Vulnerable code, fixed. Deterministically.
Finding the SQL injection is the easy part. Heeler writes the fix, proves it in your build, and opens a merge-ready pull request. A computed code change, not a model’s prediction.
Why not just use an LLM? ↓Heeler calculates what to fix first and the exact code change, then proves it builds. Your CI signs off.
Decide what to fix first
- Urgent, Plan or Defer, by real exposure
- Exposure judged from the path, not the service
- Re-evaluated as your environment changes
- Automated SLO management
Deterministic code fixes
- Decided during the scan, not predicted by a model
- Strategy matched to the weakness
- Checked against the traced tainted values
- No diff unless it clears the confidence bar
Proven by the fix agent
- Never review a fix that won’t build
- Builds the way your repo builds
- Adapts the fix to the surrounding code
- Unproven fixes arrive as drafts
Repair loop
- Edits your code to clear failures
- Developers comment; it revises
- Takes feedback from review bots
- Merge-ready when every check is green
The most dangerous get fixed first. Then the rest burn down.
A deterministic decision tree traces each flow from entry point to sink and uses context from code to cloud to decide what is real risk. Consistent, auditable, and re-evaluated as your environment changes.
A dangerous weakness on an exposed, high-value service.
Real risk, but lower exposure or a lower-tier service.
Not exposed, with nothing sensitive or chainable in reach.
Five strategies, each matched to the weakness.
Each fix addresses the root cause, not the symptom. Findings that need an architectural change get written remediation guidance instead of a risky pull request.
Parameterize
Rewrites the query to use safe parameter binding instead of string interpolation.
Escape
Applies the correct escaping for the output context: HTML, shell, logs, headers and so on.
Path normalize
Resolves and validates file paths so input cannot climb out of the intended directory.
Allowlist
Checks the value against a known-safe set of hosts, targets or identifiers before it reaches the sink.
Replace
Swaps the unsafe call for a safe one: MD5 to SHA-256, insecure random to a secure source, == to a constant-time compare.
The code fix is calculated, not predicted.
Heeler traces untrusted input to the sink during the scan and matches a fix strategy to the weakness. Same finding, same fix, every run.
The fix agent proves it in your build.
The fix agent, on the best model for each task, applies the calculated fix and keeps going until every check is green.
Merge isn’t the finish line. Deployed is.
Heeler correlates your running deployments back to source, so a fix closes only when the corrected code is seen running. No runtime agent, no tagging, no sign-off.
Start a fix from the app, a pull request or a workflow.
Fix Now from the finding
The before-and-after change is already on the finding, with its strategy and confidence. One click starts the run.
Fix it where it fired
A guardrail flags the change on a developer’s PR and Heeler offers the fix there. One click, and the check flips to passing.
Fixing as policy
A workflow turns fixing into policy. A new fixable finding appears, the agent fixes it, the PR lands ready to review.
Every run learns. Every run is on the record.
Memories
Short facts the agent keeps between runs, written by you and by the agent. The pattern a module uses for handling input, the suite that has to pass. It stops rediscovering your repos.
Agent Executions
Code fixes recorded alongside dependency fixes: the finding, the files changed, every CI iteration, and where the pull request stands.
Why not just use an LLM to fix it?
Pointing an LLM agent at a finding, or building your own harness around one, asks a model to find the fix, so the answer changes every run and every step costs tokens. Heeler gives you the best of both: it decides the fix deterministically from your context, then uses the latest models, the best one for each task, to validate it, repair CI and address review feedback.
Asks a model to find the fix
Calculates the fix, then proves it
data_arrayTokensReasons about it from what fits in its context window
checkNo costTraced at scan time, source to sink, across files
data_arrayTokensPicks a fix, differently each run
checkNo costStrategy matched to the weakness, decided at scan time
data_arrayTokensRewrites the code
checkNo costThe exact before-and-after change, checked against the traced values
data_arrayTokensRelearns it every session
checkNo costRemembered from past runs
scheduleDev timeA developer prompts, checks and reruns it
checkNo costRuns automatically, the same way for every team
scheduleDev timeFailures land on the developer
checkNo costSandbox build, CI repaired until green
scheduleDev timeA developer reviews and merges
scheduleDev timeA developer reviews and merges
Model API cost is $7.16 per fix, the blended SCA and SAST average, on the lower-priced of two frontier models at public pricing as of July 31, 2026, with 20% cached input and 35% agent overhead, and excludes infrastructure and labor.
Heeler also fixes vulnerable open source dependencies.
Heeler calculates the safest upgrade across your full dependency graph, proves it builds and opens a merge-ready pull request.
