Lucent Sky AVM is a scalable tool that removes vulnerabilities at the source code level, early in the SDLC.
Most teams rely on a lengthy back and forth between multiple stakeholders to remove even the simplest vulnerabilities.
Lucent Sky AVM streamlines the process by providing a seamless and scalable process of removing vulnerabilities.
The results of Lucent Sky AVM's proprietary analysis and remediation algorithms identify vulnerabilities, and generate and insert code-based remediation that fix them. These remediation are contextually generated for each individual vulnerability and can optionally be automatically inserted into code. Instant Fixes are not just suggestions — they functionally fix the vulnerability at the source.
IT professionals, security officers and developers are all aware of the time lost during the shuttling of source code between development and security testing.
Our clients and partners estimate that code travels between developers and security teams upwards of five times before each release. With Lucent Sky AVM, code can soar through security testing and be deployed faster — without the back and forth.
When it comes to application security, most organizations are in a constant state of catch up. The raw number of vulnerabilities increases over time, and organizations are forced to release applications with security deficiencies or to delay releases.
Lucent Sky AVM —
Common source code vulnerabilities like SQL injeciton, cross-site scripting, and privacy violation can be remediate automatically as part of the software development lifecycle.
Application source code can be uploaded as a zip file, imported from a repository, or pushed by a continuous integration (CI) pipeline.
Lucent Sky AVM uses multi-stage hybrid analysis to scan source code and binary files to identify vulnerabilities and their context, then use proprietary remediation algorithms to generates "Instant Fixes", source code replacements that remediate vulnerabilities.
Instant Fixes can be reviewed individually before inserted to source code. They can also be applied in-bulk so applications can be sent to testing and deployment right away.