AiSulivo
AiSulivo
Menu
AiSulivo
AiSulivo

Corgea

Find code and dependency risks and review AI-generated remediation

Pricing
Free $0; Growth $39 per developer/month with a 5-developer minimum; Scale $49 per developer/month with a 20-developer minimum; Enterprise custom. AI pentesting is a separate product with per-pentest pricing.
Free plan
Yes; Free supports up to 2 team members and 10 repositories and includes AI SAST, logic/auth scanning, dependency, secrets, container and IaC scanning, with limited PR scans.
Platforms
Web, Source-control integrations, IDE integrations

Tool Information

Corgea
Corgea
Updated: September 2026
Tool type: AI Application Security Platform
Pricing: Free $0; Growth $39 per developer/month with a 5-developer minimum; Scale $49 per developer/month with a 20-developer minimum; Enterprise custom. AI pentesting is a separate product with per-pentest pricing.
Free plan: Yes; Free supports up to 2 team members and 10 repositories and includes AI SAST, logic/auth scanning, dependency, secrets, container and IaC scanning, with limited PR scans.
Platforms: Web, Source-control integrations, IDE integrations
Login required: Yes
API: API and webhooks advertised on Scale; enterprise arrangements may vary
Browser extension: No official browser extension verified; IDE integrations are available
Mobile app: No official standalone native mobile app verified
AI models: AI-assisted security analysis; complete underlying model versions are not publicly specified
Developer: Corgea

About Corgea

Corgea is an application security platform that analyzes development assets and proposes remediation within an engineering workflow. Its current offering goes beyond a single code scanner, bringing together AI-assisted static analysis, dependency checks, secret detection, infrastructure configuration analysis and container scanning. The aim is to make findings actionable for the people maintaining the affected application.

Understanding a finding

The AI SAST offering emphasizes business-logic and authorization problems as well as more conventional code weaknesses. Dependency analysis and reachability information help a team decide which issues deserve attention in the context of its own application. These findings still require technical review: a proposed vulnerability must be understood against the application's behavior, deployment and intended permissions before a fix is accepted.

Connecting analysis to development

Corgea integrates with major source-control services and development environments. Proposed changes can enter a pull-request workflow, allowing developers to inspect the patch and run their own tests. This is useful when a security team needs a reproducible review process rather than a separate list of warnings. Features such as API access, webhooks and reporting are plan-dependent, so they should be checked before designing a wider automation around the service.

Choosing coverage and access

The free plan has explicit limits on team size, repositories, pull-request scans and automated fixes. Paid plans are priced per contributing developer with minimum seat counts, while enterprise requirements are scoped separately. Start with a representative repository and check language coverage, false positives, suggested fixes and build results. Review what code is shared and which permissions the integration receives. Automated analysis can improve the speed of triage, but it is not a guarantee that an application is secure or that every generated remediation preserves business behavior.

Key features
  • AI-assisted static application security testing.
  • Business-logic and authorization analysis.
  • Dependency scanning and upgrade suggestions.
  • Secret detection.
  • Infrastructure and container checks.
  • Proposed remediation pull requests.
  • Source-control and IDE integrations.
Use cases
Reviewing application vulnerabilities,Prioritizing dependency risk,Detecting exposed secrets,Preparing security fixes,Adding checks to development workflows
How to use
  1. Select a plan for the team size.
  2. Connect an authorized repository.
  3. Confirm language and scanner coverage.
  4. Configure relevant security checks.
  5. Run an initial scan.
  6. Review findings in application context.
  7. Test and approve any proposed patch.
  8. Monitor subsequent changes and tune the workflow.
Best for
Application Security Teams, Software Developers, Engineering Organizations
Integrations
GitHub,GitLab,Azure DevOps,Bitbucket,Harness,VS Code,Cursor,Visual Studio,IntelliJ,Jira; availability varies by plan
Commercial use
Commercial development and security workflows supported under the selected plan

Categories Apps

Related Tags