Platform

Application security.
From assessment to remediation planning.

Bring SBOM, SAST, IaC, Secrets and AIBOM assessments together with project visibility, contextual prioritization and shared remediation work.

01
SBOM

Software supply chain

Component inventory · Dependency graph · Vulnerabilities · Licenses

Understand packages, versions, dependency relationships, vulnerability matches and license information within the supported assessment scope.

02
SAST

Source code

Finding locations · Evidence · Fix guidance

Investigate supported source-code weaknesses through affected locations, rules and remediation guidance.

03
IaC

Infrastructure definitions

Resources · Configuration findings · Rule evidence

Review supported infrastructure code for configuration weaknesses and the resources they affect.

04
Secrets

Credentials in software

Secret findings · Redacted evidence · Exposure review

Investigate potential exposed credentials and their locations. Coordinate validation, revocation or rotation through your engineering process.

05
AIBOM

AI component visibility

AI inventory · Components · Supported relationships

Understand supported AI components and their recorded relationships. AIBOM visibility does not establish comprehensive model or behavioural security testing.

Investigation and prioritization

Make the next decision with context.

QFinch Assistant helps your team interpret findings and explore remediation options using the available project context. It is in alpha testing; review its responses against the underlying evidence.

Declared exposure is distinct from verified runtime evidence. Live runtime usage and attack-path analysis are roadmap capabilities.

Remediation workflows

Give the work an owner.

Bring findings into a shared queue, assign responsibility and track lifecycle and due work. After application changes, review comparable assessment evidence to understand the result.

Your engineering team reviews and applies changes. Closing a task alone does not establish that an issue has been resolved.

What your team can expect

Understand the risk. Plan the response.

Investigate the code, components and configuration behind your findings. Each capability gives your team a defined set of evidence to support prioritization and remediation planning.

SBOM and dependency vulnerability analysis

What you see

A package-and-version inventory, supported dependency relationships, vulnerability matches and license information.

How it helps your team

Identify affected components, investigate advisory evidence and review compatible upgrades with the application owner.

Scope: A vulnerability match needs validation against the resolved package and version. Inventory alone does not prove runtime reachability.

SAST: source-code assessment

What you see

Rule-based findings with supported file locations, evidence and remediation guidance.

How it helps your team

Trace a reported weakness in its code context and agree a change that preserves application behaviour.

Scope: Only supported languages and successfully assessed files are covered. Static analysis does not reproduce every runtime condition.

IaC: infrastructure definitions

What you see

Configuration findings linked to supported infrastructure resources and the relevant rules.

How it helps your team

Review the intended deployment configuration and plan changes with the infrastructure owner.

Scope: Source definitions may differ from a live environment. This is not continuous cloud posture monitoring.

Secrets: exposed credential investigation

What you see

Potential secret findings with locations and appropriately redacted evidence.

How it helps your team

Validate exposure, identify the owner and coordinate revocation or rotation alongside source cleanup.

Scope: A match does not establish whether a credential is active. Removing it from code alone may leave the credential usable.

AIBOM: AI component visibility

What you see

Inventory of supported AI components and the relationships captured by the assessment.

How it helps your team

Establish which AI components are represented in your project and review provenance, ownership and assessment gaps.

Scope: Component inventory does not certify model behaviour or provide comprehensive prompt-injection testing.

QFinch Assistant: AI-assisted investigation · Alpha

What you see

Assistance interpreting findings and exploring priorities and remediation options in the selected workspace context.

How it helps your team

Ask what is affected, what evidence supports the finding and what to review before a proposed change. Validate the answer against the underlying evidence.

Scope: QFinch Assistant is in alpha testing. Responses may contain errors or omissions; your team reviews and applies changes.

Shared dashboards and remediation work

What you see

Organization and project views, relevant findings, assignment and lifecycle information.

How it helps your team

Use the portfolio view to agree priorities, then investigate project evidence and assign the next action.

Scope: Available assessments differ by project type. Prioritization uses available application context. Declared exposure is distinct from verified runtime evidence.

QFinch is in beta. Explore planned policy, integration and runtime capabilities on the roadmap.

Early Access

Start with your application priorities.

30 days. Up to five projects. Complimentary expert assistance.

Register for Early Access