Platform

Connect the assessment
to the application and the action.

Native assessments and shared workflows help teams understand the risks in their application building blocks.

01
SBOM

Software supply chain

Component inventory · Dependency graph · Vulnerabilities · Licenses

Understand packages, versions, dependency relationships, vulnerability matches and license information within the supported assessment scope.

02
SAST

Source code

Finding locations · Evidence · Fix guidance

Investigate supported source-code weaknesses through affected locations, rules and remediation guidance.

03
IaC

Infrastructure definitions

Resources · Configuration findings · Rule evidence

Review supported infrastructure code for configuration weaknesses and the resources they affect.

04
Secrets

Credentials in software

Secret findings · Redacted evidence · Exposure review

Investigate potential exposed credentials and their locations. Coordinate validation, revocation or rotation through your engineering process.

05
AIBOM

AI component visibility

AI inventory · Components · Supported relationships

Understand supported AI components and their recorded relationships. AIBOM visibility does not establish comprehensive model or behavioural security testing.

Investigation and prioritization

Make the next decision with context.

QFinch Assistant supports investigation and remediation planning. Review technical severity alongside available application exposure and business context. Priority explanations should show supporting inputs and missing information.

Declared exposure is distinct from verified runtime evidence. Live runtime usage and attack-path analysis are roadmap capabilities.

Remediation workflows

Give the work an owner.

Bring findings into a shared queue, assign responsibility and track lifecycle and due work. After application changes, review comparable assessment evidence to understand the result.

Your engineering team reviews and applies changes. Closing a task alone does not establish that an issue has been resolved.

What your team can expect

Useful evidence. A practical next step.

Each assessment starts with the inputs available for your project. Review the output, its scope and its freshness before deciding what to change.

SBOM and dependency vulnerability analysis

Expected output

A package-and-version inventory, supported dependency relationships, vulnerability matches and license information.

How to use it

Identify affected components, investigate advisory evidence and review compatible upgrades with the application owner.

Scope: A vulnerability match needs validation against the resolved package and version. Inventory alone does not prove runtime reachability.

SAST: source-code assessment

Expected output

Rule-based findings with supported file locations, evidence and remediation guidance.

How to use it

Trace a reported weakness in its code context and agree a change that preserves application behaviour.

Scope: Only supported languages and successfully assessed files are covered. Static analysis does not reproduce every runtime condition.

IaC: infrastructure definitions

Expected output

Configuration findings linked to supported infrastructure resources and the relevant rules.

How to use it

Review the intended deployment configuration and plan changes with the infrastructure owner.

Scope: Source definitions may differ from a live environment. This is not continuous cloud posture monitoring.

Secrets: exposed credential investigation

Expected output

Potential secret findings with locations and appropriately redacted evidence.

How to use it

Validate exposure, identify the owner and coordinate revocation or rotation alongside source cleanup.

Scope: A match does not establish whether a credential is active. Removing it from code alone may leave the credential usable.

AIBOM: AI component visibility

Expected output

Inventory of supported AI components and the relationships captured by the assessment.

How to use it

Establish which AI components are represented in your project and review provenance, ownership and assessment gaps.

Scope: Component inventory does not certify model behaviour or provide comprehensive prompt-injection testing.

QFinch Assistant: AI-assisted investigation

Expected output

Assistance interpreting findings and exploring priorities and remediation options in the selected workspace context.

How to use it

Ask what is affected, what evidence supports the finding and what to review before a proposed change. Validate the answer against the underlying evidence.

Scope: AI responses may contain errors or omissions. Guidance is advisory; your team approves and applies changes.

Shared dashboards and remediation work

Expected output

Organization and project views, relevant findings, assignment and lifecycle information.

How to use it

Use the portfolio view to agree priorities, then investigate project evidence and assign the next action.

Scope: Available assessments differ by project type. Declared exposure should not be presented as verified runtime evidence.

Early-access capabilities are subject to beta validation. Policy enforcement, external-tool orchestration and runtime enrichment are separately identified on the roadmap.

Early Access

Start with your application priorities.

30 days. Up to five projects. Complimentary expert assistance.

Register for Early Access