Skip to content
Autonomous application security

Security findings you can act on.

Relane Security brings repository assessment, evidence-backed findings and reviewed remediation into one team workflow.

A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.

acme / checkout
main
Running
4Findings
Severity distribution
High2
Medium1
Low1
Findings
4
High
Unsanitized input in a query builder
api/orders/route.ts:42·Confirmed
High
Missing authorization check
app/webhooks/handler.ts:18·Needs validation
Medium
Unescaped input in a template
components/SearchBar.tsx:67·Confirmed
Low
Weak session expiry window
lib/auth/session.ts:23·Unconfirmed
Scan progressacme / checkout
01Queued
02Cloning repository
03Analyzing code
04Collecting results
05Completed
06Coverage recorded with the result
Illustrative product walkthrough
The pipeline

From repository to result.

  1. 01

    Connect repository

    Connect GitHub, GitLab Cloud or Bitbucket Cloud, authorize source access, and add the repositories you want to assess to your workspace.

  2. 02

    Full security scan

    Start a scan on a branch. It reports ordered progress phases, keeps running if you close the page, and can be cancelled while it runs.

  3. 03

    Evidence-backed findings

    Each finding carries a severity and a separate proof state saying how well evidenced it is, and names the file and line where the location is known.

  4. 04

    Review and remediation

    For a confirmed dependency finding in a connected GitHub repository, Relane can prepare a deterministic patch for review. It opens a pull request only after explicit approval; a merge triggers a post-merge rescan.

What you get

A console, not an alert feed.

Evidence-backed findings

Every finding carries a severity and a proof state that says how well evidenced it is, and names the file and line where the location is known.

Full security scan

A scan reports its progress through ordered phases, keeps running if you close the page, and can be cancelled while it runs.

Reviewed

A scan ends in one of a fixed set of result states, and the console presents each differently: findings, a clean result, completed with limited coverage, cancelled, or a run that produced no result.

Merge triggers a rescan

Any result can be exported as JSON or CSV from the console, and the export carries the same coverage verdict the screen showed.

Workspaces and access

Repositories, scans, findings and notification destinations belong to a personal or organization workspace, with owner, admin and member roles.

Security automation

Configure repository schedules and policies, and send selected scan events to email, Slack, Teams or an HTTPS webhook. Review actual execution and delivery outcomes in the console.

Workspaces and access

Built for teams, not just accounts.

For engineers

Every finding carries a severity and a proof state that says how well evidenced it is, and names the file and line where the location is known.

A scan reports its progress through ordered phases, keeps running if you close the page, and can be cancelled while it runs.

Any result can be exported as JSON or CSV from the console, and the export carries the same coverage verdict the screen showed.

For security owners

Repositories, scans, findings and notification destinations belong to a personal or organization workspace, with owner, admin and member roles.

A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.

Configure repository schedules and policies, and send selected scan events to email, Slack, Teams or an HTTPS webhook. Review actual execution and delivery outcomes in the console.

Integrations

Connect the code your team ships.

Connect

Connect GitHub, GitLab Cloud or Bitbucket Cloud, authorize source access, and add the repositories you want to assess to your workspace.

Sync

Review the repositories accessible through each source connection, add the ones you need, and check whether each is currently eligible to scan.

Scan

Start a scan on a branch. It reports ordered progress phases, keeps running if you close the page, and can be cancelled while it runs.

Evidence over volume

Reported with the evidence behind it.

Relane reports what it can evidence. A finding's proof state says how strongly it was validated, so a weakly-evidenced finding is labelled as one rather than presented as certain.

A scan ends in one of a fixed set of result states, and the console presents each differently: findings, a clean result, completed with limited coverage, cancelled, or a run that produced no result.

Findings
Clean result
Completed with limited coverage
No result produced
Our standard
A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.
Access and evidence

What the console guarantees.

Workspaces and access

Repositories, scans, findings and notification destinations belong to a personal or organization workspace, with owner, admin and member roles.

Security automation

Configure repository schedules and policies, and send selected scan events to email, Slack, Teams or an HTTPS webhook. Review actual execution and delivery outcomes in the console.

Evidence over volume

Relane reports what it can evidence. A finding's proof state says how strongly it was validated, so a weakly-evidenced finding is labelled as one rather than presented as certain.

What coverage means

A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.

Review and remediation

For a confirmed dependency finding in a connected GitHub repository, Relane can prepare a deterministic patch for review. It opens a pull request only after explicit approval; a merge triggers a post-merge rescan.

Get in touch

Talk to the team behind the console.

Security and product enquiries reach the team at [email protected].

Start with one repository.

Controlled beta access. Plans, pricing, supported capabilities and availability are confirmed in writing during approved onboarding. Self-service plan selection and checkout are not currently available.