The Heeler platform

You can’t defer risk anymore. Prevent it and fix it at machine speed.

AI is uncovering vulnerabilities faster than ever, and attackers use AI to weaponize them, often within a day. A backlog is no longer a place risk can wait. Heeler runs AppSec as one automated loop and brings your team in only where a decision needs a person.

One 
automated
 loop, from before the code is written to the fix that ships.
edit_notevisibilityterminalrulerocket_launchcrisis_alertbalancegavelgroupsbuildmergeSTART HEREWriteIn the agent before it writes a lineMCP · AGENT SKILLSObservePrompts, tool calls and skills, per sessionWORKSTATION SENSORCommitLive secrets and bad packages stoppedCLI · AT COMMIT AND IN CIReviewEvery pull request checkedPR GUARDRAILSRunWhat deployed, and where it is exposedAUTOMATED SERVICE MODELINGDetectEvery new finding, code to cloud to agentsALL NINE RISK AREASDecideUrgent, Plan or Defer, or your exceptionAUTOTRIAGERouteOwner found, ticket and message sentOWNERSHIP · WORKFLOWSFixFix PR through review, you merge itAUTO-FIXContext & Policy EngineEvery step reads the same modeltune
person
You stay in charge
merge
Merge the fix
gavel
Grant exceptions
tune
Set once
Tiers · SLOs · Guardrails
Why a loop, now

The math stopped working.

AI is helping uncover vulnerabilities faster than ever, and attackers use AI to weaponize them. CVE disclosures are on pace for a record of about 74,000 this year, and the median time to exploitation is now a day. The people who can triage and fix by hand stay the same. That is the vulnpocalypse.

020k40k60k80k28,818202340,009202448,185202537,137first half~74,000ON PACE FOR2026CVES PUBLISHED PER YEAR
MEDIAN TIME FROM DISCLOSURETO EXPLOITATION2021about a year20261 dayDeferring a finding used tobuy time. Now it buys exposure.
+51%

vulnerabilities published in the first half of 2026, compared with the first half of 2025

38%

of exploited CVEs were exploited before, on or within seven days of disclosure

<1 day

for a frontier AI model to turn known vulnerabilities into working exploits, with no human involved

~60%

of breaches happened when a patch was already available

So AppSec has to change in three ways.

trending_up
From security debt and exposure
arrow_downward
shield
To prevention

Stop new risk where it starts: in the agent, at the commit and on the pull request.

MCP and Skills
CLI
PR Guardrails
inbox
From triage by hand
arrow_downward
balance
To automated decisions

Every finding ranked the moment it lands, from what runs and what it reaches. Same inputs, same answer.

Context Engine
Autotriage
confirmation_number
From tickets
arrow_downward
bolt
To deterministic agentic fixes

The fix version is calculated, not guessed. An agent makes the change, validates it in your CI and repairs what breaks. Your team merges it.

SCA Auto-fix
SAST Auto-fix
Operationalized AppSec

Automate everything a person does not need to decide.

Runs on its own
Checking code as it is written
Ranking every finding
Finding the owner
Opening tickets and messages
Writing and validating fixes
Reminding before SLOs lapse
Re-checking when exceptions end
People decide
Merge the fix
Grant exceptions
Set tiers, SLOs and guardrails
Watch it work

Five moments every AppSec team knows. Here is what Heeler does with each.

Each one runs end to end without a triage meeting. Pick one.

  1. crisis_alert
    01 · New finding

    CVE-2022-22965 in spring-beans, on checkout-api

    Threat intel
  2. hub
    02 · Context

    Tier 1, production, internet accessible, function reachable

    Context Engine
  3. balance
    03 · Decision

    Urgent. The SLO is 14 days.

    Autotriage
  4. groups
    04 · Owner

    CODEOWNERS names @payments-team

    Ownership
  5. send
    05 · Response

    Ticket in PAY, message in #payments-security

    Workflows
  6. build
    06 · Fix

    Auto-fix opens the upgrade PR, validated in CI

    Auto-fix
check_circle
Fixed inside the SLO.
Nobody triaged it, assigned it or wrote the upgrade by hand.
  1. edit_note
    01 · The task

    Add PDF export to billing-service

    MCP and Skills
  2. policy
    02 · Your policy

    Heeler MCP tells the agent your guardrails: licenses, minimum package age, known vulnerable versions

    MCP and Skills
  3. verified
    03 · A safe choice

    The agent picks a version that passes, not the newest one

    MCP and Skills
  4. visibility
    04 · The record

    The sensor records prompts, tool calls and skills as the agent works

    Workstation sensor
  5. terminal
    05 · The commit

    The CLI hook checks secrets and packages, and the session is linked to the commit

    CLI
  6. rule
    06 · The pull request

    PR Guardrails check new dependencies, secrets and agent files

    PR Guardrails
check_circle
The risk never lands.
The agent wrote it right the first time, and the PR proves it.
Keep it out
If it is already in
  1. crisis_alert
    01 · Reported

    Malicious-package intelligence reports the bad version as soon as it is known

    Threat intel
  2. schedule
    02 · Cooling off

    A minimum package age rule was already holding brand-new versions back

    PR Guardrails
  3. block
    03 · No way in

    PR Guardrails block any pull request that adds the malicious version

    PR Guardrails
  4. travel_explore
    04 · Do I have exposure?

    Every repository and running service with it, at the exact version, even when unpinned, from what runs

    Context Engine
  5. campaign
    05 · Response

    Security is alerted and each owning team gets a ticket

    Workflows
  6. build
    06 · Fixed

    Auto-fix opens a pull request to a safe version, validated in your CI

    Auto-fix
check_circle
Kept out before it lands.
And if it already has, you know where it runs and the fix is on its way.
Stop it at the commit
If one is already in code
  1. terminal
    01 · Caught at commit

    The CLI hook checks the key with its provider before the commit exists. It is live

    CLI
  2. block
    02 · Commit stopped

    The agent is told to remove the key and rotate it. Nothing reaches the repository

    CLI
  3. rule
    03 · Flagged on the PR

    A key already in the change is exposed, so PR Guardrails alert the reviewer that it must be rotated

    PR Guardrails
  4. history
    04 · Found in history

    Keys on any branch or in git history are found and proven live against the provider

    Secrets
  5. send
    05 · Rotated by the owner

    Rotate now. Ticket to the team that owns the repository, alert to security

    Workflows
check_circle
New secrets stop at the commit.
The ones already in code are proven live and rotated first.
  1. timer
    01 · SLO expiring

    A finding is days from its SLO due date

    SLOs and exceptions
  2. forum
    02 · Nudge

    Heeler messages the owning team before the deadline passes

    Workflows
  3. lock
    03 · Vuln jail

    Past due, PR Guardrails block new pull requests in that repository

    PR Guardrails
  4. merge
    04 · The way out

    The fix PR passes, because it removes the vulnerable version. Merge it and the block lifts

    Auto-fix
  5. gavel
    05 · Or an exception

    Cannot fix yet? Record a reason and an end date. When it ends, the finding comes back

    SLOs and exceptions
check_circle
Deadlines do not slip.
Past due, the repository waits for the fix, not the other way round.
What you get

Built for the vulnpocalypse.

AI coding means more code, AI attackers mean less time, and together they add up to more findings than any team can work by hand. Every part of the platform answers one of the three.

smart_toy
AI coding
Agents write more code than people can review.
shield

Risk stops before it lands

Agents get your policy while they write, commits are checked before they exist, and every pull request is checked before merge.

MCP and Skills
CLI
PR Guardrails
visibility

Agent work you can see and govern

Every agent file is scored from 0 to 100, changes to them are guarded, and the sensor shows what each session did.

Agent file scoring
Workstation sensor
PR Guardrails
bolt
AI attackers
The gap between a new CVE and an attack keeps closing.
filter_list

The exploitable few, first

Each finding is ranked the moment it lands, from what runs, what it reaches and how critical the service is.

Context Engine
Autotriage
timer

Deadlines that hold, on the record

SLOs you set, reminders before they lapse, and every exception kept with a reason, an owner and an end date. SBOMs when you ask.

SLOs
Exceptions
SBOM
storm
The vulnpocalypse
More findings than any team can work by hand.
merge

Fixes ready to merge

Upgrade and code fixes arrive as pull requests, validated in your CI and repaired when the build fails.

SCA Auto-fix
SAST Auto-fix
groups

Every finding has an owner

Work goes to the right team, in its own tools, without a triage queue.

Ownership
Workflows
Why it holds together

It works end to end because it is built as one system.

hub

One model underneath

Code, cloud, agents, owners, business and threat intel in one Context Engine. Prevent, Fix and Operate all read it.

See the Context Engine →
balance

Same inputs, same answer

Rankings, fix versions, guardrail results and owners are decided by rules, not by an LLM. AI writes and repairs code where it helps.

See how Autotriage decides →
conversion_path

Your tools, your teams

Work lands in each team's own tickets and channels, on the timeframes you set. Nothing to add to your pipelines.

See setup →
Purpose-built for the AI SDLC

See the loop run on your code.