Corgea is an AI-native application security platform that scans source code, dependencies, infrastructure-as-code, and container images. It combines multiple security layers, including SAST, secrets detection, and dependency scanning, into a single control plane. The platform targets engineering and security teams that want fewer disconnected scanning tools.
Corgea was built to reduce the operational burden that traditional SAST tools create for developers. Legacy scanners often produce high volumes of false positives and offer little context about real-world exploitability. Corgea’s approach aims to cut through that noise so teams can focus on issues attackers could actually reach.
The platform integrates with source repositories, CI/CD pipelines, IDEs, and third-party scanners. It maps reachable endpoints and traces execution paths from public entry points, such as login routes, into the codebase. When it finds a vulnerability, it generates a code patch that developers can review before merging.
Differentiators include reachability-aware prioritization, automated patch generation, and support for Model Context Protocol (MCP) agent workflows. Corgea maintains AICPA SOC 2 Type II compliance and offers a free tier alongside a 14-day trial of its Growth plan with no credit card required.
Pricing
Corgea offers four tiers. Free costs $0 per month and covers AI SAST, logic and auth scanning, dependency scanning, secrets detection, container scanning, and IaC scanning for up to 2 team members and 10 repositories, with 10 PR scans and 10 SAST auto-fixes per month. Growth costs $39 per developer per month with a 5-seat minimum, adds PR scanning, code quality checks, the Corgea Agent, JIRA integration, and license enforcement, and covers up to 100 repositories with 50 SAST auto-fixes per month. Scale costs $49 per developer per month with a 20-seat minimum, adds custom rules, blocking rules, reporting and analytics, team management, and APIs and webhooks, and covers up to 200 repositories with 200 SAST auto-fixes per month. Enterprise pricing is custom and includes SSO and SCIM, single-tenant deployment, SLA management, audit logs, and unlimited repositories, seats, and auto-fixes. A 14-day trial of Growth is available without a credit card.
* Disclaimer: Please note that pricing information may not be up to date. For the most accurate and current pricing details, refer to the official website.
Key Features
- ✓
AI SAST with review-ready generated code fixes
- ✓
Reachability-aware prioritization tracing public routes to code
- ✓
Logic and authorization flaw detection in workflows
- ✓
Dependency scanning with reachability and upgrade guidance
- ✓
IaC and container image scanning for cloud pipelines
- ✓
AI pentest producing auditor-ready reports
Use Cases
Automated Pull Request Reviews
Engineering teams connect Corgea to source control so it scans every pull request automatically. It generates review-ready patches before code merges, preventing vulnerabilities from reaching production.
Business Logic and Auth Auditing
Security engineers use Corgea to uncover hidden authentication gaps and logic flaws. These issues often escape traditional pattern-matching SAST tools entirely.
Reachability-Based Vulnerability Triage
Security teams use reachability mapping to separate theoretical code issues from vulnerabilities reachable by attackers. This lets them target remediation at real exposure first.
Software Supply Chain Management
Developers and DevOps staff use dependency scanning and license enforcement to spot vulnerable third-party packages. This helps verify exploitability and maintain compliance across projects.
Cloud Infrastructure and Container Security
DevOps teams run automated IaC and container image scans inside CI/CD pipelines. This catches cloud misconfigurations early, before they reach production environments.
Strengths & Weaknesses
Strengths
Reduces false positives through context-aware, reachability-based analysis.
Generates review-ready code patches, cutting manual remediation work.
Integrates natively with major repositories, IDEs, and ticketing tools.
Covers SAST, dependencies, IaC, containers, secrets, and pentesting in one platform.
Maintains SOC 2 Type II compliance and offers a free tier with a no-card trial.
Weaknesses
The Free plan limits usage to 2 team members and 10 repositories.
Growth and Scale plans require minimum purchases of 5 and 20 developer seats.
Monthly SAST auto-fix counts are capped on every non-Enterprise tier.
Two risk and governance integrations, Brinqa and Nucleus, are still listed as coming soon.
Who Is This For?
Developers who want to fix security flaws inside their IDE or pull requests without wading through noisy false positives.
Security engineers and CISOs consolidating fragmented scanners into one platform and prioritizing risk through reachability mapping.
DevOps and platform engineers needing automated shift-left guardrails for infrastructure-as-code, containers, and dependencies.
Fintech, SaaS, and enterprise organizations in regulated markets that require verified SOC 2 Type II compliance and audit logging.
Frequently Asked Questions
What is included in the Free plan?
The Free plan includes AI SAST, logic and auth scanning, dependency scanning, secrets detection, container scanning, and IaC scanning for up to 2 team members and 10 repositories.
How is a developer seat counted?
Developer seats are counted as contributing developers active in the last 90 days, subject to minimum seat thresholds on Growth and Scale plans.
Can I start without a credit card?
Yes. You can sign up for the Free plan or start a 14-day Growth trial without entering payment details.
What happens when I upgrade from Free to Growth or Scale?
You keep your existing repository setup and scan history while unlocking PR scanning, code quality checks, the Corgea Agent, JIRA integration, and higher auto-fix limits.
Does Corgea support enterprise procurement requirements?
Yes. The Enterprise tier includes SSO, SCIM, single-tenant deployment, SLA management, audit logs, and premium support.
Is Corgea SOC 2 Type II compliant?
Corgea maintains AICPA SOC 2 Type II controls for how it handles customer code and security data.
Which code repositories and IDEs does Corgea connect to?
It connects to GitHub, GitLab, Azure DevOps, BitBucket, and Harness, plus IDE extensions for VS Code, Cursor, Windsurf, Visual Studio 2022, and IntelliJ.
Are all of Corgea’s listed integrations available today?
Nearly all are live, including Claude Code, Copilot, OpenCode, Codex, and Linear. Only the Brinqa and Nucleus risk and governance integrations remain listed as coming soon.
Does Corgea replace existing scanners like Snyk or Semgrep?
Corgea can import findings from third-party scanners such as Snyk and Semgrep rather than requiring teams to remove them outright.
How many SAST auto-fixes are included per plan?
Free includes 10 auto-fixes per month, Growth includes 50, Scale includes 200, and Enterprise is unlimited.
Corgea connects to GitHub, GitLab, Azure DevOps, BitBucket, and Harness for source control, and to Visual Studio Code, Cursor, Windsurf, Visual Studio 2022, IntelliJ, Claude Code, Copilot, OpenCode, and Codex for IDE workflows. It offers a CLI, plus JIRA and Linear for ticketing, and imports findings from Snyk, Semgrep, Checkmarx, CodeQL, Fortify, and Coverity. Additional integrations cover Splunk for SIEM, Slack for alerts, Zapier for automation, and Entra ID, Okta, and Active Directory for SSO. Corgea also supports MCP, an API, and webhooks for custom workflows. Brinqa and Nucleus, both risk and governance integrations, remain listed as coming soon.