FOR SECURITY AND COMPLIANCE

Separate deterministic security evidence from optional model processing.

Prioritize dependency vulnerabilities against actual repository usage, inspect function-level evidence where coverage supports it, find secrets across git history, and export SBOM and VEX from the same index.

Security scanning is Pro+. Audit, rollup, webhook, and compliance coverage are Teams+. Optional model-backed features remain a separate data flow.

Book a security review
required model calls
0

Dependency scanning, secret detection, SBOM/VEX, and scoring are deterministic.

secret scan scope
Full history

Redacted previews and live-at-HEAD state keep the result actionable.

security scanning
Pro+

The backend gates scan creation and reads to paid plans.

governance
Teams+

Rollups, audit export, signed webhooks, and control-coverage reports.

Relevant product evidence

A finding carries priority, reachability evidence, and remediation context.

The security surface joins the dependency inventory, advisory data, exploit signals, repository usage, and code context. A reader can distinguish imported, used, function-reachable, function-unreachable, and unknown states instead of accepting a flat severity list.

Capture: the Repowise security surface. Reachability coverage varies by ecosystem and is labeled in product output.

Repowise security view showing dependency vulnerabilities, reachability evidence, and secret findings.
Security findings in Repowise, ranked with repository and advisory evidence.

How the index produces it

From repository to evidence-backed triage.

The security pipeline reuses the deterministic index, enriches it with public advisory and exploit data, and preserves the distinction between measured evidence and unknown coverage.

  1. 01 / Inventory

    Resolve dependencies and repository usage

    Parse manifests and lockfiles, connect imports to repository files, and keep the dependency graph and source identity beside each result.
  2. 02 / Enrich

    Join advisories, KEV, and EPSS

    Match packages against OSV data, add exploit signals, and retain the advisory and affected-version evidence used for the finding.
  3. 03 / Reach

    Assess usage and affected symbols

    Classify package usage first, then compare advisory symbols with imported names only where the ecosystem has declared coverage. Missing evidence remains unknown.
  4. 04 / Govern

    Export and monitor the result

    Generate SBOM/VEX, inspect redacted secret findings, and on Teams use rollups, audit history, signed webhooks, and control-coverage reports.

Know which boundary each operation crosses.

Local does not mean model-backed work is automatically offline, and hosted does not mean every deterministic result needs a model. The configured operation and deployment determine the data path.

Stage
Deterministic local core
Input
Repository source, manifests, and git history.
Processing
Language parsing, graph construction, health, history, risk, dependency and secret analysis run without a model.
Destination
Derived artifacts stay in the storage and runtime chosen for the self-hosted deployment.
Stage
Managed hosted indexing
Input
A connected public or authorized private repository.
Processing
Repowise-managed workers clone and process source transiently, then publish the derived index used by the product.
Destination
Derived artifacts and product metadata are stored in Repowise-managed hosted infrastructure.
Stage
Optional model-backed work
Input
Selected code-derived context, source excerpts, indexed documentation, and the user's request.
Processing
Documentation, grounded answers, and generated code may be sent to the configured model provider when the user invokes that feature.
Destination
The configured model provider processes the request; generated output is returned to and may be stored by the chosen Repowise deployment.
Stage
Customer-managed deployment
Input
Repository data and configuration inside the customer's environment.
Processing
The deterministic core runs there. Optional model traffic follows the provider or local model endpoint configured for that engagement.
Destination
Storage, retention, network egress, and provider policy are fixed in the deployment design and agreement.

Plan or deployment fit

Match the security workflow to the plan boundary.

The scan is a paid capability, while governance layers are team-level. Enterprise becomes relevant when the deployment or operating agreement, rather than the scan feature itself, is the decision.

Pro

Repository security for one operator

From $15/month on monthly billing. Includes dependency/CVE scanning, function-level evidence where supported, full-history secrets, and SBOM/VEX.

Details

Teams

Security governance across shared repositories

From $20/seat/month on monthly billing. Adds workspace rollups, audit read/export, signed webhooks, and PCI-DSS / SOC 2 control-coverage reports.

Details

Enterprise

Customer-managed boundary and scoped support

Evaluate when the source-processing environment, provider route, retention, support, or commercial terms must be designed for the organization.

Details

Shipping status

Security capability status.

Available still carries plan and coverage conditions. In-development work is visible without being sold as a finished control.

Scroll sideways to read capability scope and availability.

CapabilityStatusScope and boundaryWhere
Dependency and CVE scanningAvailableDependency inventory, OSV advisory matching, KEV and EPSS enrichment, and graph-aware usage triage are available on paid plans.Pro and above
Function-level reachabilityAvailableAffected-symbol evidence is crossed with imported names where ecosystem coverage supports it. Coverage is strongest for Go, partial for several ecosystems, and explicitly unknown elsewhere.Pro and above
Full-history secret detectionAvailableSecrets are scanned across git history with redacted previews, live-at-HEAD state, and rotation guidance.Pro and above
CycloneDX SBOM and VEXAvailableExport the dependency inventory and evidence-backed triage state, including version-to-version diffs.Pro and above
Audit, webhooks, and compliance coverageAvailableTeams adds the security audit trail, signed outbound alerts, workspace rollups, and PCI-DSS / SOC 2 control-coverage reports. Reports are evidence maps, not audits or certifications.Teams and above
Expanded language-specific security rulesIn developmentThe graph-aware security layer continues to add ecosystem and framework depth. Current coverage remains visible rather than inferred.Coverage varies

Honest limitations

Evidence is not certification.

Function-level reachability depends on explicit advisory symbols and ecosystem coverage. An unknown result is not proof of safety. PCI-DSS and SOC 2 output maps automated evidence to a limited control subset and does not constitute an audit, certification, legal opinion, or claim that the customer complies with either framework.

Questions, answered

The details behind the claim.

Does repowise scan code I do not actually call?

Dependency findings are first classified against repository usage, then affected-symbol evidence is crossed with imported names where ecosystem coverage supports it. Function-level coverage is strongest for Go, partial for PyPI, npm, and Cargo, and explicitly unknown for unsupported ecosystems. Unknown is not reported as unreachable.

Where does my code go?

The deterministic local core reads source and git history in the environment where it runs. Hosted indexing processes repository source in Repowise-managed infrastructure and stores derived artifacts and product metadata. Optional documentation, grounded answers, and generated code may send selected code-derived context to the configured model provider.

Can we self-host?

Yes. The AGPL-3.0 core is self-hostable. Customer-managed private-cloud and on-premise deployments are available as scoped Enterprise engagements. A packaged air-gapped enterprise bundle is planned; do not infer that packaging from the local engine's ability to run without hosted services.

What about secrets already committed to history?

Paid security scanning inspects git history, records only redacted previews, identifies whether a finding is live at HEAD, and provides provider-specific rotation or revocation guidance.

Do you generate an SBOM and VEX?

Yes. Paid security includes CycloneDX SBOM export and evidence-backed VEX state. The output can describe what was observed and why a finding was triaged; it is not a certification of the software.

Is there a model in the scanning path?

No model is required for dependency inventory, advisory matching, secret detection, SBOM/VEX generation, or security prioritization. Optional prose and answer features are separate and may send code-derived context to the configured model provider.

What compliance reports are available?

Teams and above can render PCI-DSS and SOC 2 control-coverage reports from current findings, with evidence drill-ins and JSON or Markdown export. These reports are evidence maps, not audits, certifications, or legal conclusions.

Last reviewed: September 2026

Review the exact security and data boundary.

Bring a representative repository, target deployment, model-provider policy, and required evidence outputs to one scoped evaluation.