Connect your repo and get merge-ready PRs that fix critical vulnerabilities: SQL injection, broken auth flows, race conditions, and logic flaws that SAST tools miss. Deep semantic analysis finds what pattern-matching can't.
| Severity | Finding | Status |
|---|---|---|
| Second-Order SQL Injection in Report Builder | Fix Ready | |
| JWT Audience Confusion in Auth Middleware | Fix Ready | |
| Unsafe Deserialization in Product Config | Needs Review | |
| CORS Subdomain Injection via Wildcard Match | Fix Ready | |
| Time-of-Check Race Condition in File Access | Open | |
| Token Refresh Race Condition | Fix Ready |
Projects shipping Kolega.dev security fixes
A two-tier detection engine: industry-standard SAST plus deep semantic analysis that catches logic flaws, race conditions, and cross-boundary exploits.
For standard compliance and known vulnerabilities, we orchestrate industry-standard detection engines:
Standard tools miss complex logic flaws. Kolega.dev Deep Code Scan goes beyond pattern matching to understand code intent and identify critical vulnerabilities:
Stop drowning in alerts. Kolega.dev groups, deduplicates, and prioritizes so your team focuses on real risks.
See how Kolega.dev detects a sophisticated Second-Order SQL Injection across service boundaries and generates a complete fix
Severity: Critical (CVSS 9.3)
Second-order SQL injection where user input stored safely via ORM is later retrieved and used unsafely in dynamic report generation. Attacker payloads in company names execute 30+ days later during quarterly executive reporting, enabling complete database compromise.
Cross-boundary taint analysis traced user input through 4 code paths:
TenantController.updateProfile() - User input via REST APITenantRepository.save() - ORM storage (appears safe)ReportBuilder.generateQuarterly() - Dynamic SQL constructionanalytics.buildCompanyFilter() - String interpolation of stored dataservices/analytics/ReportBuilder.tsservices/analytics/SafeQueryBuilder.tscontrollers/TenantController.tsvalidators/ContentValidator.tsdatabase/migrations/add_taint_metadata.sqltests/security/second_order_sqli.test.tstests/integration/report_security.test.tsComplex vulnerabilities detected and automatically resolved by our engine. Click any card to see the complete fix details.
No config files. No CLI tools. Connect and scan from the browser.
One-click OAuth for GitHub, GitLab, or Azure DevOps.
Browse your repos, group them into applications, and configure scan schedules. All from the dashboard.
Kolega.dev scans your code, generates fixes with tests, and opens PRs you can merge with confidence.
From startups to enterprise, teams choose Kolega.dev for reliable security automation
“Other tools find vulnerabilities. This engine finds them, writes the fix, generates the tests, and hands me a merge-ready PR. I went from 8 hours fixing to 30 minutes reviewing.”
“A colleague invited me to the early beta and I owe them big time. Before: 3 hours per vulnerability. After: 5 minutes reviewing the PR. This tool is a 36x time multiplier.”
“Other tools just bump versions and hope for the best, but their PRs broke my build 40% of the time. Kolega PRs include tests that prove they work. One I disabled, one I trust.”
“We had 180 open vulnerabilities when we were invited to the early access program. The platform generated fixes for all of them in one week. We merged them progressively. Security debt: zero.”
“First automated security tool where I actually trust the PRs. Tests prove they work, conflicts are resolved, fixes are architecturally sound. I merge with confidence.”
“This system does the grunt work: reading CVEs, writing patches, generating tests. I just review and merge. Way better use of my time.”
Most security tools find known patterns. Kolega.dev finds what they miss, and fixes it for you.
| Traditional SAST | Kolega.dev | |
|---|---|---|
| Detection method | Pattern matching | Semantic analysis + pattern matching |
| Logic flaws & race conditions | Not detected | Detected |
| Cross-boundary vulnerabilities | Not detected | Traced across services |
| Automated fix generation | - | Merge-ready PRs with tests |
| False positive rate | High, manual triage required | 90% noise reduction |
| Setup time | CI pipeline changes, config files | 3 clicks, no config files |
| AI-generated code validation | - | Catches insecure LLM-generated patterns |
Start with the full Pro plan for 7 days
No credit card required · 7-day free trial
| Free | ProPopular | Team | Enterprise | |
|---|---|---|---|---|
| Price | $0 /mo | $99 /mo | $499 /mo | Custom |
| Applications | 1 Application | 1 Application | up to 5 Applications | Custom |
| Application LOC Limit | 100k | 100k | 100k | Custom |
| LOC Top-ups | - | Available | Available | Available |
| Pull Requests | 0 PRs | 4 PRs /mo | 25 PRs /mo | Custom |
| Scanning Mode | Scheduled Only | Scheduled Only | On-Demand & Triggered | Custom / Continuous |
| Included Scans | 20 SAST /mo 4 Deep Scans /mo | 20 SAST /mo 4 Deep Scans /mo | 20 SAST /mo 8 Deep Scans /mo | Custom |
| Noise Reduction | - | |||
| Automated Vulnerability Exploitation Testing | - | - | - | |
| Scan & PR Top-ups | - | - | Available | Custom |
| Core Features | ||||
| Automated Fixes | - | |||
| Ticket Integration | ||||
| Enterprise & Compliance | ||||
| Action Audit & Logging | - | - | ||
| Self-Hosted Runners | - | - | - | |
| SSO / SAML | - | - | - | |
| Compliance Readiness | - | - | - | SOC2, ISO, HIPAA, GDPR, CCPA, PCI, Bespoke |
| Get Started | No credit card required · 7-day free trial | No credit card required · 7-day free trial | ||
All plans include a 7-day free trial. No credit card required.
Your code is cloned into isolated, ephemeral containers for scanning and deleted immediately after. We never store source code at rest. Enterprise customers can run self-hosted runners in their own infrastructure for full data sovereignty.
Traditional SAST tools match known patterns. Kolega.dev adds a second tier of deep semantic analysis that understands code intent, catching logic flaws, race conditions, cross-boundary injection, and architectural vulnerabilities that pattern-matching misses. There is 0% overlap between our deep scan findings and standard SAST results.
Three clicks: connect your GitHub, GitLab, or Azure DevOps account via OAuth, select your repositories, and start a scan. No config files, no CLI tools, no CI pipeline changes. Most teams are scanning in under 3 minutes.
Every generated PR includes regression tests that prove the fix works, conflict resolution, and a detailed explanation of the vulnerability and remediation. You review and merge. Nothing ships without your approval.
After your 7-day Pro trial ends, you automatically move to the Free tier. You keep access to Kolega.dev with core scanning features at no cost. Upgrade to a paid plan anytime to unlock deeper analysis, automated PRs, and higher limits.
The Compliance module tracks adherence to ISO 27001, SOC 2, and SMB 1001 with SLA-based metrics including MTTR, resolution rates, and scan coverage. Enterprise plans support custom compliance requirements.