Software Assurance

Your code hasvulnerabilities.Neolyt fixes them.

From detection to a verified fix, with you in control of what ships.

Software moves fast.

Assurance needs to keep up.

Traditional scanners stop at the alert. Neolyt continues the loop: it finds the issue, proposes a bounded fix when it is safe, verifies the result, and prepares a pull request for human review.

The product is built for engineering teams that need security decisions they can act on without turning every finding into a manual investigation.

Real product sequence

From 0 / 100 to verified remediation.

The score reflects risks detected by configured scanners. It helps prioritize work; it is not a guarantee that an application is fully secure.

Before Neolyt
0/ 100
2Critical
6High
6Medium
0Low
Fix with Neolytactive attempt
- const token = "sk_live_..."+ const token = process.env.PAYMENT_API_TOKEN+ if (!token) throw new Error("Missing payment token")
  1. 1Generating fix
  2. 2Applying patch
  3. 3Validating
  4. 4Re-scanning
  5. 5Creating Pull Request
  6. 6Verified Fixed
After verification
100/ 100
Verified Fixed

Original finding disappeared. No new Critical or High regression detected.

How it works

One loop, six product moments.

01

Connect GitHub

Install the Neolyt GitHub App and choose exactly which repositories can be analyzed.

02

Find

Neolyt scans source, secrets and dependencies, then normalizes findings into one view.

03

Understand

Severity, evidence, affected location and remediation are presented as a decision, not noise.

04

Fix

Deterministic findings can be sent through Fix with Neolyt for a bounded patch proposal.

05

Verify

The original scanner runs again and regression gates check for new Critical or High findings.

06

Ship

Neolyt creates a pull request. Your team reviews and decides what ships.

Find

Signals become decisions.

Neolyt does not sell a list of scanner names. It turns scanner output into a normalized product surface your team can use.

CriticalHard-coded API token
Signalsrc/payments/provider.ts:42

Credential exposed in payment provider configuration.

DecisionMove token to a managed secret

Bounded remediation, runtime validation and a human-reviewed pull request.

Location
src/payments/provider.ts:42
Risk
Unauthorized payment infrastructure access.
Next step
Create a verified remediation PR.

Secrets

Exposed credentials and sensitive values that should never be committed.

Dependencies

Known vulnerabilities in packages, lockfiles and dependency metadata.

Source code

Security problems detected directly in application logic.

Fix with Neolyt

Automatic where it can be trusted.

Neolyt does not try to repair everything. Automatic fixes are reserved for deterministic cases where the patch can be bounded, validated and re-scanned.

Fix attemptpolicy gated
  1. 1Generating fix
  2. 2Applying patch
  3. 3Validating
  4. 4Re-scanning
  5. 5Creating Pull Request
  6. 6Verified Fixed
VerifiedFixed

Signature concept

Not fixed because code was generated. Fixed because it was verified.

A finding becomes Verified Fixed only when the original scanner completes, the original fingerprint disappears, no unsafe suppression is introduced, no new Critical or High regression appears, and a pull request exists for human review.

Human control

Neolyt fixes. You decide what ships.

Neolyt can detect, propose, patch, validate, re-scan and create the pull request. Your team keeps the final decision before anything reaches the default branch.

Pull Requestneolyt/fix-hard-coded-token

Ready for review. Verified Fixed by Neolyt.

Security and trust

Built around isolation, least privilege and verification.

Neolyt treats repository content as untrusted. Customer execution remains gated while production infrastructure validation continues.

01

Repository selection through the GitHub App

02

Short-lived GitHub credentials

03

No package managers, tests or repository code executed during scans

04

Temporary execution workspaces

05

Tenant-scoped product queries

06

No automatic merge without human review

07

Bounded scanner and AI output

08

Audit trail for fix and verification events

Pricing

Prepared for careful onboarding.

Pricing is intentionally centralized and not finalized here. The right action is access by review, not a fake self-serve signup.

Access by review

Early access

For teams that want to evaluate Software Assurance with a clear repository review process.

Coming soon

Team

Planned for engineering teams connecting multiple repositories.

Coming soon

Enterprise

Planned for organizations needing deeper governance, limits and support.

Request access

Ship software with confidence.

Tell us about your repositories, team and current security workflow. We will get back to you with a clear next step.

contact@neolyt.fr