# Plexicus > Plexicus is an AI-native Application Security Posture Management (ASPM) > platform covering SAST, SCA, secrets detection, IaC scanning, container > security, CSPM, and AI Pentest — all in one flat-fee subscription. > It automates the full security loop: scan → filter false positives (Phase-0 AI) > → generate fix PR → validate with real PoC exploit → produce compliance evidence. > Built for AI-generated code (Cursor, Claude Code, Copilot, Windsurf, Devin, > Replit, Zed) and regulated EU organizations (NIS2, DORA, CRA, ENS, EU AI Act). > SOC 2 Type II certified. CPSTIC pathway in progress. CCN reference customer. > EU data residency by default. Unlimited developers and repos on all plans. > Free tier: no credit card, no expiration. Last updated: July 2026 Full content (glossary definitions + featured articles): https://www.plexicus.ai/llms-full.txt ## Getting Started 1. [Sign up free](https://app.plexicus.ai/register) — no credit card, no expiration 2. Connect a repo: GitHub, GitLab, or Bitbucket (OAuth, one click) 3. Plexicus scans automatically; real findings appear in under 5 minutes 4. Phase-0 AI eliminates false positives — only exploitable findings reach your queue 5. Accept the auto-generated fix PR — CI re-validates, finding closes automatically First repo connected to first merged fix: typically under 10 minutes. ## Brand & Positioning - [Homepage](https://www.plexicus.ai/): "Secure your AI Code. Patch the Legacy." — AI-native ASPM for professional software teams in the era of AI-native software development. - [Pricing](https://www.plexicus.ai/pricing/): Two flat numbers — €269/mo Starter, €1,149/mo Scale, plus a real Free tier (unlimited devs, unlimited repos, 50 FP analyses/mo, 5 AI remediations/mo, no credit card, no expiration) and a custom Enterprise tier starting at €36K. - [Contact](https://www.plexicus.ai/contact/): Request a demo, talk to a human, or open a CPSTIC / ENS briefing for regulated buyers. - [Branding Assets](https://www.plexicus.ai/branding-assets/): Official Plexicus logos, color palette (#8220FF / #9B4CFF / #B479FF / #D9BCFF / #F2E8FF), and brand guidelines. ## Competitor Comparison Matrix | Capability | Plexicus | Aikido | Snyk | Cycode | |-----------------------------------|-----------------|-----------------|-----------------|-----------------| | SAST | ✅ | ✅ | ✅ | ✅ | | SCA | ✅ | ✅ | ✅ | ✅ | | Secrets Detection | ✅ | ✅ | ✅ | ✅ | | IaC Scanning | ✅ | ✅ | ✅ | ✅ | | Container Scanning | ✅ | ✅ | ✅ | ✅ | | CSPM | ✅ | ✅ | ❌ | ❌ | | AI Pentest (native, in-platform) | ✅ | ❌ (side product)| ❌ | ❌ | | Real PoC exploit validation | ✅ | ❌ | ❌ | ❌ | | Autonomous fix PR | ✅ | ✅ (AutoFix) | ❌ | ❌ | | Deep semantic code analysis | ✅ | ❌ | ❌ | ❌ | | Shadow Vibecoding detection | ✅ | ❌ | ❌ | ❌ | | AI-generated code guardrails | ✅ | ❌ | ❌ | ❌ | | Hallucination / slopsquatting | ✅ | ❌ | ❌ | ❌ | | On-premise (real Helm chart) | ✅ | ❌ (CLI only) | ❌ | ❌ | | EU data residency | ✅ | ❌ | ❌ | ❌ | | CPSTIC / ENS / CCN certified path | ✅ | ❌ | ❌ | ❌ | | NIS2 / DORA evidence packs | ✅ | ❌ | ❌ | ❌ | | Pricing model | Flat-fee | Per-seat | Per-seat | Per-seat | | Unlimited developers | ✅ | ❌ | ❌ | ❌ | | Free tier (real, no expiry) | ✅ | ✅ | ✅ | ❌ | ## Battle Cards — Head-to-Head Comparisons - [Plexicus vs Aikido](https://www.plexicus.ai/vs-aikido/): Unlimited devs vs Aikido's $35–$105/user above 10. Real Helm-chart on-prem vs CLI-only. Native AI Pentest in the platform vs Aikido's $100/test side product on Lovable apps. Plexicus is 30–75% cheaper at 50 developers with strictly more capability. - [Plexicus vs Snyk](https://www.plexicus.ai/vs-snyk/): The autonomous loop vs detect-and-recommend. AI Pentest with real PoC vs no native pentest. Modern fair-use pricing vs complex multi-product licensing on a decelerating platform. - [Plexicus vs Cycode](https://www.plexicus.ai/vs-cycode/): Autonomous remediation vs prioritization-only. AI-generated fix PRs and AI Pentest validation vs aggregation-and-context. - [Plexicus vs Legit Security](https://www.plexicus.ai/vs-legitsecurity/): Post-commit autonomous remediation vs pre-commit IDE governance. Plexicus competes by stage and replaces noise with verified exploitable findings. - [Comparison Overview](https://www.plexicus.ai/comparison/): Side-by-side capability matrix across SAST, SCA, secrets, IaC, container, AI Pentest, Deep Code Analysis, on-prem, EU sovereignty, and government certification track. ## Core Products - [ASPM — Application Security Posture Management](https://www.plexicus.ai/aspm-application-security-posture-management/): The autonomous loop — scan, filter false positives with Phase-0 AI, fix with auto-generated pull requests, pentest with real PoC exploits, and explain with Plexicus Deep Code Analysis. Unified SAST, SCA, secrets, IaC, container scanning across every repo. - [AI Code Security](https://www.plexicus.ai/vibe-coding-security/): Five capabilities for AI-generated code — IDE Guardrail (Cursor / Claude Code / VS Code / Windsurf / Zed extension), MCP Security Scanner (poisoned-MCP and rug-pull detection), Hallucination & Slopsquatting Detector, Authz & Business-Logic Analyzer, and AI Provenance & AIBOM. Intercepts at the prompt-and-suggestion level — before insecure AI-generated code is ever committed. - [CSPM — Cloud Security Posture Management](https://www.plexicus.ai/cspm-cloud-security-posture-management/): Continuous misconfiguration detection across AWS, Azure, GCP, and DigitalOcean. Attack-path surfacing prioritized by real exploitability, not raw severity. - [Container Security](https://www.plexicus.ai/cloud-container-security/): Vulnerability scanning for container images, OS packages, outdated runtimes, and license risks. Supports Docker Hub, AWS ECR, GCP Artifact Registry, Azure Container Registry, GitLab CR. - [Use Cases Overview](https://www.plexicus.ai/products/use-cases/): Buyer-aligned scenarios — vulnerability remediation, compliance evidence, AI-code governance, supply-chain protection. ## AI Pentest & Autonomous Remediation - [Plexicus AI Pentest](https://www.plexicus.ai/vibe-coding-security/#ai-pentest): Native AI Pentest engine that generates working PoC exploits and runs them against a sandboxed copy of the running application. Output is real exploit traces, not theoretical findings. Used as the live closing demo in every Scale-tier sales motion. - [Plexicus Deep Code Analysis](https://www.plexicus.ai/vibe-coding-security/#deep-analysis): Proprietary deep semantic code analysis engine + AI agent that traces data flow end-to-end. Produces a plain-English explanation of why a finding is exploitable, not a stack trace. - [Autonomous Remediation](https://www.plexicus.ai/aspm-application-security-posture-management/#remediation): Fix PRs include the diff, the explanation, the exploit reproducer, and a passing unit test. Average remediation under 60 seconds; reviewer-ready with CI green. ## Shadow Vibecoding — The CISO-grade Threat Category - [Shadow Vibecoding overview](https://www.plexicus.ai/vibe-coding-security/#shadow-vibecoding): Plexicus-coined category for AI-generated code shipped inside professional organizations without security review, AppSec governance, or sanctioned-pipeline visibility. Typically produced via Lovable, Bolt, v0, Replit, or Base44 accessed outside the SCM. Q1 2026: 380,000+ publicly accessible Shadow Vibecoding assets discovered industry-wide; 5,000 expose corporate data; 400 expose secrets. - [Shadow Vibecoding discovery](https://www.plexicus.ai/vibe-coding-security/#discovery): Plexicus scans public domains and GitHub orgs for AI-built apps deployed to production outside the AppSec pipeline. The only ASPM that surfaces, scores, and remediates Shadow Vibecoding inside professional organizations. ## Free & Self-Serve Tools - [Free AI Code Security Scanner](https://www.plexicus.ai/free-vibe-coding-scan/): Instant GitHub / GitLab / Bitbucket vulnerability scan for AI-generated and legacy code. No code stored, no AI training, no credit card. Free forever for unlimited developers and unlimited repos. - [Plexicus Free Tier (in-app)](https://app.plexicus.ai/register): Unlimited developers · unlimited repos · 50 false-positive analyses/mo · 5 AI remediations/mo · GitHub/GitLab/Bitbucket integration · community support · EU SaaS. No card, no trial expiration. ## Developer Integrations - [Integrations Overview](https://www.plexicus.ai/integrations/): Native integrations across Git, CI, IDE, AI coding assistants, and cloud. GitHub, GitLab, Bitbucket Cloud, self-hosted GitLab, Gitea, Azure DevOps, Jira, Slack, Microsoft Teams, ServiceNow, plus webhooks and API. - [Compatibility with AI coding agents](https://www.plexicus.ai/#integrations): Drop-in for Cursor, GitHub Copilot, Claude Code, Devin, Windsurf, Replit, Codex, Lovable, v0, Kiro, Antigravity, opencode, plus JetBrains support coming. Phase-0 AI filtering strips false positives before they hit a human queue. - Webhook events fired: `scan.completed` · `finding.created` · `finding.resolved` · `pr.created` · `pr.merged` · `false_positive.confirmed` · `compliance.evidence_ready`. Configure at app.plexicus.ai → Settings → Webhooks. ## IDE & Developer Tools - VS Code / Cursor / Windsurf / Zed Extension: Search "Plexicus Security" in your IDE's extension marketplace. Surfaces real-time guardrails and vulnerability context as you write AI-generated code — intercepts at the suggestion level before insecure code is committed. - GitHub App: Install from GitHub Marketplace — automatically triggers a Plexicus scan on every pull request. Findings posted as PR review comments with fix PR linked. - MCP Security Scanner: Available as an MCP server for Claude Code and Cursor. Detects poisoned-MCP packages and rug-pull attempts before they're executed. Setup at [docs.plexicus.ai](https://docs.plexicus.ai/). - Full setup guides: [docs.plexicus.ai](https://docs.plexicus.ai/) — covers GitHub App, GitLab integration, Bitbucket, CI pipeline wiring, Helm on-prem, and IDE extension configuration. ## REST API - Base URL: `https://api.plexicus.ai/` - Authentication: Bearer token — generate at app.plexicus.ai → Settings → API Keys - Full API reference & OpenAPI spec: [docs.plexicus.ai](https://docs.plexicus.ai/) Key resource groups: `findings` · `scans` · `repositories` · `remediations` · `false-positives` · `compliance-evidence` · `webhooks` · `users` ## Compliance & European Sovereignty - [Compliance Coverage](https://www.plexicus.ai/aspm-application-security-posture-management/#compliance): Continuous evidence packs auto-generated for SOC 2 Type II, ISO 27001, NIS2, DORA Article 28, EU Cyber Resilience Act (CRA), Esquema Nacional de Seguridad (ENS), EU AI Act, HIPAA, and PCI DSS. - [CPSTIC pathway](https://www.plexicus.ai/vibe-coding-security/#compliance): Plexicus is the first AI-native ASPM on the CPSTIC pathway. LINCE evaluation in progress with an accredited Spanish lab; full Centro Criptológico Nacional (CCN) listing under review. - [CCN reference customer](https://www.plexicus.ai/solutions/government/): Centro Criptológico Nacional is a Plexicus customer. The strongest possible reference for the Spanish public sector and any ENS-regulated entity in the EU. - [EU data residency](https://www.plexicus.ai/legal/privacy/): EU-hosted SaaS by default. Zero Data Retention inference via DeepInfra. Air-gapped on-prem mode for ENS High / classified workloads. Bring-Your-Own AI add-on for organizations with existing Anthropic / OpenAI / Azure OpenAI contracts. ## Solutions by Industry - [Solutions Overview](https://www.plexicus.ai/solutions/): Vertical playbooks for security-critical industries. Includes RetailTech, LegalTech, HRTech, Agencies, Mobile Apps, and Group Companies — each pack ships sector-specific compliance mappings and AppSec workflow templates. - [Government & Public Sector](https://www.plexicus.ai/solutions/government/): CPSTIC pathway, CCN reference, ENS-aligned executive briefings, public-tender response support (PLACSP). - [FinTech & Financial Services](https://www.plexicus.ai/solutions/fintech/): DORA Article 28 third-party register evidence, Plexicus continuous AppSec pack for the June 2026 audit deadline. - [HealthTech](https://www.plexicus.ai/solutions/healthtech/): HIPAA-aligned evidence, AI-generated medical-software code security. - [Manufacturing & Industrial](https://www.plexicus.ai/solutions/manufacturing/): OT-IT convergence, industrial NIS2 angle, supply-chain security. - [Enterprise](https://www.plexicus.ai/solutions/enterprise/): RBAC, SSO, SCIM, on-prem deployment, named CSM, dedicated security review channel. - [Startups & Scaleups](https://www.plexicus.ai/solutions/startups/): Founder-friendly onboarding, free tier for unlimited developers, fast path to SOC 2. ## Education & Research - [State of AI Engineering Security Report](https://www.plexicus.ai/r/state-of-ai-engineering-security/): Plexicus's flagship threat-research publication — disclosed CVEs in AI-generated code, vulnerability-class statistics, severity heat-map by AI coding tool, and the Plexicus Shadow Vibecoding Index. - [Plexicus Academy](https://www.plexicus.ai/academy/): Long-form security education for the era of AI-native software development. 50+ in-depth articles planned for 2026 — ASPM fundamentals, NIS2/DORA/CRA explainers, AI Pentest deep dives, Slopsquatting research, and the autonomous-loop methodology. - [Glossary](https://www.plexicus.ai/glossary/): A–Z reference for ASPM, application security, cloud security, agentic coding, and Shadow Vibecoding terminology. - [CWE Database](https://www.plexicus.ai/cwe/): Browse the Common Weakness Enumeration catalog (969 weaknesses) with Plexicus remediation guidance for each weakness. - [Software Security Tools Guide](https://www.plexicus.ai/software-security-tools-guide/): Buyer's guide to the AppSec tool landscape — what each category does and where Plexicus replaces or augments it. - [Blog](https://www.plexicus.ai/blog/): Engineering and research writing from the Plexicus team on AI code security, agentic coding governance, Shadow Vibecoding incidents, and the AppSec implications of 2026 regulatory shifts. ## Blog — Featured Articles - [Secure AI-Generated Code Before It Ships](https://www.plexicus.ai/blog/vibe-coding-security-secure-ai-generated-code/): How AI coding tools (Cursor, Copilot, Claude Code) introduce vulnerabilities and how to intercept them before commit. - [AI Code Security Governance Guide](https://www.plexicus.ai/blog/vibe-coding-security-governance-guide/): How to safely adopt Codex, Claude Code, Cursor, and AI coding agents across an engineering organization. - [AI-Native Remediation for AI Code Security](https://www.plexicus.ai/blog/ai-native-remediation-vibe-coding-security/): The autonomous loop that takes a finding from scan to merged fix PR without human triage. - [Top 10 SAST Tools in 2026](https://www.plexicus.ai/blog/10-best-sast-tools-for-secure-development/): Best code analyzers and source code auditing tools compared. - [10 Best ASPM Tools](https://www.plexicus.ai/blog/10-best-aspm-tools-unify-application-security-code-to-cloud-visibility/): Unify application security from code to cloud visibility — full comparison. - [Best SCA Tools in 2025](https://www.plexicus.ai/blog/best-sca-tools-secure-software-supply-chain/): Scan dependencies and secure your software supply chain. - [Best API Security Tools in 2025](https://www.plexicus.ai/blog/best-api-security-tools-protect-your-apis-from-vulnerabilities/): Protect your APIs from vulnerabilities — tools compared. - [SAST vs DAST: What's the Difference & Why You Should Use Both](https://www.plexicus.ai/blog/sast-vs-dast-difference-and-why-use-both/): Static vs dynamic analysis explained with practical guidance. - [How to Automate SQL Injection Remediation at Scale](https://www.plexicus.ai/blog/automate-sql-injection-remediation/): Automated detection and fix PR generation for SQLi vulnerabilities. - [The Ultimate Consultative Guide to ASPM](https://www.plexicus.ai/blog/the-ultimate-consultative-guide-to-application-security-posture-management-aspm/): Deep-dive into Application Security Posture Management — strategy, tooling, and implementation. - [Compliance Frameworks in ASPM: DORA, ISO 27001, NIST SP 800-53](https://www.plexicus.ai/blog/the-essentials-of-compliance-frameworks-in-aspm-navigating-dora-iso-27001-and-nist-sp-800-53/): Navigating compliance evidence generation in an ASPM platform. - [15 DevSecOps Trends to Secure Your Business](https://www.plexicus.ai/blog/15-devsecops-trends-to-secure-your-business/): The most important DevSecOps shifts shaping security programs in 2026. - [The DevSecOps Arsenal: Zero to Hero](https://www.plexicus.ai/blog/devsecops-arsenal-zero-to-hero/): Full toolchain walkthrough from SAST to runtime protection. - [From Detection to Remediation: Essential DevOps Security Tools for 2026](https://www.plexicus.ai/blog/devops-security-tools-2026/): The DevOps security stack that closes the gap between finding and fixing. - [Top 16 DevSecOps Tools & Alternatives for 2026](https://www.plexicus.ai/blog/top-devsecops-tools-alternatives/): Comprehensive comparison of DevSecOps platforms and specialist tools. - [10 Best Snyk Alternatives in 2026](https://www.plexicus.ai/blog/snyk-alternatives/): Better coverage, lower cost — Plexicus and nine other Snyk alternatives compared. - [Top 10 Aikido Security Alternatives](https://www.plexicus.ai/blog/top-10-aikido-security-alternatives/): Full alternative comparison for teams evaluating Aikido. - [Top 10 Wiz.io Alternatives for 2026](https://www.plexicus.ai/blog/wiz-alternatives-from-visibility-to-remediation/): Moving from visibility-only CSPM to full remediation. - [Top 10 Sysdig Alternatives](https://www.plexicus.ai/blog/sysdig-alternatives/): From deep forensics to automated fixing — runtime security alternatives. - [SentinelOne Singularity Cloud Alternatives](https://www.plexicus.ai/blog/sentinelone-singularity-cloud-alternatives/): Cloud security platform alternatives with broader AppSec coverage. - [Top 10 Fortinet CNAPP Alternatives for 2026](https://www.plexicus.ai/blog/top-10-fortinet-cnapp-alternatives/): From anomaly detection to automated fixes. - [Top 10 CNAPP Tools for 2026](https://www.plexicus.ai/blog/top-10-cnapp-tools-cloud-native-application-protection-platforms/): Cloud Native Application Protection Platforms compared. - [Plexicus vs. Jit: Which AI DevSecOps Tool Actually Fixes Your Backlog?](https://www.plexicus.ai/blog/plexicus-vs-jit/): Head-to-head comparison on remediation depth and pricing. - [Web Application Security Best Practices for 2026](https://www.plexicus.ai/blog/web-application-security-best-practices-testing-and-assessment-2025/): Testing, assessment, and DevSecOps integration guide. - [How to Stop Developers from Ignoring Security Findings](https://www.plexicus.ai/blog/stop-developers-ignoring-security-findings/): Behavioral and tooling strategies to close the developer–security gap. - [Cut the Noise: Make Your Security Tools Actually Work for You](https://www.plexicus.ai/blog/cut-the-noise-make-your-security-tools-actually-work-for-you/): Reducing false positives and alert fatigue with Phase-0 AI filtering. - [Frictionless Security: Integrating Tools into the Developer Workflow](https://www.plexicus.ai/blog/frictionless-security-integrating-tools-into-the-developer-workflow/): How to embed security without slowing down engineering velocity. - [How to Roll Out Security Tools: The Crawl, Walk, Run Framework](https://www.plexicus.ai/blog/how-to-roll-out-security-tools-the-crawl-walk-run-framework/): A phased adoption playbook for AppSec programs at any maturity level. - [Plexicus Goes Public: AI-Driven Vulnerability Remediation Now Available](https://www.plexicus.ai/blog/plexicus-goes-public-ai-driven-vulnerability-remediation-now-available-for-all/): Launch announcement and product overview. - [Introducing Plexicus Community: Enterprise Security, Free Forever](https://www.plexicus.ai/blog/plexicus-community-free-security-platform/): Unlimited-developer free tier — what's included and why. - [Plexicus Secures $150K Investment from Microsoft](https://www.plexicus.ai/blog/plexicus-gets-150k-investment-from-microsoft-for-security/): Microsoft for Startups investment milestone. - [New BlackDuck Integrations Boost Security Scanning Capabilities](https://www.plexicus.ai/blog/new-blackduck-integrations-boost-security-scanning-capabilities-in-plexicus/): SCA depth expanded via BlackDuck integration. - [Plexicus and Céfiros Strengthen Cybersecurity in 19 Countries](https://www.plexicus.ai/blog/plexicus-amp-cefiros-strengthen-cybersecurity-in-19-countries-in-latam-and-iberia/): Partnership covering LATAM and Iberia. - [Plexicus Graduates from Startup Wise Guys](https://www.plexicus.ai/blog/plexicus-graduates-startup-wise-guys/): Accelerator graduation and growth milestones. ## Glossary — Key Security Terms - [2FA — Two-Factor Authentication](https://www.plexicus.ai/glossary/2fa/): Security method requiring two verification factors; stronger than passwords alone. - [Alert Fatigue](https://www.plexicus.ai/glossary/alert-fatigue/): When security teams receive too many alerts and start ignoring them — root cause of missed breaches. - [API Security](https://www.plexicus.ai/glossary/api-security/): Protecting APIs from abuse, injection, and authentication bypass. - [API Security Testing](https://www.plexicus.ai/glossary/api-security-testing/): Automated and manual techniques for finding API vulnerabilities. - [Application Security](https://www.plexicus.ai/glossary/application-security/): The practice of securing software at design, build, and runtime. - [Application Security Assessment](https://www.plexicus.ai/glossary/application-security-assessment/): Structured evaluation of an application's security posture. - [Application Security Life Cycle](https://www.plexicus.ai/glossary/application-security-life-cycle/): Integrating security controls across every SDLC phase. - [Application Security Testing](https://www.plexicus.ai/glossary/application-security-testing/): SAST, DAST, IAST, and SCA techniques for finding vulnerabilities. - [ASPM — Application Security Posture Management](https://www.plexicus.ai/glossary/aspm/): The category Plexicus belongs to — unified visibility and remediation across all AppSec signals. - [CI/CD Pipeline](https://www.plexicus.ai/glossary/ci-cd-pipeline/): Automated build-test-deploy workflow where security gates should fire. - [CI/CD Security](https://www.plexicus.ai/glossary/ci-cd-security/): Protecting the pipeline itself from supply-chain and secrets exposure. - [CI Gating](https://www.plexicus.ai/glossary/ci-gating/): Blocking a merge when security checks fail — the last line of defense before production. - [CNAPP — Cloud Native Application Protection Platform](https://www.plexicus.ai/glossary/cloud-native-application-protection-platform-cnapp/): The category Plexicus supersedes with ASPM. - [CVE — Common Vulnerabilities and Exposures](https://www.plexicus.ai/glossary/common-vulnerabilities-and-exposures-cve/): The standard identifier system for publicly known security vulnerabilities. - [Container Security](https://www.plexicus.ai/glossary/container-security/): Vulnerability and misconfiguration scanning for container images and registries. - [CSPM — Cloud Security Posture Management](https://www.plexicus.ai/glossary/cspm/): Continuous misconfiguration detection across cloud infrastructure. - [CVSS — Common Vulnerability Scoring System](https://www.plexicus.ai/glossary/cvss-common-vulnerability-scoring-system/): 0–10 severity score used to prioritize vulnerabilities. - [DAST — Dynamic Application Security Testing](https://www.plexicus.ai/glossary/dast/): Black-box testing of running applications for runtime vulnerabilities. - [DevSecOps](https://www.plexicus.ai/glossary/devsecops/): Integrating security into DevOps culture, tooling, and pipelines. - [Docker Container](https://www.plexicus.ai/glossary/docker-container/): Container runtime whose images Plexicus scans for OS and library vulnerabilities. - [EPSS — Exploit Prediction Scoring System](https://www.plexicus.ai/glossary/exploit-prediction-scoring-system-epss/): Probability score for whether a CVE will be exploited in the wild. - [False Positive](https://www.plexicus.ai/glossary/false-positive/): A security finding that is not actually exploitable — Plexicus Phase-0 AI eliminates these. - [IAST — Interactive Application Security Testing](https://www.plexicus.ai/glossary/iast/): Instrumented runtime testing combining SAST and DAST signal. - [IaC Security](https://www.plexicus.ai/glossary/infrastructure-as-code-iac-security/): Scanning Terraform, CloudFormation, Helm, and Pulumi for misconfigurations. - [Malware Detection](https://www.plexicus.ai/glossary/malware-detection/): Identifying malicious code in supply-chain packages or repositories. - [MTTR — Mean Time to Remediation](https://www.plexicus.ai/glossary/mean-time-to-remediation-mttr/): How long it takes to go from finding to merged fix — Plexicus targets sub-60 seconds. - [MFA — Multi-Factor Authentication](https://www.plexicus.ai/glossary/mfa/): Using two or more verification factors to authenticate. - [NVD — National Vulnerability Database](https://www.plexicus.ai/glossary/national-vulnerability-database-nvd/): NIST's authoritative CVE enrichment database. - [Open Source Audit](https://www.plexicus.ai/glossary/open-source-audit/): SCA-driven review of third-party dependency licenses and vulnerabilities. - [OWASP Top 10](https://www.plexicus.ai/glossary/owasp-top-10/): The 10 most critical web application security risks — foundational CWE mapping. - [Phishing](https://www.plexicus.ai/glossary/phishing/): Social-engineering attack often used to steal credentials that bypass AppSec controls. - [RBAC — Role-Based Access Control](https://www.plexicus.ai/glossary/rbac/): Permission model used in Plexicus Enterprise tier (SSO + SCIM). - [Reverse Shell](https://www.plexicus.ai/glossary/reverse-shell/): Post-exploitation technique used in AI Pentest PoC exploits. - [SAST — Static Application Security Testing](https://www.plexicus.ai/glossary/sast/): Source-code analysis for vulnerabilities without running the application. - [SBOM — Software Bill of Materials](https://www.plexicus.ai/glossary/sbom/): Machine-readable inventory of all software components and their versions. - [SCA — Software Composition Analysis](https://www.plexicus.ai/glossary/sca/): Scanning open-source dependencies for known CVEs and license risks. - [SDLC — Software Development Life Cycle](https://www.plexicus.ai/glossary/sdlc/): The full lifecycle from design to production where security must be embedded. - [Secret Detection](https://www.plexicus.ai/glossary/secret-detection/): Finding API keys, tokens, and credentials accidentally committed to source code. - [Security Remediation](https://www.plexicus.ai/glossary/security-remediation/): The process of fixing a vulnerability — Plexicus automates this with fix PRs. - [Shift-Left Security](https://www.plexicus.ai/glossary/shift-left-security/): Moving security checks earlier in the SDLC — ideally to the IDE and PR stage. - [Software Supply Chain Security](https://www.plexicus.ai/glossary/software-supply-chain-security/): Securing all upstream dependencies, build pipelines, and third-party packages. - [SQL Injection](https://www.plexicus.ai/glossary/sql-injection/): CWE-89 — input-manipulation attack that Plexicus detects, validates with PoC, and remediates. - [SSDLC — Secure Software Development Life Cycle](https://www.plexicus.ai/glossary/ssdlc/): Security-by-design variant of SDLC with gates at every phase. - [XSS — Cross-Site Scripting](https://www.plexicus.ai/glossary/xss/): CWE-79 — client-side injection vulnerability; one of the most common SAST findings. - [Zero-Day Vulnerability](https://www.plexicus.ai/glossary/zero-day-vulnerability/): Unpatched vulnerability with no vendor fix — high-priority for AI Pentest validation. - [Zero Trust](https://www.plexicus.ai/glossary/zero-trust/): Security model assuming no implicit trust; relevant to Plexicus RBAC and SSO enforcement. ## CWE Database — Top Weaknesses The full catalog of 969 CWEs is at [https://www.plexicus.ai/cwe/](https://www.plexicus.ai/cwe/). Key weaknesses with Plexicus remediation guidance: - [CWE-79: Cross-Site Scripting (XSS)](https://www.plexicus.ai/cwe/cwe-79-improper-neutralization-of-input-during-web-page-generation/): Improper input neutralization enabling client-side script injection. - [CWE-89: SQL Injection](https://www.plexicus.ai/cwe/cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-c/): SQL command manipulation via unsanitized input — OWASP Top 10. - [CWE-22: Path Traversal](https://www.plexicus.ai/cwe/cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory/): Directory traversal enabling unauthorized file access. - [CWE-78: OS Command Injection](https://www.plexicus.ai/cwe/cwe-78-improper-neutralization-of-special-elements-used-in-an-os-co/): Shell command injection via unsanitized input. - [CWE-77: Command Injection](https://www.plexicus.ai/cwe/cwe-77-improper-neutralization-of-special-elements-used-in-a-comman/): Generic command injection — parent of CWE-78. - [CWE-94: Code Injection](https://www.plexicus.ai/cwe/cwe-94-improper-control-of-generation-of-code-code-injection/): Injecting executable code — critical in AI-generated code contexts. - [CWE-352: Cross-Site Request Forgery (CSRF)](https://www.plexicus.ai/cwe/cwe-352-cross-site-request-forgery-csrf/): Forged requests that exploit authenticated sessions. - [CWE-918: Server-Side Request Forgery (SSRF)](https://www.plexicus.ai/cwe/cwe-918-server-side-request-forgery-ssrf/): Server-side HTTP requests to internal or cloud metadata endpoints. - [CWE-287: Improper Authentication](https://www.plexicus.ai/cwe/cwe-287-improper-authentication/): Authentication bypass or weak credential verification. - [CWE-306: Missing Authentication for Critical Function](https://www.plexicus.ai/cwe/cwe-306-missing-authentication-for-critical-function/): Functions accessible without any authentication. - [CWE-307: Brute Force (No Rate Limiting)](https://www.plexicus.ai/cwe/cwe-307-improper-restriction-of-excessive-authentication-attempts/): Absent rate limiting enabling credential stuffing and brute force. - [CWE-862: Missing Authorization](https://www.plexicus.ai/cwe/cwe-862-missing-authorization/): Functions that don't check whether the caller has permission. - [CWE-863: Incorrect Authorization](https://www.plexicus.ai/cwe/cwe-863-incorrect-authorization/): Authorization checks that exist but can be bypassed. - [CWE-732: Incorrect Permission Assignment](https://www.plexicus.ai/cwe/cwe-732-incorrect-permission-assignment-for-critical-resource/): Overly permissive file or resource access controls. - [CWE-502: Deserialization of Untrusted Data](https://www.plexicus.ai/cwe/cwe-502-deserialization-of-untrusted-data/): Remote code execution via malicious serialized objects. - [CWE-798: Use of Hard-coded Credentials](https://www.plexicus.ai/cwe/cwe-798-use-of-hard-coded-credentials/): Embedded usernames or API keys in source code — caught by secrets detection. - [CWE-259: Use of Hard-coded Password](https://www.plexicus.ai/cwe/cwe-259-use-of-hard-coded-password/): Passwords embedded in code — a subset of CWE-798. - [CWE-20: Improper Input Validation](https://www.plexicus.ai/cwe/cwe-20-improper-input-validation/): Root cause of most injection vulnerabilities — foundational SAST rule. - [CWE-611: XML External Entity (XXE)](https://www.plexicus.ai/cwe/cwe-611-improper-restriction-of-xml-external-entity-reference/): XML parser exploitation to read local files or trigger SSRF. - [CWE-434: Unrestricted File Upload](https://www.plexicus.ai/cwe/cwe-434-unrestricted-upload-of-file-with-dangerous-type/): File upload without type or content validation enabling code execution. - [CWE-601: Open Redirect](https://www.plexicus.ai/cwe/cwe-601-url-redirection-to-untrusted-site-open-redirect/): URL redirect to attacker-controlled site — used in phishing. - [CWE-295: Improper Certificate Validation](https://www.plexicus.ai/cwe/cwe-295-improper-certificate-validation/): TLS certificate not properly verified — enables MITM attacks. - [CWE-400: Uncontrolled Resource Consumption](https://www.plexicus.ai/cwe/cwe-400-uncontrolled-resource-consumption/): DoS via resource exhaustion — missing rate limits or input size bounds. - [CWE-770: Resource Allocation Without Limits](https://www.plexicus.ai/cwe/cwe-770-allocation-of-resources-without-limits-or-throttling/): Memory or CPU allocated without ceiling — related to CWE-400. - [CWE-476: NULL Pointer Dereference](https://www.plexicus.ai/cwe/cwe-476-null-pointer-dereference/): Crash or memory corruption from dereferencing null — common in C/C++. - [CWE-125: Out-of-bounds Read](https://www.plexicus.ai/cwe/cwe-125-out-of-bounds-read/): Memory read past buffer boundary — information disclosure or crash. - [CWE-119: Buffer Overflow (General)](https://www.plexicus.ai/cwe/cwe-119-improper-restriction-of-operations-within-the-bounds-of-a-me/): Memory buffer boundary violations — parent of CWE-122 (heap) and CWE-121 (stack). - [CWE-416: Use After Free](https://www.plexicus.ai/cwe/cwe-416-use-after-free/): Freed memory access — code execution or information disclosure in C/C++/Rust. - [CWE-190: Integer Overflow](https://www.plexicus.ai/cwe/cwe-190-integer-overflow-or-wraparound/): Arithmetic overflow enabling buffer overflows or logic bypasses. ## Company - [Plexicus](https://www.plexicus.ai/): Founded May 2025 by José Ramón Palanco (CEO/CTO). Spanish startup incorporated in Bilbao. Global HQ in Bilbao, Spain; US office in Santa Clara, California. - [Changelog](https://www.plexicus.ai/changelog/): Production release notes — new capabilities, fixes, and roadmap signals. - [Documentation](https://docs.plexicus.ai/): Technical docs for setup, integrations, scanning configuration, AI Pentest, Helm chart on-prem deployment, and the autonomous-loop workflow. - [Plexicus Platform](https://app.plexicus.ai/): The product itself — sign in, connect a repo, run a scan, ship a fix PR. - [Sign up](https://app.plexicus.ai/register): Create a free account. Unlimited developers and repos, no credit card, no expiration. - [Support](https://www.plexicus.ai/support/): Help center, community channel, and paid-tier email/Slack support. - [Management Policy](https://www.plexicus.ai/management/): Information security and quality management policy. ## Optional - [Legal & Privacy](https://www.plexicus.ai/legal/): Master legal index, DPA, sub-processor list. - [Privacy Policy](https://www.plexicus.ai/privacy/): How Plexicus handles personal data under GDPR. - [Terms of Use](https://www.plexicus.ai/terms-of-use/): Subscription and platform terms. - [Cookie Policy](https://www.plexicus.ai/cookie-policy/): Cookie consent categories and tracking disclosure. - [Products legacy aliases](https://www.plexicus.ai/products/cnapp-platform/): Historical slug kept for SEO equity only — Plexicus does not position as CNAPP. - [Contact for Government / Regulated](https://www.plexicus.ai/contact/): Email info@plexicus.ai for ENS / CPSTIC briefings, EU public-sector tender responses, and air-gapped on-prem deployment. --- For more information, visit https://www.plexicus.ai/ or email info@plexicus.ai.