Managed code remediation · Outcome-based

Your scanner found the problems. Someone still has to fix them.

Your scanner found the problems. Someone still has to fix them.

Fixes written with automation, reviewed by a senior engineer, merged into your repo. You pay when a fix lands.

Fixes written with automation, reviewed by a senior engineer, merged into your repo. You pay when a fix lands.

Detection was solved years ago. What nobody solved is the queue that comes after it: hundreds of findings from Snyk or SonarQube that nobody has time to action. We take that work off your team. One senior engineer, an AI framework for volume, pull requests your team approves.

Start with the free diagnostic

How it works

0.0%

of enterprise findings are still unpatched a year after discovery.

of mid-market AI pilots never reach production


of enterprise findings are still unpatched a year after discovery.

Edgescan, 2025

Edgescan, 2025

0%

of breaches now begin with an exploited vulnerability, the #1 entry point for the first time.

average cost of a single data breach in 2024


of breaches now begin with an exploited vulnerability, the #1 entry point for the first time.

Verizon DBIR, 2026

Verizon DBIR, 2026

0.0%

of one-click, machine-generated security fixes are closed without ever merging.

of one-click, machine-generated security fixes are closed without ever merging.

of one-click, machine-generated security fixes are closed without ever merging.

Peer-reviewed study, 2021

Peer-reviewed study, 2021

0x

industry critical-fix times against the 15-day CISA benchmark. E

typical time from

audit to first agent

in production


industry critical-fix times against the 15-day CISA benchmark. E

dgescan; CISA BOD 19-02

dgescan; CISA BOD 19-02

THE PROBLEM

Every security tool you buy gives your engineers more work.

Every security tool you buy gives your engineers more work.

A finding is not information. It's a task.

Investigate it, rank it, fix it, test the fix, merge it, prove it stayed fixed. Multiply that by everything your scanner flags in a quarter and you have a second roadmap nobody staffed. Autofix tools didn't change this. They converted the work from writing to reviewing, and the queue kept its owner: whoever on your team was busiest already. The numbers above are what that arrangement produces, while SOC 2 and customer security reviews keep asking how fast you fix things.

how it works

Automation does the volume. An engineer answers for every merge.

One senior engineer, embedded in your workflow, accountable for outcomes.

The framework ingests the findings from the scanner you already run, generates candidate fixes that match your conventions, and validates them: the tests run and the build passes before a human ever looks. Then a forward-deployed engineer does the part no tool closes on its own. Triage against real reachability. Judgment on the edge cases. Review of every fix before it becomes a pull request into your codebase. No blind merges, ever. Your team stays the final authority on what ships.

What your engineer does from week one

What your engineer does from week one

1

Findings ingestion

Your existing scanner export, via SARIF. Nothing new to install.

2

Triage

Which findings are real and reachable, and which come first. Most backlogs are twelve problems wearing four hundred costumes.

3

Fix generation and validation

Candidate fixes written at volume, tested against your build.

4

Review and merge

The engineer validates each fix and raises the PR. Your team approves.

5

Reporting

Fixes merged, backlog remaining by severity, merge rate, regressions. Audit-ready, SOC 2 and HIPAA-mappable.

HOW YOU ENGAGE

A phased engagement. Each step earns the next.

A phased engagement.

Each step earns the next.

Start free. Commit only to what the numbers justify.

01

Diagnostic

We scan a repo or two and quantify what's actually in your backlog, by severity and by real exploitability. You see the findings either way.

2–4 weeks. We read your code, workflows, and operations. We find where AI has been introduced without the structure changing. You get a prioritised roadmap, not a slide deck.

free

02

PILOT

Bounded scope, merged fixes shipped. You judge us on merge rate, regressions, and time saved. Nothing else.

Five personas reviewing your codebase in parallel. Every finding priced to fix before you commit. Audit-ready output. Pre-approved severity tiers — no surprise invoices.

FIXED FEE

03

Embed

The engineer joins your workflow: CI/CD, git, your policy gates. Billed per merged, validated fix with a monthly minimum.

We identify recurring tasks that cost you real money but aren't worth a full hire. We spec it, build it, ship it with monitoring. Priced against what it recovers — not how long it took.

monthly

04

GROW

More repos, more teams. Code quality and technical debt come later, once the security backlog is under control.

More repos, more teams. Code quality and technical debt come later, once the security backlog is under control.

Expansion

Pricing

You pay for fixes that land.

You pay for fixes

that land.

Nothing is billed for looking.

HOW THIS WORK IS USUALLY BILLED

Access-based

Seats and per-repo fees

Seats and per-repo fees

Hours billed whether fixes ship or not

Hours billed whether fixes ship or not

Billed for looking

Billed for looking

Billed for looking

The invoice and the risk report tell different stories

The invoice and the risk report tell different stories

VS

VS

The Keystone model

Outcome-based

Fees accrue per merged, validated fix

Fees accrue per merged, validated fix

Priced by severity, agreed before any work begins

Priced by severity, agreed before any work begins

A monthly minimum keeps coverage continuous

A monthly minimum keeps coverage continuous

One ledger. Billing and reporting run on the same numbers

One ledger. Billing and reporting run on the same numbers

The diagnostic

Most backlogs are smaller than they look. And worse.

The findings count is noise. The exploitable subset is the problem.

A typical mid-market scan produces hundreds of findings across severity tiers. Most are duplicates, unreachable code paths, or issues that sound scary and aren't. What's left after triage is a short list that actually matters.

Exposed secrets living in repo history.

Dependencies with published exploits and unapplied patches.

Permissions opened during an incident and never closed.

The diagnostic separates the two groups and prices what fixing the real ones takes.

The objection

You could run Claude on your codebase yourself.

For a weekend review, you should.

For a production system, four things get in the way.

01

Your codebase does not fit in the window.

Your codebase does not fit in the window.

Even the largest context windows hold 1–2M tokens — a production system runs 12–80M. You review a fragment, and most bugs hide in the interactions between files that were never in context together.

Even the largest context windows hold 1–2M tokens — a production system runs 12–80M. You review a fragment, and most bugs hide in the interactions between files that were never in context together.

02

LLMs are confidently wrong. Regularly.

LLMs are confidently wrong. Regularly.

The dangerous output is not the obvious error — it is the plausible answer your team ships without questioning. Catching it takes an expert who knows which question to ask and can tell when the answer is wrong.

The dangerous output is not the obvious error — it is the plausible answer your team ships without questioning. Catching it takes an expert who knows which question to ask and can tell when the answer is wrong.

03

A chat answer is not a merged fix.

A chat answer is not a merged fix.


A suggestion is the start, not the end. Someone validates it, implements it, reviews it, ships it. Keystone's framework writes the fix, the engineer validates it, and the PR is raised against a branch for your team to merge.

A suggestion is the start, not the end. Someone validates it, implements it, reviews it, ships it. Keystone's framework writes the fix, the engineer validates it, and the PR is raised against a branch for your team to merge.

04

Pasting code into a commercial LLM is a risk.

Pasting code into a commercial LLM is a risk.

Without a data-processing agreement, your source — your most valuable asset — enters a third-party model. For SOC 2, HIPAA or GDPR that is a compliance event, and a chat export is not evidence an auditor will accept.

Without a data-processing agreement, your source — your most valuable asset — enters a third-party model. For SOC 2, HIPAA or GDPR that is a compliance event, and a chat export is not evidence an auditor will accept.

The AI does the scanning. The human does the judgment.

The AI does the scanning.

The human does the judgment.

Access and trust

Built for teams that ask

hard questions about access.

The model is being validated at the highest level.

We'd worry if you didn't.

Least-privilege, read-scoped, revocable access under a signed DPA. Nothing standing. Your source is never used to train models and never pooled with another client's. Every finding and fix is logged as audit-ready evidence, mappable to SOC 2, HIPAA, and GDPR. On the roadmap: SOC 2 certification and a VPC deployment path for stricter environments.

Start with the

free diagnostic.

Start with the free diagnostic.

It costs nothing and it ends the guessing.

We scan a repo or two and show you the backlog you can't see: quantified and priced, inside 48 hours. If the numbers are bad, a bounded pilot will tell you whether we merge fixes or just talk about them.

Book a 30-minute call

Powered by

© 2026 Copyright | PrimeHire / Keystone.

All rights reserved

Powered by

© 2026 Copyright | PrimeHire / Keystone.

All rights reserved