Skip to content
Autonomous application security

Security findings you can act on.

Relane Security scans a connected GitHub repository and reports the security findings it can support with evidence.

A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.

acme / checkout
main
Running
4Findings
Severity distribution
High2
Medium1
Low1
Findings
4
High
Unsanitized input in a query builder
api/orders/route.ts:42·Confirmed
High
Missing authorization check
app/webhooks/handler.ts:18·Needs validation
Medium
Unescaped input in a template
components/SearchBar.tsx:67·Confirmed
Low
Weak session expiry window
lib/auth/session.ts:23·Unconfirmed
Scan progressacme / checkout
01Queued
02Cloning repository
03Analyzing code
04Collecting results
05Completed
06Coverage recorded with the result
Illustrative product walkthrough
The pipeline

From repository to result.

  1. 01

    Connect repository

    Install the GitHub App and choose which repositories Relane may read. A repository can be disconnected or reconnected at any time.

  2. 02

    Full security scan

    Start a scan on a branch. It reports ordered progress phases, keeps running if you close the page, and can be cancelled while it runs.

  3. 03

    Evidence-backed findings

    Each finding carries a severity and a separate proof state saying how well evidenced it is, and names the file and line where the location is known.

  4. 04

    Review and remediation

    For a confirmed dependency finding in a connected GitHub repository, Relane can prepare a deterministic patch for review. It opens a pull request only after explicit approval; a merge triggers a post-merge rescan.

What you get

A console, not an alert feed.

Evidence-backed findings

Every finding carries a severity and a proof state that says how well evidenced it is, and names the file and line where the location is known.

Full security scan

A scan reports its progress through ordered phases, keeps running if you close the page, and can be cancelled while it runs.

Reviewed

A scan ends in one of a fixed set of result states, and the console presents each differently: findings, a clean result, completed with limited coverage, cancelled, or a run that produced no result.

Merge triggers a rescan

Any result can be exported as JSON or CSV from the console, and the export carries the same coverage verdict the screen showed.

Workspaces and access

Repositories, scans, findings, keys and usage belong to a personal or organization workspace, with owner, admin and member roles.

Developer API

Personal and organization API keys can be created and revoked from the console, and a key is shown in full only once.

Workspaces and access

Built for teams, not just accounts.

For engineers

Every finding carries a severity and a proof state that says how well evidenced it is, and names the file and line where the location is known.

A scan reports its progress through ordered phases, keeps running if you close the page, and can be cancelled while it runs.

Any result can be exported as JSON or CSV from the console, and the export carries the same coverage verdict the screen showed.

For security owners

Repositories, scans, findings, keys and usage belong to a personal or organization workspace, with owner, admin and member roles.

A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.

Personal and organization API keys can be created and revoked from the console, and a key is shown in full only once.

Integrations

Connected through the GitHub App.

Connect

Install the GitHub App and choose which repositories Relane may read. A repository can be disconnected or reconnected at any time.

Sync

Repositories come from your GitHub App installation and can be re-synced, and each one shows whether it can currently be scanned.

Scan

Start a scan on a branch. It reports ordered progress phases, keeps running if you close the page, and can be cancelled while it runs.

Evidence over volume

Reported with the evidence behind it.

Relane reports what it can evidence. A finding's proof state says how strongly it was validated, so a weakly-evidenced finding is labelled as one rather than presented as certain.

A scan ends in one of a fixed set of result states, and the console presents each differently: findings, a clean result, completed with limited coverage, cancelled, or a run that produced no result.

Findings
Clean result
Completed with limited coverage
No result produced
Our standard
A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.
Access and evidence

What the console guarantees.

Workspaces and access

Repositories, scans, findings, keys and usage belong to a personal or organization workspace, with owner, admin and member roles.

Developer API

Personal and organization API keys can be created and revoked from the console, and a key is shown in full only once.

Evidence over volume

Relane reports what it can evidence. A finding's proof state says how strongly it was validated, so a weakly-evidenced finding is labelled as one rather than presented as certain.

What coverage means

A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.

Review and remediation

For a confirmed dependency finding in a connected GitHub repository, Relane can prepare a deterministic patch for review. It opens a pull request only after explicit approval; a merge triggers a post-merge rescan.

Get in touch

Talk to the team behind the console.

Security and product enquiries reach the team at security@relane.ai.

Start with one repository.

Controlled beta access. Plans, pricing, supported capabilities and availability are confirmed in writing during approved onboarding. Self-service plan selection and checkout are not currently available.