The mechanism Five frontier-model capabilities, not a bolt-on.
Everything on screen comes from real analysis of real repositories — nothing is
hardcoded. The model does the reading, the tracing, and the judgment an analyst would.
01 Agentic reachability analysis
The flagship capability. For each high-signal finding, a frontier model reads the actual codebase — grepping, opening files, tracing call chains — to decide whether the vulnerable path is truly reachable from an entry point. It reads the code the way an analyst would, and shows its work.
02 Mission-context triage
EPSS exploitation probability, CISA KEV status, dependency position, and the reachability verdict fuse into a single mission priority — written for a program manager, not a pentester.
03 Reachability-gated remediation
For the findings that survive triage, the model drafts the exact fix — an appliable pull request with the version bump or transitive override, breaking-change risk, and test focus. Automation fires only for what's proven reachable, not the whole backlog.
04 Drift narration & AI-BOM risk
Every change to the software bill of materials is narrated in mission terms, and every discovered ML model gets an AI-written risk assessment — license suitability for government use, provenance confidence, training-data lineage.
05 Grounded natural-language query
Ask in plain English — “which critical findings are actually reachable,” “do any of our AI models have license problems.” Answers are grounded in the real scan data through query tools and cited to actual records. Never a hallucination.