PLEXICUS AUTOMATION

Every finding,
routed to the next action.

Build flows that react to findings the moment they appear: open a fix, raise a ticket, wait for an approval or rotate a leaked secret. Your team designs the rules and keeps control of every step.

Illustrative flow · synthetic data

PRODUCT VIEW

Design the flow. Watch it run.

Steps on the left, the flow on the canvas, configuration on the right. A dry run shows exactly which path a finding takes before anything goes live.

Product view recreated with synthetic data.

HOW IT WORKS

Trigger, decide, act. With a human where it matters.

Each flow is a set of steps your team defines once. Plexicus runs it for every finding that matches and records what happened.

  1. 01

    Trigger

    Start a flow when a finding is created, enriched or reopened. You can also run it by hand, on a schedule or from a signed webhook.

  2. 02

    Decide

    Route by severity, finding type or repository with if and switch conditions. Every step has a success path and an error path.

  3. 03

    Act

    Draft a fix, open a ticket, notify the team, call an external API or rotate a leaked secret with the integrations you already use.

  4. 04

    Control

    Add approval gates, set timeouts and review each run. Editing a flow creates a new version, so runs in progress keep the rules they started with.

THREE WAYS TO BUILD

Start from a template, a canvas or a sentence.

Whichever way you start, the flow is validated before it is saved, and nothing runs until an admin activates it.

  • Templates Install a ready-made flow, adjust it with simple forms and activate it.
  • Visual designer See the whole flow on a canvas. Reorder steps, reconnect branches and configure each step from the side panel.
  • Prompt to flow Describe the workflow in plain language. Plexicus drafts it, shows which external systems it will contact and waits for your confirmation.
READY-MADE FLOWS

Two flows most teams start with.

Conditional remediation

Fix what is urgent. Ticket the rest.

High and critical findings go straight to automated remediation with a reviewer-ready change. Everything else becomes a triage ticket. If a fix cannot be prepared, a ticket is opened instead.

New finding → severity check → remediation or Jira ticket

Secret rotation

A leaked secret, rotated end to end.

Generate a new value, store it in HashiCorp Vault, open a draft PR that replaces the hardcoded secret with an environment variable, verify the new value, then promote the PR after approval. Any failure opens a ticket.

Rotate → store in Vault → draft PR → verify → approve → promote PR

Findings that share the same secret are grouped, so one leak means one rotation and one PR.

INTEGRATIONS

Connects to the tools your team already runs.

Every integration must pass a connection test before a flow that uses it can be activated.

Ticketing Jira · ServiceNow
Source control GitHub · GitLab · Bitbucket · Azure DevOps · Gitea · Forgejo
Secrets HashiCorp Vault · Kubernetes Secrets
Anything with an API HTTP API · outgoing webhooks
Inbound Signed webhooks (HMAC-SHA256)
GUARDRAILS

Automation your security team can sign off on.

Flows run inside the same controls as the rest of Plexicus.

Admins build, members review

Only admins can create, edit or activate flows. Everyone else can read the run history. Every change is audited.

Approvals and timeouts

Wait for an approver before sensitive steps. A step that waits too long follows its error path, and a run that exceeds its maximum duration is stopped.

Credentials stay sealed

Integration secrets are encrypted at rest and write-only: they are never shown again after saving. Outbound HTTP calls are protected against internal network access.

One run per finding

Each finding runs a flow once and runs it again only when it is reopened. Duplicate triggers do not create duplicate work.

Dry runs and replay

Test a flow before activating it, then replay any run step by step with the input and output of each step.

Scoped to your workspace

Every flow, integration and run belongs to one workspace. Nothing crosses between customers.

PLEXICUS AUTOMATION

Put your triage rules to work.

Book a walkthrough to see a finding trigger a flow, pause for approval and hand over a reviewer-ready change.

Qualification

Check whether AI Swarm Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

0 / 280

No commitment. If you don't fit, we'll tell you.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)