1 / 14
Heeler · Product briefing

You can’t defer risk anymore.

Prevent it and fix it at machine speed.

AI is uncovering vulnerabilities faster than ever, and attackers use AI to weaponize them, often within a day. A backlog is no longer a place risk can wait. Burn down the backlog with deterministic fixes, exploitable first. Heeler automates security at every stage of the AI SDLC, from prompt to runtime.

  1. 01
    Why now
  2. 02
    The platform
  3. 03
    Context and code-to-runtime mapping
  4. 04
    Autotriage
  5. 05
    Auto-fix at scale, safely
  6. 06
    Prevention
keyboard
Use the arrow keys or the dots on the right
01 · Why now

The math stopped working.

AI is uncovering vulnerabilities faster than ever and attackers use AI to weaponize them. Risk can no longer wait in a backlog: it has to be prevented and fixed at machine speed.

020k40k60k80k28,818202340,009202448,185202537,137first half~74,000ON PACE FOR2026CVES PUBLISHED PER YEAR
MEDIAN TIME FROM DISCLOSURETO EXPLOITATION2021about a year20261 dayDeferring a finding used tobuy time. Now it buys exposure.
+51%
vulnerabilities published, first half of 2026 vs 2025
38%
of exploited CVEs hit before, on or within 7 days of disclosure
<1 day
for a frontier model to turn known vulnerabilities into working exploits
~60%
of breaches happened when a patch was already available
02 · The platform

Automate everything a person does not need to decide.

edit_notevisibilityterminalrulerocket_launchcrisis_alertbalancegavelgroupsbuildmergeSTART HEREWriteIn the agent before it writes a lineMCP · AGENT SKILLSObservePrompts, tool calls and skills, per sessionWORKSTATION SENSORCommitLive secrets and bad packages stoppedCLI · AT COMMIT AND IN CIReviewEvery pull request checkedPR GUARDRAILSRunWhat deployed, and where it is exposedAUTOMATED SERVICE MODELINGDetectEvery new finding, code to cloud to agentsALL NINE RISK AREASDecideUrgent, Plan or Defer, or your exceptionAUTOTRIAGERouteOwner found, ticket and message sentOWNERSHIP · WORKFLOWSFixFix PR through review, you merge itAUTO-FIXContext & Policy EngineEvery step reads the same modeltune
person
People stay in charge
merge
Merge the fix
gavel
Grant exceptions
tune
Set once: tiers, SLOs, guardrails
03 · Context Engine

Context is the difference. Heeler gathers it for you.

Many tools hand your code to an LLM and hope it reasons its way to the right answer. Security cannot run on hope: the same finding has to get the same answer every time. Heeler gathers the context itself, from your catalog and ownership to what actually runs, so it can be deterministic wherever security requires it, and use AI where it helps.

Always deterministic
Which findings are urgent
Which version fixes it
Which pull requests are blocked
Who owns the fix
AI where it helps
Validating the fix in your build
Repairing a failed build
Reviewing agent files
Drafting a guardrail from plain words
ReposDependenciesAPIsReachabilityData flowsApplicationsTiers 1 to 4Shared codeTeamsCODEOWNERSContributorsRoutingPromptsTool callsSkillsMCP serversCommitsKEVEPSSMalwareCampaignsScorecardDeploymentsRuntimeExposureImagesDatastorescodeCodedomainBusinessgroupsOwnershipsmart_toyAgentcrisis_alertThreatcloudCloudContextEngine
Fed by
code
Source control
cloud
Clouds and hosting
inventory_2
Registries
crisis_alert
Threat intelligence
laptop_mac
Workstation sensor
optional
03 · The catalog

Everything you build and run, in one catalog.

Heeler builds the inventory itself. Source control fills in your code and agent files, the optional workstation sensor adds what agents actually do, and your cloud and registries add everything that runs.

From your code
folder_code
Repositories
view_module
Modules
account_tree
Dependencies
api
API endpoints
description
SBOMs
conversion_path
CI workflows
table
Data entities
key
Secrets
group
Contributors
From your agents
smart_toy
Agent files
extension
Skills and hooks
account_tree
Subagents
lan
MCP configs
forum
Sessions
sensor
chat
Prompts
sensor
terminal
Tool calls
sensor
commit
Agent commits
sensor
From your cloud
hub
Services
rocket_launch
Deployments
cloud
Cloud resources
grid_view
Kubernetes
deployed_code
Running images
public
Exposure
From threat intel
shield
Advisories
crisis_alert
KEV
trending_up
EPSS
coronavirus
Malicious packages
verified
Scorecard
sensor
From the optional workstation sensor. Everything else builds on its own once source control and your cloud are connected.
03 · Automated service modeling
Patent pending

Every finding, linked to what runs, what matters and who owns it.

Heeler models how your code becomes a running service, where it is exposed, how critical it is and who owns it. Autotriage reads that model to decide what comes first. Here are two findings in one service, with two different answers.

auto_awesome
Heeler builds the model on its own.
Connect source control and your cloud. Code to service to deployment, with owners and exposure attached. No tagging and no mapping.
EXAMPLE · TWO DEPENDENCY (SCA) FINDINGS IN ONE SERVICEfolder_codeRepositoryacme/paymentsview_moduleModuleservices/checkouthubServicecheckout-apirocket_launchDeploymenta1b2c3 · productionpublicCloud resourceLoad balancer · publicgroupsOwning team@payments-teamCODEOWNERSdomainApplicationPayments · Tier 1business impactdeployed_codeContainer imagecheckout:1.8.2runningbug_reportSCA findingCVE-2025-24813Defernot function reachablein the manifestmemoryRuntime evidencecommons-text loadedfound at runtimebug_reportSCA findingCVE-2022-42889Urgentloaded · public · Tier 1runtime onlydatabaseDatastore reachedorders-db · PIIchaining
What Autotriage reads here
function
Function reachability
memory
Found at runtime
public
Internet accessible
database
Datastore reached
domain
Service tier
crisis_alert
Threat intel: KEV, EPSS
03 · Ownership and routing

Every finding goes to the team that should fix it.

Autotriage decides how urgent it is. Heeler then walks the ownership you already keep, from a rule for one package down to the repository's team, and stops at the first real team. That team gets a ticket, a message and an Auto-fix pull request.

bug_reportSCA findingCVE-2022-22965spring-beans · checkoutAUTOTRIAGEUrgentfix within 14 daysWHO OWNS IT? THE MOST SPECIFIC ANSWER WINS1dependency_owners.jsonrule for this packageNO MATCH2dependency_owners.jsonrule for this manifestNO MATCH3CODEOWNERSlast matching path winsMATCH@payments-team4Module teamset on services/checkoutNOT NEEDED5Repository teamsynced from GitHub, GitLab or PortNOT NEEDEDgroupsPayments teamOwner, fromCODEOWNERSconfirmation_numberTicketPAY project in JiraforumMessage#payments-securitymergeAuto-fix PRvalidated in your CINo team at any levelSkip, or send to a fallbackreportA rule that names a team that no longer exists is skipped and flagged, and the walk goes on.Every level is ownership you already keep. Teams sync every four hours.
04 · Autotriage

Fix what can hurt you first.

Autotriage sets Heeler Risk on each dependency and code finding: Urgent, Plan or Defer. It asks how critical the service is, whether an attacker can reach the flaw, and whether it is under attack. Teams get a short list to fix now.

CVE-2025-24813
tomcat-embed-core 10.1.34
checkout-api
1
How critical is the service?
High
Tier 1 · Production
2
Can an attacker reach it?
High
Function reachable
Runtime library reachable
Internet accessible
Mitigated: No
Chaining: reaches PII datastore
3
Is it under attack?
High
Exploit threat: Confirmed
Same inputs, same answer. No LLM involved
Urgent
Fix within 14 days
04 · Deterministic decisions

Your context sets the priority. Not an LLM's opinion.

An LLM asked what matters gives a different answer each run and cannot show its work. Autotriage applies fixed rules to what the Context Engine knows about your environment, so the same inputs always give the same level.

Automated
Runs on every finding as it lands, and again when your environment changes.
Deterministic
Same inputs, same level, on every run.
Auditable
Each finding shows the inputs behind its level.
Context driven
Your deployments, exposure and threat data. Not a model's guess.

Six finding types, six rules. Choose one:

Three answers pick one cell: how critical the service is, whether an attacker can reach it, and whether it is under attack.

INPUTS FROM THE CONTEXT ENGINEFIXED DECISION TABLE · NO WEIGHTSBusiness impactPICKS THE TABLETier 1-2, in productionHighTier 3-4, in productionMediumOutside productionLowEnvironment impactPICKS THE ROWWHAT HEELER CHECKSRunning deploymentRuntime library loadedVulnerable function calledInternet accessibleMitigations checkedChaining: datastores, secrets, Tier 1CVSS impactExposed, full control or a path to dataHighExposed, limited damageMediumNot exposed, or mitigatedLowThreatPICKS THE COLUMNOn CISA or VulnCheck KEV, or maliciousHighEPSS 0.40 or higherMediumNo threat signalLowBusiness HighTier 1-2Business MediumTier 3-4Business LowOutside productionLowMediumHighTHREAT →HighMediumLowENVIRONMENT ↓PlanUrgentUrgentPlanPlanUrgentDeferDeferDeferPlanPlanUrgentPlanPlanPlanDeferDeferDeferDeferDeferDeferDeferDeferDeferDeferDeferDeferRows: environment impact·Columns: threat· Pick the business impact above

The traced path decides. A flaw on an open internet route outranks the same flaw behind auth on an internal service.

INPUTS FROM THE CONTEXT ENGINEFIXED DECISION TABLE · NO WEIGHTSBusiness impactPICKS THE TABLETier 1-2, in productionHighTier 3-4, in productionMediumOutside productionPlan at mostEnvironment impactPICKS THE ROWWHAT HEELER CHECKSInternet accessiblePath from a network entryAuth on the endpointCredentials, PII or financial dataChaining: data, Tier 1, auth issuerSuppressions, false positivesInternet accessible, no authHighInternet accessible, behind authMediumInternal only, or mitigatedLowSensitive data or chaining+1 levelThreatPICKS THE COLUMNWeakness on the CWE KEV Top 10HighCWE Top 25, CAPEC or OWASP Top 10MediumActive campaign+1 levelNo CWE dataRule severityBusiness HighTier 1-2Business MediumTier 3-4Business LowOutside productionLowMediumHighTHREAT →HighMediumLowENVIRONMENT ↓PlanUrgentUrgentPlanPlanUrgentDeferDeferDeferPlanPlanUrgentPlanPlanPlanDeferDeferDeferPlanPlanPlanPlanPlanPlanDeferDeferDeferRows: environment impact·Columns: threat· Pick the business impact above

The misconfiguration is matched to the live cloud resource it builds, and ranked on what Heeler sees there.

INPUTS FROM THE CONTEXT ENGINEFIXED DECISION TABLE · NO WEIGHTSBusiness impactPICKS THE TABLETier 1-2, in productionHighTier 3-4, in productionMediumOutside productionPlan at mostEnvironment impactPICKS THE ROWWHAT HEELER CHECKSMatched live cloud resourceProbe, network config, S3 policySeen darkExposure declared in the IaCSuppressions, false positivesLive resource seen internet accessibleHighExposure declared in code onlyMediumSeen dark, unknown, or mitigatedLowThreatPICKS THE COLUMNWeakness on the CWE KEV Top 10HighCWE Top 25, CAPEC or OWASP Top 10MediumNo CWE dataRule severityBusiness HighTier 1-2Business MediumTier 3-4Business LowOutside productionLowMediumHighTHREAT →HighMediumLowENVIRONMENT ↓PlanUrgentUrgentPlanPlanUrgentDeferDeferDeferPlanPlanUrgentPlanPlanPlanDeferDeferDeferPlanPlanPlanPlanPlanPlanDeferDeferDeferRows: environment impact·Columns: threat· Pick the business impact above

An image is ranked by the workloads that run it: their tier, their environment, and whether they are internet accessible.

INPUTS FROM THE CONTEXT ENGINEFIXED DECISION TABLE · NO WEIGHTSBusiness impactPICKS THE TABLETier 1-2 workload, in productionHighTier 3-4 workload, in productionMediumRuns only outside productionLowEnvironment impactPICKS THE ROWWHAT HEELER CHECKSWorkloads running the imageInternet accessible workloadTier and environment of eachCVSS impactExposed workload, full controlHighExposed workload, limited damageMediumNo internet accessible workloadLowThreatPICKS THE COLUMNKnown exploited (KEV)HighEPSS 0.40 or higherMediumNo threat signalLowBusiness HighTier 1-2Business MediumTier 3-4Business LowOutside productionLowMediumHighTHREAT →HighMediumLowENVIRONMENT ↓PlanUrgentUrgentPlanPlanUrgentDeferDeferDeferPlanPlanUrgentPlanPlanPlanDeferDeferDeferDeferDeferDeferDeferDeferDeferDeferDeferDeferRows: environment impact·Columns: threat· Pick the business impact above

Heeler scans git and its full history, every branch and every commit. It discards fakes with an offline checksum check, then proves what is left with a safe, read-only live test. Each secret lands in an action bucket by what that test found.

BEFORE ANYTHING IS SORTED1 · Scan git and all its historyEvery branch and every commit, so asecret deleted later is still found.2 · Drop the fakes offlineBuilt-in token checksums verifiedwith no network call, nothing sent.3 · Prove it liveA read-only call to the provider,or a test connection for databases.Default branchElsewhere in gitUnknownEACH SECRET SHOWS WHERE IT LIVESSO NO CANDIDATE LEAVES YOUR ENVIRONMENTFabricated look-alikes never become findings.EVIDENCE ON EVERY FINDINGThe provider's response, field by field.ACTION BUCKETWHY IT LANDS THERERotate nowProven validHeeler tested it and the credential works. Rotate and revoke it now.RotatePresumed liveReal key material, like a private key, with no provider to test it against. Treated as live until rotated.TriageNo verdictNo test applies, or the provider's answer did not settle it. Review these by hand.SORTED BY DETECTION CONFIDENCEHigh→Medium→Lowhow sure Heeler is it is a real secretA secret with a missing or unknown status lands here too, never in No action.No actionConfirmed inactiveAlready rotated or revoked, or not valid key material. A rotated key moves here on its own.ExpectedCanary tokenA decoy you planted. Not tested, and not a leak.

Each agent file, skill and MCP config gets a 0 to 100 safety score from fixed arithmetic on what Heeler finds in it.

WHAT HEELER FINDS IN THE FILESAFETY SCORE · 0 TO 100 · SAME INPUTS, SAME SCORERule findingsSTATIC RULESCritical finding95 pointsHigh finding80 pointsLow confidencecounts lessAI reviewLLM JUDGEPrompt injection, data exfiltrationfoundDestructive or privileged actionsfoundMalicious verdict10 or lowerReachHOSTS AND SCRIPTSRemote script that runs on its own70 pointsPaste site, raw IP, plain HTTP40 pointsWell-known developer hosts0 pointsThe worst factor sets the riskThe other two add 15% of theirs, capped at 100.Score = 100 minus risk.070100AT RISK · BELOW 70SAFER
04 · Re-evaluated

Priorities follow your environment as it changes.

Flip what is true about one real CVE and watch the level move. Heeler does this on its own whenever your environment changes. No re-triage meeting.

Heeler Risk
Urgent
Fix within 14 days
Plan
Fix within 60 days
Defer
Track it, 120 days

Try it: turn off Internet accessible, or add a mitigation.

05 · Auto-fix

Vulnerable dependencies and vulnerable code, fixed. Deterministically.

Heeler computes the fix, proves it builds in a sandbox and in your CI, and opens a merge-ready pull request. No human in the loop until review.

SCA Auto-fix
Remediate Pillow 9.0.0
Autotriage
Urgent · fix now
Tier 1 · Production
Function reachable
Runtime library reachable
Internet accessible
Chaining: reaches PII datastore
Exploit threat: Confirmed
Deterministic fix
Upgrade to 12.3.0
  • check
    Calculated, not LLM reasoned
  • check
    Breaking changes identified
  • check
    Dependency graph compatible
  • check
    Clears every open CVE
  • check
    Optimal version, not newest
  • check
    No new CVEs
  • check
    Package age enforced
Agent validation
Merge-ready PR #519
  • check
    Built in a sandbox with your toolchain
  • check
    Your repo conventions applied
  • check
    First-party code updated for the upgrade
  • check
    CI: 2 failures repaired · 47 green
  • check
    Developer comment addressed
verified
Developer merges · 21 CVEs remediated
SAST Auto-fix
Remediate SQL injection in orders/query.py
Autotriage
Urgent · fix now
Tier 1 · Production
Entry point: HTTP handler
Internet accessible
No authentication
Touches PII
CWE-89 · CWE Top 25
Deterministic fix
Parameterize · effort low
  • check
    Decided at scan time, not LLM reasoned
  • check
    Traced source to sink, cross-file
  • check
    Strategy matched to the weakness
  • check
    F-string rewritten to a bound parameter
Agent validation
Merge-ready PR #612
  • check
    Built in a sandbox with your toolchain
  • check
    Adapted to the surrounding code
  • check
    CI: 1 failure repaired · 38 green
  • check
    Developer comment addressed
  • check
    Your conventions applied from memories
verified
Developer merges · SQL injection closed
05 · Remediation at scale

Fix what is exploitable first. Then burn down the rest.

A backlog is live exposure, not debt. Heeler decides what to fix first, computes the fix, proves it builds, and your checks decide.

AGENTIC VALIDATION · SANDBOX, THEN YOUR CIAutotriageUrgent · Plan · Deferevery finding typeCalculate fixdeterministic · SCA · SASTSandbox buildremediation harnessPR openedwith detailed contextRepair loopCI · comments · botsMerge-readyall checks greenRepair on redpushes a fix commit · CI re-runsAgent memoriesread before each run, written back after1234writes backwhat it learned
1

Decide what to fix first

  • Urgent, Plan or Defer, by real exposure
  • Re-scored as your environment changes
  • Sequencing, not skipping
  • Automated SLO management
Autotriage →
2

Deterministic fixes

  • Never trades one CVE for another
  • No upgrade that breaks your build
  • Least disruptive, not the newest
  • One PR clears the package’s CVEs
SCA Auto-fix →
3

Proven by the fix agent

  • Never review a fix that won’t build
  • Builds the way your repo builds
  • Works behind private registries
  • Unproven fixes arrive as drafts
SAST Auto-fix →
4

Repair loop

  • Edits your code to clear failures
  • Developers comment; it revises
  • Takes feedback from review bots
  • Merge-ready when every check is green
Agent Executions →

06 · Prevention

Prevention at every step, from before the first line to the merge.

Heeler MCP and Agent Skills guide the agent while it plans and writes. The Workstation Sensor watches what it does, the CLI stops bad commits, and PR Guardrails gate the merge. Each layer catches what the one before it could not.

Workstation Sensor →PromptTool callsshell · skills · MCPDiffSecret in a promptDangerous actionInjected instructionWORKSTATION SENSOR · AS THE AGENT ACTSWorkstation Sensor →Heeler CLI →CommitCommit blockedHEELER CLIHeeler CLI →PR Guardrails →Pull requestthe merge gateGated at mergePR GUARDRAILSPR Guardrails →Coding agentClaude Code · Codex · CursorOpenCode · VS Code (Copilot)Guided as it writesMCP · AGENT SKILLS
Heeler

Prevent it. Fix it.

At machine speed.