Spotlight · application security

Security review that arrives with proof.

Spotlight is an AI application security engineer. It reviews code, reproduces high-severity findings, proposes tested fixes, and leaves every decision ready to audit.

Become a design partner
Shipping first Spotlight. Continuous application-security review for authorized repositories.
01 · The accountability gap

One name on the audit log. Four agents in the delivery chain.

AI-assisted delivery compresses the path from prompt to production. Traditional audit trails rarely show which agents wrote, reviewed, or changed the code along the way.

What the audit log shows
14:22 jdoe merged PR #4821
14:22 → payments-auth-svc deployed to prod
The final action is visible. The chain of authorship is not.
What actually shipped to production
13:08agent-coderauthored PR #4821
13:41agent-refactorrewrote authz check
14:19agent-reviewapproved the PR
14:22agent-deployreleased to prod
The full chain matters when a change has to be explained, reproduced, or reversed.
02 · What's missing

Context, threat models, and adversarial testing.

01

Context.

The hardest vulnerabilities emerge from how permissions, data, and business logic compose. They cannot be understood from a rule match alone.

02

Threat models.

Each review starts with an explicit view of attacker goals, entry points, trust boundaries, and potential blast radius.

03

Simulation at scale.

Bounded agents test competing attack paths in parallel, then compare results before a finding is promoted.

03 · Positioning

Not another scanner. A security engineer.

A scanner flags patterns. Spotlight follows a finding through investigation, reproduction, remediation, and human sign-off.

A scanner gives you
  • A list of alerts
  • Findings without application context
  • False positives to triage
  • A backlog you still have to work
A security engineer gives you
  • Verified findings, reproduced
  • A written attack path
  • A tested fix and a pull request
  • A decision trail you can defend to an auditor
04 · The core

The Consensus Kernel.

Independent agents investigate the same risk from different angles. The Consensus Kernel weighs their evidence, surfaces disagreement, and decides whether a finding has cleared the verification threshold.

05 · Shipping first
Spotlight application security engineer · v0.1

Continuous review. Reproducible evidence.

Spotlight reviews authorized code on a schedule you control. High-severity findings are reproduced in an isolated sandbox and evaluated by the Consensus Kernel before they are marked confirmed. It then proposes a fix and requests human approval.

8
Bounded agents available for parallel investigation
100%
Confirmed findings must carry reproducible evidence
<20%
Target duplicate rate, measured on every run
Authorized repositories only · sandbox egress off by default · human approval before any PR merge.
06 · The team

One engineer now. A shared protocol for what comes next.

Spotlight is the first specialist. Future capabilities will use the same verification, provenance, and human-approval protocol.

01
Spotlight
Application Security Engineer

Finds, verifies, and fixes code vulnerabilities.

Shipping now
02
Exposure Intelligence
Vulnerability Management

Maps where each exposure lives — all the way to customer impact.

On the roadmap
03
Agent Identity
Security Auditor

Traces every AI action to a human, with signed proof.

On the roadmap
04
Data Protection
Data Protection Specialist

Guards information by meaning, not by filename.

On the roadmap
07 · Across the cycle

One accountability layer across the security lifecycle.

STEP 01
Build & ship code
Spotlight
STEP 02
Know your exposure
Exposure Intelligence
STEP 03
Agents act for you
Agent Identity
STEP 04
Share & handle data
Data Protection

The roadmap extends one protocol across each stage: evidence for every finding, provenance for every action, and human approval for every consequential change.

08 · Roadmap

From application security to an accountable security function.

01 · 0–12 MO
The security engineer

Spotlight ships — an AI application-security engineer for authorized repositories.

02 · 12–24 MO
The security team

Exposure management and a security auditor join — across cloud and infrastructure.

03 · 24–36 MO
The security function

A full autonomous security function across code, infrastructure, identity, and data.

09 · Posture

Authorized code only. Sandboxed execution. Human approval before any change. An attributable audit trail on every action.

10 · The through-line

It does the work. And proves it.

Every confirmed finding traces to reproducible evidence. Every consequential action waits for a human. Every decision leaves a record. That is how autonomous security earns trust.

Become a design partner