1 / 14
Heeler · Product briefing

You can’t defer risk anymore.

Prevent it and fix it at machine speed.

AI is uncovering vulnerabilities faster than ever, and attackers use AI to weaponize them, often within a day. A backlog is no longer a place risk can wait. Burn down the backlog with deterministic fixes, exploitable first. Heeler automates security at every stage of the AI SDLC, from prompt to runtime.

  1. 01
    Why now
  2. 02
    The platform
  3. 03
    Context
  4. 04
    Prevention
  5. 05
    Autotriage and remediation at scale
  6. 06
    How Heeler compares
  7. 07
    Pricing
keyboard
 Use the arrow keys or the dots on the right
01 · Why now

The vulnpocalypse is here.

More vulnerabilities than ever, often exploited within a day, and the same team to fix them. The math no longer works, and every open finding is real risk.

020k40k60k80k28,818202340,009202448,185202537,137first half~74,000ON PACE FOR2026CVES PUBLISHED PER YEAR
MEDIAN TIME FROM DISCLOSURETO EXPLOITATION2021about a year20261 dayDeferring a finding used tobuy time. Now it buys exposure.
+51%
vulnerabilities published, first half of 2026 vs 2025
38%
of exploited CVEs hit before, on or within 7 days of disclosure
<1 day
for a frontier model to turn known vulnerabilities into working exploits
~60%
of breaches happened when a patch was already available
01 · Why now

To survive the vulnpocalypse, AppSec has to adapt now.

trending_up
From security debt and exposure
arrow_downward
shield
To prevention

Stop new risk where it starts: in the agent, at the commit and on the pull request.

inbox
From triage by hand
arrow_downward
balance
To automated decisions

Every finding ranked the moment it lands, from what runs and what it reaches.

confirmation_number
From tickets
arrow_downward
bolt
To deterministic agentic fixes

The fix version is calculated, not guessed. An agent makes the change, validates it in your CI and repairs what breaks. Your team merges it.

02 · The platform

One automated loop: prevent, decide, fix.

Heeler stops risk as code is written, ranks and routes every finding on its own, and fixes it with merge-ready pull requests. People step in only to merge and grant exceptions.

edit_notevisibilityterminalrulerocket_launchcrisis_alertbalancegavelgroupsbuildmergeSTART HEREWriteIn the agent before it writes a lineMCP AND AGENT SKILLSObservePrompts, tool calls and skills, per sessionWORKSTATION SENSORCommitLive secrets and bad packages stoppedCLI · AT COMMIT AND IN CIReviewEvery pull request checkedPR GUARDRAILSRunWhat deployed, and where it is exposedAUTOMATED SERVICE MODELINGDetectEvery new finding, code to cloud to agentsALL NINE RISK AREASDecideUrgent, Plan or Defer, or your exceptionAUTOTRIAGERouteOwner found, ticket and message sentOWNERSHIP · WORKFLOWSFixFix PR through review, you merge itAUTO-FIXContext EngineEvery step reads the same modeltune
person
People stay in charge
merge
Merge the fix
gavel
Grant exceptions
tune
Set once: tiers, SLOs, guardrails
03 · Context Engine

Context is the difference. Heeler builds it on its own.

Many tools hand your code to an LLM and hope it reasons its way to the right answer. Security cannot run on hope: the same finding has to get the same answer every time. Heeler gathers the context itself, from your catalog and ownership to what actually runs, so it can be deterministic wherever security requires it, and use AI where it helps.

ReposDependenciesAPIsReachabilityData flowsApplicationsTiers 1 to 4Shared codeTeamsCODEOWNERSContributorsRoutingPromptsTool callsSkillsMCP serversCommitsKEVEPSSMalwareCampaignsScorecardDeploymentsRuntimeExposureImagesDatastorescodeCodedomainBusinessgroupsOwnershipsmart_toyAgentcrisis_alertThreatcloudCloudContextEngine

04 · Prevention

Prevention at every step, from before the first line to the merge.

MCP and Agent Skills guide the agent while it plans and writes. The Workstation Sensor watches what it does, the CLI stops bad commits, and PR Guardrails gate the merge. Each layer catches what the one before it could not.

Workstation Sensor →PromptTool callsshell · skills · MCPDiffSecret in a promptDangerous actionInjected instructionWORKSTATION SENSOR · AS THE AGENT ACTSWorkstation Sensor →Heeler CLI →CommitCommit blockedHEELER CLIHeeler CLI →PR Guardrails →Pull requestthe merge gateGated at mergePR GUARDRAILSPR Guardrails →Coding agentClaude Code · Codex · CursorOpenCode · VS Code (Copilot)Guided as it writesMCP AND AGENT SKILLS
05 · Autotriage

Fix what can hurt you first.

Autotriage sets Heeler Risk on each dependency and code finding: Urgent, Plan or Defer. It asks how critical the service is, whether an attacker can reach the flaw, and whether it is under attack. Teams get a short list to fix now.

CVE-2025-24813
tomcat-embed-core 10.1.34
checkout-api
1
How critical is the service?
High
Tier 1 · Production
2
Can an attacker reach it?
High
Function reachable
Runtime library reachable
Internet accessible
Mitigated: No
Chaining: reaches PII datastore
3
Is it under attack?
High
Exploit threat: Confirmed
No LLM involved
Urgent
Fix within 14 days
05 · Re-evaluated

Priorities follow your environment as it changes.

Flip what is true about one real CVE and watch the level move. Heeler does this on its own whenever your environment changes. No re-triage meeting.

Heeler Risk
Urgent
Fix within 14 days
Plan
Fix within 60 days
Defer
Track it, 120 days

Try it: turn off Internet accessible, or add a mitigation.

05 · Remediation at scale

Burn down the backlog with fixes engineers can trust.

Heeler sequences the whole backlog, exploitable first, and works through it for you. Every fix is calculated, proven in your CI and opened merge-ready, so engineers review instead of research and AppSec stops chasing tickets.

AGENTIC VALIDATION · SANDBOX, THEN YOUR CIAutotriageUrgent · Plan · Deferevery finding typeCalculate fixdeterministic · SCA · SASTSandbox buildremediation harnessPR openedwith detailed contextRepair loopCI · comments · botsMerge-readyall checks greenRepair on redpushes a fix commit · CI re-runsAgent memoriesread before each run, written back after1234writes backwhat it learned
1

Sequence the whole backlog

  • Exploitable first, then everything else
  • Every finding gets an SLO, nothing is skipped
  • Re-sequenced as your environment changes
  • Deadlines tracked and reminded for you
Autotriage →
2

Deterministic fixes

  • Never trades one CVE for another
  • No upgrade that breaks your build
  • Least disruptive, not the newest
  • One PR clears the package’s CVEs
SCA Auto-fix →
3

Proven by the fix agent

  • Never review a fix that won’t build
  • Builds the way your repo builds
  • Works behind private registries
  • Unproven fixes arrive as drafts
SAST Auto-fix →
4

Repair loop

  • Edits your code to clear failures
  • Developers comment; it revises
  • Takes feedback from review bots
  • Merge-ready when every check is green
Agent Executions →
05 · Ownership and routing

Every fix goes to the team that owns it.

Autotriage decides how urgent it is. Heeler then walks the ownership you already keep, from a rule for one package down to the repository's team, and stops at the first real team. That team gets a ticket, a message and an Auto-fix pull request.

bug_reportSCA findingCVE-2022-22965spring-beans · checkoutAUTOTRIAGEUrgentfix within 14 daysWHO OWNS IT? THE MOST SPECIFIC ANSWER WINS1dependency_owners.jsonrule for this packageNO MATCH2dependency_owners.jsonrule for this manifestNO MATCH3CODEOWNERSlast matching path winsMATCH@payments-team4Module teamset on services/checkoutNOT NEEDED5Repository teamsynced from GitHub, GitLab or PortNOT NEEDEDgroupsPayments teamOwner, fromCODEOWNERSconfirmation_numberTicketPAY project in JiraforumMessage#payments-securitymergeAuto-fix PRvalidated in your CINo team at any levelSkip, or send to a fallbackreportA rule that names a team that no longer exists is skipped and flagged, and the walk goes on.Every level is ownership you already keep. Teams sync every four hours.
06 · How Heeler compares

Heeler replaces three categories of tools.

Not another tool for your stack. One platform that retires three categories of them, and finishes the job each one only started.

Traditional scanning tools
Heeler adds cloud context for true exploitability and the ownership context to automate it. Post-Mythos, AppSec fixes what is actually dangerous first, at machine speed.
Remediation point solutions
Deterministic fixing built into one platform. No stitching together a separate tool for each part of the AI SDLC.
ASPM and all-in-one platforms
All their context and automation, but post-Mythos you need fixes at machine speed, not posture management.
07 · Pricing

One price per developer. The whole platform.

Priced per contributing developer: anyone who committed to a monitored private repository in the last 90 days. AI agents that commit for a developer count under that developer.

Contributing developers
Per developer, per month
$35
1–199 devs
$30
200–299
$25
300–499
$21
500–999
$19
1,000–1,499
$17
1,500+
Every tier includes the whole platform: SCA, SAST, secrets, IaC, containers, CI/CD and agent file security, Auto-fix, Autotriage, PR Guardrails, MCP, Agent Skills, CLI, the Workstation Sensor, workflows, SSO and enterprise support.
Your rate
$21
per developer per month
Per year
$126,000
Billed annually, with quarterly true-ups as your contributing-developer count changes.
Heeler

Prevent it. Fix it.

At machine speed.