Corgea is an AI-powered security code scanner that finds business logic flaws, broken authentication, API vulnerabilities, and more. Unlike other tools, users have reported a <5% false positive rate, so developers don’t get buried in noise. Plus, it automatically writes security fixes for them to approve. What makes Corgea unique is our use of LLMs to detect, triage, and fix vulnerabilities—and teams can even customize Corgea using natural language.
Hey there! I'm really intrigued by Corgea's ability to automatically fix code vulnerabilities. Can you share more about the technology behind the automated fixes? Also, have you conducted any security assessments to measure the effectiveness of these fixes? Looking forward to learning more about how Corgea can revolutionize application security!
@andrew_leader Thanks for the comment, and great questions!
Behind the scenes we leverage LLM's like OpenAI and various pre-processing and post-processing techniques to make sure we produce great fixes. We actually parse code using static code analysis techniques before we fix it to make sure it's valid. We don't want to fix a broken file. Afterwards, the LLM produces fixes, and we weave them through out the affected file, placing imports in the correct places, and fixes only the affected lines without damaging other parts of the file. The part I just described is the trickiest. We test the file's validity after the fix, and validate that the fix was correct using AI. At any point, if any of our checks fail, Corgea does not produce a fix.
You can tell from the above our goal is make sure the fix is great. The way we measure effectiveness is 2 ways. Would we issue a PR from this fix? Did the issue get resolved on the next scan? The team and I run QA checks on Corgea several times a month to see it's performance, and to iterate. We will be publishing performance reports soon on all of this!
Hope this answers your question!
OpenCopilot
Corgea
Corgea
Corgea
Corgea
Tandem
Corgea
Lunch with me at
Corgea
Strada
Corgea