Security findings you can act on.
Relane Security scans a connected GitHub repository and reports the security findings it can support with evidence.
A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.
From repository to result.
- 01
Connect repository
Install the GitHub App and choose which repositories Relane may read. A repository can be disconnected or reconnected at any time.
- 02
Full security scan
Start a scan on a branch. It reports ordered progress phases, keeps running if you close the page, and can be cancelled while it runs.
- 03
Evidence-backed findings
Each finding carries a severity and a separate proof state saying how well evidenced it is, and names the file and line where the location is known.
- 04
Review and remediation
For a confirmed dependency finding in a connected GitHub repository, Relane can prepare a deterministic patch for review. It opens a pull request only after explicit approval; a merge triggers a post-merge rescan.
A console, not an alert feed.
Evidence-backed findings
Every finding carries a severity and a proof state that says how well evidenced it is, and names the file and line where the location is known.
Full security scan
A scan reports its progress through ordered phases, keeps running if you close the page, and can be cancelled while it runs.
Reviewed
A scan ends in one of a fixed set of result states, and the console presents each differently: findings, a clean result, completed with limited coverage, cancelled, or a run that produced no result.
Merge triggers a rescan
Any result can be exported as JSON or CSV from the console, and the export carries the same coverage verdict the screen showed.
Workspaces and access
Repositories, scans, findings, keys and usage belong to a personal or organization workspace, with owner, admin and member roles.
Developer API
Personal and organization API keys can be created and revoked from the console, and a key is shown in full only once.
Built for teams, not just accounts.
Every finding carries a severity and a proof state that says how well evidenced it is, and names the file and line where the location is known.
A scan reports its progress through ordered phases, keeps running if you close the page, and can be cancelled while it runs.
Any result can be exported as JSON or CSV from the console, and the export carries the same coverage verdict the screen showed.
Repositories, scans, findings, keys and usage belong to a personal or organization workspace, with owner, admin and member roles.
A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.
Personal and organization API keys can be created and revoked from the console, and a key is shown in full only once.
Connected through the GitHub App.
Install the GitHub App and choose which repositories Relane may read. A repository can be disconnected or reconnected at any time.
Repositories come from your GitHub App installation and can be re-synced, and each one shows whether it can currently be scanned.
Start a scan on a branch. It reports ordered progress phases, keeps running if you close the page, and can be cancelled while it runs.
Reported with the evidence behind it.
Relane reports what it can evidence. A finding's proof state says how strongly it was validated, so a weakly-evidenced finding is labelled as one rather than presented as certain.
A scan ends in one of a fixed set of result states, and the console presents each differently: findings, a clean result, completed with limited coverage, cancelled, or a run that produced no result.
A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.
What the console guarantees.
Workspaces and access
Repositories, scans, findings, keys and usage belong to a personal or organization workspace, with owner, admin and member roles.
Developer API
Personal and organization API keys can be created and revoked from the console, and a key is shown in full only once.
Evidence over volume
Relane reports what it can evidence. A finding's proof state says how strongly it was validated, so a weakly-evidenced finding is labelled as one rather than presented as certain.
What coverage means
A scan is presented as clean only when coverage was adequate and nothing was found. A scan that could not examine enough of the repository is reported as limited coverage, never as an all-clear.
Review and remediation
For a confirmed dependency finding in a connected GitHub repository, Relane can prepare a deterministic patch for review. It opens a pull request only after explicit approval; a merge triggers a post-merge rescan.
Talk to the team behind the console.
Security and product enquiries reach the team at security@relane.ai.
Start with one repository.
Controlled beta access. Plans, pricing, supported capabilities and availability are confirmed in writing during approved onboarding. Self-service plan selection and checkout are not currently available.