Product guides
Relane Security, from first scan to verified fix
Find security issues in your repositories, understand the evidence, and move from review to remediation in one shared workspace.
Turn security results into decisionsPermalink to Turn security results into decisions
Relane Security helps engineering and security teams understand what needs attention in their code and what to do next. Connect a repository, choose what to assess, and review findings with their severity, supporting evidence and affected locations. Keep investigation, remediation and follow-up in the same workspace instead of passing around disconnected lists of warnings.
A useful security result answers more than how many issues were found. Relane distinguishes confirmed findings from items that need validation, explains the coverage of the assessment, and preserves the context you need to choose the next action. Eligible findings can continue into a reviewed fix proposal, a pull request and post-merge verification.
One workflow, several useful outcomesPermalink to One workflow, several useful outcomes
| Your question | How Relane helps |
|---|---|
| What should we investigate first? | Review confirmed findings by severity, evidence and code location; keep unvalidated leads separate. |
| What was actually checked? | Read the assessment scope, coverage and limitations alongside its findings. |
| How do we address it? | Triage the issue, follow its remediation guidance, or review an eligible fix proposal before approving repository changes. |
| Did the change resolve the issue? | Use follow-up assessment and, for supported fix sessions, post-merge verification tied to the original finding. |
| How do we make this part of delivery? | Set repository schedules and policies, then send relevant events to your team's notification destinations. |
| How do we communicate the result? | Use scan reports and exports for engineering handoffs and stakeholder reviews, with limitations intact. |
The path through RelanePermalink to The path through Relane
Connect the right source
Choose your personal or organization workspace, authorize a supported source connection and add the repositories you want to assess.
Choose the code to assess
Select the repository and the branch or ref you intend to review. Start the scan, then check the recorded revision and coverage with its result.
Review evidence and coverage
Open the result, check its scope and limitations, and prioritize confirmed findings. A lead that needs validation is not a confirmed vulnerability.
Act and verify
Investigate or triage findings, review eligible fixes, and verify the result after the code changes. Share the report with the people who own the next step.
Choose your next stepPermalink to Choose your next step
- Source connectionsGitHub, GitLab Cloud and Bitbucket Cloud: access, repositories and reconnecting.
- Coverage and assessmentUnderstand the types of issues Relane can assess and how to read the scope.
- Findings and triageUnderstand proof, severity, accepted risk and the next engineering action.
- Reviewed fixesMove from an eligible finding to a reviewed pull request and verification.
- AutomationBuild schedules, policies and notifications around your team's workflow.
- Reports and exportsPrepare a technical handoff or a stakeholder-ready assessment summary.
Start with what your workspace offers