the supported assessment scope.
Bring SBOM, SAST, IaC, Secrets and AIBOM assessments together with project visibility, contextual prioritization and shared remediation work.
Understand packages, versions, dependency relationships, vulnerability matches and license information within the supported assessment scope.
Investigate supported source-code weaknesses through affected locations, rules and remediation guidance.
Review supported infrastructure code for configuration weaknesses and the resources they affect.
Investigate potential exposed credentials and their locations. Coordinate validation, revocation or rotation through your engineering process.
Understand supported AI components and their recorded relationships. AIBOM visibility does not establish comprehensive model or behavioural security testing.
QFinch Assistant helps your team interpret findings and explore remediation options using the available project context. It is in alpha testing; review its responses against the underlying evidence.
Declared exposure is distinct from verified runtime evidence. Live runtime usage and attack-path analysis are roadmap capabilities.
Bring findings into a shared queue, assign responsibility and track lifecycle and due work. After application changes, review comparable assessment evidence to understand the result.
Your engineering team reviews and applies changes. Closing a task alone does not establish that an issue has been resolved.
Investigate the code, components and configuration behind your findings. Each capability gives your team a defined set of evidence to support prioritization and remediation planning.
A package-and-version inventory, supported dependency relationships, vulnerability matches and license information.
Identify affected components, investigate advisory evidence and review compatible upgrades with the application owner.
Scope: A vulnerability match needs validation against the resolved package and version. Inventory alone does not prove runtime reachability.
Rule-based findings with supported file locations, evidence and remediation guidance.
Trace a reported weakness in its code context and agree a change that preserves application behaviour.
Scope: Only supported languages and successfully assessed files are covered. Static analysis does not reproduce every runtime condition.
Configuration findings linked to supported infrastructure resources and the relevant rules.
Review the intended deployment configuration and plan changes with the infrastructure owner.
Scope: Source definitions may differ from a live environment. This is not continuous cloud posture monitoring.
Potential secret findings with locations and appropriately redacted evidence.
Validate exposure, identify the owner and coordinate revocation or rotation alongside source cleanup.
Scope: A match does not establish whether a credential is active. Removing it from code alone may leave the credential usable.
Inventory of supported AI components and the relationships captured by the assessment.
Establish which AI components are represented in your project and review provenance, ownership and assessment gaps.
Scope: Component inventory does not certify model behaviour or provide comprehensive prompt-injection testing.
Assistance interpreting findings and exploring priorities and remediation options in the selected workspace context.
Ask what is affected, what evidence supports the finding and what to review before a proposed change. Validate the answer against the underlying evidence.
Scope: QFinch Assistant is in alpha testing. Responses may contain errors or omissions; your team reviews and applies changes.
Organization and project views, relevant findings, assignment and lifecycle information.
Use the portfolio view to agree priorities, then investigate project evidence and assign the next action.
Scope: Available assessments differ by project type. Prioritization uses available application context. Declared exposure is distinct from verified runtime evidence.
QFinch is in beta. Explore planned policy, integration and runtime capabilities on the roadmap.
30 days. Up to five projects. Complimentary expert assistance.