Looks at every PR through five lenses — auth, input, secrets, supply chain, agent risk. Gates merges that miss the bar.
Devon is the security review discipline. Every PR gets passed through five lenses. Misses are blocking. Findings go in line with a suggested fix.
Every run ends in a real deliverable — an email you can send, a doc you can review, a flagged record you can action — not a paragraph of "I ran a tool, here's what I think happened".
Auth, input validation, secrets, supply chain, agent risk. Each PR goes through every lens.
Doesn’t just flag — proposes the patch. You can accept or reject.
New deps trigger a license + maintainer check. Suspicious additions block.
New endpoints get a quick threat model. STRIDE bullets land in the PR description.
Native, no Zapier in the middle. Tool calls land in the audit log.
Early access opens shortly. We onboard Engineering customers in cohorts so the bar stays high.