Corgea

AI-native AppSec platform (BLAST SAST) that finds business-logic vulnerabilities across code, dependencies, containers and IaC, and ships AI-generated pull-request fixes.

$31/dev/moLast verified 2026-09-09

Deployment

Cloud

Languages

12+

Pricing model

Per developer seat, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle Corgea operates.

Real-Time IDE FeedbackPartial

On-demand only (Full Scan / Scan Uncommitted Changes), no as-you-type

AI Agent Guardrail (MCP)Yes

Agent Skill + MCP for Cursor/Claude Code/Copilot/Codex

Local CLI / Pre-CommitYes

corgea setup-hooks; offline deps commands need no network

PR Inline ReviewYesGrowth

Inline PR/MR comments (GitHub/GitLab/Azure/Bitbucket/Harness); PR Scanning named at Growth

Merge Gate BlockingYesScale

Blocks GitHub/Azure/Harness merges, or CI via --block-on; Blocking Rules at Scale

Full Repo ScanYes

Baseline scan mode from Free tier

Scheduled / Continuous RescanYes

Scheduled re-scan cadences available; enabled at plan level rather than self-serve

Runtime / Production MonitoringYes

AI Pentesting against live targets; needs admin enablement

Analysis & detection

Every detection and code-analysis capability tracked for Corgea.

SASTYes

BLAST AI-native SAST, ~900 CWEs, 11 languages

Taint / Data-Flow AnalysisYes

Cross-file source-to-sink taint tab in BLAST Full View

Secrets DetectionYes

Pattern matching, entropy analysis and AI context

Secrets ValidationNo

Not documented. Secret-scanning page covers detection methods in depth, never live/provider verification.

SCA (Dependencies)Yes

Lockfile/manifest scanning across 25+ ecosystems with CVE/CVSS

Reachability AnalysisYes

Checks import plus whether the vulnerable function is called; direct deps only

Malicious Package DetectionYes

Typosquats, hijacked releases, backdoors via OpenSSF malicious-packages data

License ComplianceYesGrowth

SCA captures per-dependency license; enforced via blocking rule; License Enforcement named at Growth

SBOM GenerationYes

corgea deps sbom produces a CycloneDX SBOM

IaC ScanningYes

Terraform, CloudFormation, Kubernetes, Docker, Helm, Azure ARM

Container ScanningYes

Base-image/OS/library CVEs across 7 named registries

Cloud Posture (CSPM)No

Not documented. No CSPM/cloud-account-posture page exists anywhere in Corgea's own doc directory.

DAST / API ScanningYes

AI Pentesting actively tests live web-app targets; API-type breakdown not enumerated

Code Smells & MaintainabilityYesGrowth

9-category AI code review: cleanliness, naming, logic/correctness, incomplete work

Complexity MetricsPartialGrowth

Flags deeply-nested logic/complex one-liners qualitatively; no tracked complexity number

Duplication DetectionYesGrowth

Detects repeated logic and magic numbers

Dead / Unused CodeYesGrowth

Empty blocks, unused code, unreachable statements (CWE-563, CWE-1041)

Test Coverage TrackingNo

Not documented. The 9-category quality-scanner page never mentions coverage ingestion.

Diff / New-Code CoverageNo

Not documented, same page/domain as test coverage.

Architecture GovernanceYesGrowth

Circular dependencies (CWE-1047) and SOLID violations

Technical Debt QuantificationNo

Not documented. Framed as preventing technical debt qualitatively; no time/cost quantification.

Behavioral Delivery AnalyticsNo

Not documented. No git-history hotspot/bus-factor analysis described.

AI Logic Bug DetectionYes

Free tier explicitly includes Logic and Auth Scanning

PR Summaries & WalkthroughsNo

Not documented. GitHub PR integration page covers finding comments in depth, never a change walkthrough.

Custom Rule AuthoringYesScale

PolicyIQ UI or corgea.yaml policies; YAML needs Scale/Enterprise; Custom Rules named at Scale

Autofix SuggestionsYes

AI generates and quality-checks a fix; auto-fix quota included from Free upward

Autofix via Agentic PRsYes

Automatically opens a PR with issue and fix context on GitHub/Azure DevOps/Harness

AI Triage / False-Positive FilteringYes

AI classifies findings as false positive with reasoning; AST fingerprinting dedupes across scans

Monorepo SupportYes

BLAST endpoint-reachability analysis attributes findings to the correct sub-project within a monorepo.

AI capabilities

AI Review EngineYes

BLAST combines LLM reasoning with static/AST analysis

BYO Model / BYOKNo

Not documented. Security/agent/MCP pages are covered in depth, never a customer-supplied model or key.

MCP ServerYes

Corgea exposes its own MCP server: 9 read-only tools for scans, issues, dependencies, blocking rules

AI Usage GovernanceNo

Not documented. Corgea Agent's scope is fully enumerated (web chat plus 6 PR actions) with no org-wide AI-usage inventory feature.

Chat With ReviewerYes

Corgea Agent web chat lets teams query scans, issues and policies conversationally

Learns From FeedbackNo

Not documented. False-positive/fingerprinting pages describe classification and dedup in depth, never adaptive learning.

Code Excluded From TrainingYesIncluded on all plans

Your data is never used to train AI models; Zero Data Retention with OpenAI/Azure OpenAI

Models used

OpenAIAzure OpenAI

Compliance & governance

Audit LogsYesEnterprise

Audit Logs is an Enterprise-only pricing inclusion

SSO / SAMLYesEnterprise

SAML SSO (Okta, Entra ID, generic) with SCIM provisioning; SSO and SCIM is Enterprise-only on pricing

Role-Based Access ControlYesScale

6 recommended roles plus custom permission groups across 18 permission categories; Team Management named at Scale

Compliance Reporting ExportsYesScale

SARIF/CSV exports plus Reporting and Analytics dashboards at Scale; no framework-mapped report, PDF export in development

Certifications

SOC 2 Type II

Standards mapping

OWASP Top 10CWE (~900 mappings, incl. Top 25)GDPRHIPAACCPAPCI DSS

Integrations

GitHubYes
GitHub Enterprise ServerNo
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterNo
Azure DevOpsYes
REST APIYes
CLIYes
WebhooksYes

CI/CD systems

GitHub Actions (via CLI in a workflow)

IDEs

VS CodeJetBrains IDEsVisual Studio 2022

Issue trackers

JiraLinear

Chat & notifications

Slack (via Workflow Builder webhook)

Pricing & plans

$31/dev/month billed annually ($39/dev/month if billed monthly)

Minimum seats: None published on the pricing page as of 2026-08-25 (rendered page checked on both monthly and annual toggles shows no minimum-seat text)

Free$0Individual developers
  • AI SAST
  • Logic and Auth Scanning
  • Dependency Scanning
  • Secrets Detection
  • Container Scanning
  • IaC Scanning
  • No PR scanning, code quality, Corgea Agent, Jira integration, or license enforcement
Growth$31/dev/month billed annually ($39/dev/month billed monthly)Teams shipping secure code
  • Everything in Free
  • PR Scanning
  • Code Quality
  • Corgea Agent
  • JIRA Integration
  • License Enforcement
  • No custom/blocking rules, reporting & analytics, team management, or API/webhooks
Scale$39/dev/month billed annually ($49/dev/month billed monthly)A true security program (marked Most Popular)
  • Everything in Growth
  • Custom Rules
  • Blocking Rules
  • Reporting & Analytics
  • Team Management
  • APIs / Webhooks
  • No SSO/SCIM, single-tenant, SLA management, audit logs, or premium support
EnterpriseCustom (contact sales)Enterprise controls
  • Everything in Scale
  • SSO & SCIM
  • Single-tenant
  • SLA Management
  • Audit Logs
  • Premium Support
  • Quote-only, no published numbers

Who it's for

Notable strengths

  • Business-logic/auth vulnerability detection (BLAST) is the marketed core differentiator, included from the Free tier
  • PII/PHI scanning (50+ sensitive-data types) is bundled alongside secrets — not in this taxonomy but a real capability
  • Security Design Review scans PRDs/specs pre-implementation (beta)
  • AI Pentesting against live targets plus static SAST/SCA/IaC/container/secrets in one platform
  • MCP server + Agent Skill give AI coding agents (Claude Code, Cursor, Copilot, Codex) a security checkpoint

Notable limitations

  • No code-quality domain-adjacent facets: no coverage tracking, tech-debt quantification, or behavioral/git-history analytics
  • No CSPM/cloud-account-posture scanning documented anywhere in the doc set
  • SSO, SCIM and audit logs are Enterprise-only (quote-only) — no self-serve identity federation
  • IDE plugins (VS Code/JetBrains/VS2022) are on-demand only — no real-time-as-you-type findings documented
  • Several features (IaC scanning, Scheduled Scans, private package registries) require contacting support to enable despite appearing on the public pricing page

Similar tools

Other Code Security Platform tools in the directory.

FAQ

When should you choose Corgea?

Corgea best fits Indie developers, Startups, Mid-market teams, Enterprise. Business-logic/auth vulnerability detection (BLAST) is the marketed core differentiator, included from the Free tier

What languages does Corgea support?

Corgea supports 12+ languages and frameworks, including C#, Python, Ruby, Go, JavaScript, TypeScript, Java, PHP, Kotlin, Swift, and 2 more.

What does Corgea integrate with?

Corgea integrates with GitHub, GitLab, GitLab Self-Managed, Bitbucket, Azure DevOps for source control, CI systems including GitHub Actions (via CLI in a workflow), and IDEs including VS Code, JetBrains IDEs, Visual Studio 2022.

What tools are similar to Corgea?

Similar Code Security Platform tools tracked here include Aikido, Checkmarx One, GitHub Advanced Security, Semgrep.

What are Corgea's plans and pricing?

Corgea offers a free tier, with paid plans starting around $31/dev/mo; enterprise pricing is quote-only.