Code Security Platform
Corgea
AI-native AppSec platform (BLAST SAST) that finds business-logic vulnerabilities across code, dependencies, containers and IaC, and ships AI-generated pull-request fixes.
Deployment
Cloud
Languages
12+
Pricing model
Per developer seat, Quote-based / Enterprise
Free tier
Yes
Workflow coverage
Where in the development lifecycle Corgea operates.
On-demand only (Full Scan / Scan Uncommitted Changes), no as-you-type
Agent Skill + MCP for Cursor/Claude Code/Copilot/Codex
corgea setup-hooks; offline deps commands need no network
Inline PR/MR comments (GitHub/GitLab/Azure/Bitbucket/Harness); PR Scanning named at Growth
Blocks GitHub/Azure/Harness merges, or CI via --block-on; Blocking Rules at Scale
Baseline scan mode from Free tier
Scheduled re-scan cadences available; enabled at plan level rather than self-serve
AI Pentesting against live targets; needs admin enablement
Analysis & detection
Every detection and code-analysis capability tracked for Corgea.
BLAST AI-native SAST, ~900 CWEs, 11 languages
Cross-file source-to-sink taint tab in BLAST Full View
Pattern matching, entropy analysis and AI context
Not documented. Secret-scanning page covers detection methods in depth, never live/provider verification.
Lockfile/manifest scanning across 25+ ecosystems with CVE/CVSS
Checks import plus whether the vulnerable function is called; direct deps only
Typosquats, hijacked releases, backdoors via OpenSSF malicious-packages data
SCA captures per-dependency license; enforced via blocking rule; License Enforcement named at Growth
corgea deps sbom produces a CycloneDX SBOM
Terraform, CloudFormation, Kubernetes, Docker, Helm, Azure ARM
Base-image/OS/library CVEs across 7 named registries
Not documented. No CSPM/cloud-account-posture page exists anywhere in Corgea's own doc directory.
AI Pentesting actively tests live web-app targets; API-type breakdown not enumerated
9-category AI code review: cleanliness, naming, logic/correctness, incomplete work
Flags deeply-nested logic/complex one-liners qualitatively; no tracked complexity number
Detects repeated logic and magic numbers
Empty blocks, unused code, unreachable statements (CWE-563, CWE-1041)
Not documented. The 9-category quality-scanner page never mentions coverage ingestion.
Not documented, same page/domain as test coverage.
Circular dependencies (CWE-1047) and SOLID violations
Not documented. Framed as preventing technical debt qualitatively; no time/cost quantification.
Not documented. No git-history hotspot/bus-factor analysis described.
Free tier explicitly includes Logic and Auth Scanning
Not documented. GitHub PR integration page covers finding comments in depth, never a change walkthrough.
PolicyIQ UI or corgea.yaml policies; YAML needs Scale/Enterprise; Custom Rules named at Scale
AI generates and quality-checks a fix; auto-fix quota included from Free upward
Automatically opens a PR with issue and fix context on GitHub/Azure DevOps/Harness
AI classifies findings as false positive with reasoning; AST fingerprinting dedupes across scans
BLAST endpoint-reachability analysis attributes findings to the correct sub-project within a monorepo.
AI capabilities
BLAST combines LLM reasoning with static/AST analysis
Not documented. Security/agent/MCP pages are covered in depth, never a customer-supplied model or key.
Corgea exposes its own MCP server: 9 read-only tools for scans, issues, dependencies, blocking rules
Not documented. Corgea Agent's scope is fully enumerated (web chat plus 6 PR actions) with no org-wide AI-usage inventory feature.
Corgea Agent web chat lets teams query scans, issues and policies conversationally
Not documented. False-positive/fingerprinting pages describe classification and dedup in depth, never adaptive learning.
Your data is never used to train AI models; Zero Data Retention with OpenAI/Azure OpenAI
Models used
Compliance & governance
Audit Logs is an Enterprise-only pricing inclusion
SAML SSO (Okta, Entra ID, generic) with SCIM provisioning; SSO and SCIM is Enterprise-only on pricing
6 recommended roles plus custom permission groups across 18 permission categories; Team Management named at Scale
SARIF/CSV exports plus Reporting and Analytics dashboards at Scale; no framework-mapped report, PDF export in development
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Chat & notifications
Pricing & plans
$31/dev/month billed annually ($39/dev/month if billed monthly)
Minimum seats: None published on the pricing page as of 2026-08-25 (rendered page checked on both monthly and annual toggles shows no minimum-seat text)
- AI SAST
- Logic and Auth Scanning
- Dependency Scanning
- Secrets Detection
- Container Scanning
- IaC Scanning
- No PR scanning, code quality, Corgea Agent, Jira integration, or license enforcement
- Everything in Free
- PR Scanning
- Code Quality
- Corgea Agent
- JIRA Integration
- License Enforcement
- No custom/blocking rules, reporting & analytics, team management, or API/webhooks
- Everything in Growth
- Custom Rules
- Blocking Rules
- Reporting & Analytics
- Team Management
- APIs / Webhooks
- No SSO/SCIM, single-tenant, SLA management, audit logs, or premium support
- Everything in Scale
- SSO & SCIM
- Single-tenant
- SLA Management
- Audit Logs
- Premium Support
- Quote-only, no published numbers
Who it's for
Notable strengths
- Business-logic/auth vulnerability detection (BLAST) is the marketed core differentiator, included from the Free tier
- PII/PHI scanning (50+ sensitive-data types) is bundled alongside secrets — not in this taxonomy but a real capability
- Security Design Review scans PRDs/specs pre-implementation (beta)
- AI Pentesting against live targets plus static SAST/SCA/IaC/container/secrets in one platform
- MCP server + Agent Skill give AI coding agents (Claude Code, Cursor, Copilot, Codex) a security checkpoint
Notable limitations
- No code-quality domain-adjacent facets: no coverage tracking, tech-debt quantification, or behavioral/git-history analytics
- No CSPM/cloud-account-posture scanning documented anywhere in the doc set
- SSO, SCIM and audit logs are Enterprise-only (quote-only) — no self-serve identity federation
- IDE plugins (VS Code/JetBrains/VS2022) are on-demand only — no real-time-as-you-type findings documented
- Several features (IaC scanning, Scheduled Scans, private package registries) require contacting support to enable despite appearing on the public pricing page
Similar tools
Other Code Security Platform tools in the directory.
FAQ
When should you choose Corgea?
Corgea best fits Indie developers, Startups, Mid-market teams, Enterprise. Business-logic/auth vulnerability detection (BLAST) is the marketed core differentiator, included from the Free tier
What languages does Corgea support?
Corgea supports 12+ languages and frameworks, including C#, Python, Ruby, Go, JavaScript, TypeScript, Java, PHP, Kotlin, Swift, and 2 more.
What does Corgea integrate with?
Corgea integrates with GitHub, GitLab, GitLab Self-Managed, Bitbucket, Azure DevOps for source control, CI systems including GitHub Actions (via CLI in a workflow), and IDEs including VS Code, JetBrains IDEs, Visual Studio 2022.
What tools are similar to Corgea?
Similar Code Security Platform tools tracked here include Aikido, Checkmarx One, GitHub Advanced Security, Semgrep.
What are Corgea's plans and pricing?
Corgea offers a free tier, with paid plans starting around $31/dev/mo; enterprise pricing is quote-only.
Opens corgea.com in a new tab. Review Radar is not affiliated with Corgea.