Technology & Cybersecurity

Intelligent code auditing with INCIBE backing

Client: Startup incubated in the NextAI ecosystem, with support from INCIBE

Client
Startup incubated in the NextAI ecosystem, with support from INCIBE
Sector
Technology & Cybersecurity
Alignment with today's offering
Superagents
The Challenge

The starting point

Decentralised code management and accelerated cloud growth raised the risk of critical vulnerabilities.

The Solution

What we built

We built proprietary continuous auditing technology that analyses code, dependencies and configurations in CI/CD pipelines with contextual AI-based SAST and DAST, prioritising by criticality, with technical and methodological support from the National Cybersecurity Institute.

Key features
  • Continuous auditing in CI/CD pipelines
  • Contextual AI-based SAST and DAST
  • Vulnerability prioritisation by criticality
  • Dependency and configuration analysis
  • Technical and methodological support from INCIBE
  • GitHub Actions integration

Anatomy of the solution

From technical finding to prioritised review

From input to outcome: explore the four parts of the journey.

Code

Project repositories, dependencies and configurations.

Explanatory diagram based on the described solution. It simplifies the journey; it is not a deployed infrastructure diagram or a live monitor.

Reading the project

The thinking behind the technology

01 / Business

What really needed solving

Growing code, dependency and configuration volumes make consistent review difficult. This case places analysis within CI/CD so security becomes part of development. The aim is not more alerts but better context for prioritising review.

02 / Design

Why this structure matters

SAST and DAST cover different analytical perspectives. Including dependencies, configuration and severity helps interpret a finding within the system. GitHub Actions integration puts that information where software is built and delivered.

Connection to today’s offering

Superagents

Execution, with clear boundaries

Explore the service

Current relevance and possible evolution

This is aligned with Superagents through a specialist role within a process. An extension could prepare fixes and tests; accepting changes or deploying to production should retain explicit review controls.

This connects the case experience to our current services. Proposed extensions are not presented as features already delivered.

Impact
92%
critical vulnerabilities detected
45 h
saved per month
70%
security improvement
100%
INCIBE validation

Method and scope

How to read the outcome

What to measure

Specify the reference vulnerability set, false positives and negatives, severity and review time. Detection and remediation are different outcomes.

What not to infer

The INCIBE support described in the case should not be read as universal product certification or a guarantee that vulnerabilities are absent.

Basis of this analysis: the description, capabilities and stack published in this case. No new measurements are added and no independent audit of its results is implied.

Tech stack
PythonFastAPIPostgreSQLKubernetesGitHub ActionsElastic Stack
In context

How it fits with the rest

NextAI

Does your company need this?

One hour, no sales deck: we analyse your operation and tell you what can be built, where to start and what is not worth touching yet.

Ready to apply this to your business?

Nora helps you choose. Our team scopes your project.

Book an audit · €290 ↗