Skip to content

Fendix for SaaS

Ship quickly without making security a guess.

Turn disconnected application-security findings into a release decision engineering can understand, enforce, and verify.

Release outcomes

A security gate designed for shipping teams.

Prioritize proven risk

Focus review on reachable and corroborated evidence where it exists.

Decide in CI/CD

Apply committed policy consistently before production.

Explain every result

Give engineering the rule, evidence, component, and remediation context.

Verify the fix

Re-run evidence and record whether remediation changed the result.

03Security Decision Record

One defensible security decision for every release.

See what changed, what was tested, which policies were triggered, and why the release received its decision.

Illustrative example — fictional data, not a customer record.Decided:

Release

payments-api · 2.14.0 · commit 9f3c1ab

Policy: .fendix.yaml v1 — blocks at CRITICAL

Highest finding status

WARN

Decision reasons

  1. 011 HIGH finding reachable from an authenticated route — warns, does not block, under your policy.
  2. 02Dependency scan did not complete, so part of the release is undecided.
  3. 031 accepted risk expires in 6 days and has no fix in progress.

Tests and scanners

  • Static analysis· completed
  • Secret scanning· completed
  • API probing· completed
  • Dependency scan· failed
  • Infrastructure config· not configured

Coverage gaps

  • Dependency scan failed — lockfile could not be resolved. Re-run before relying on this decision.
  • Infrastructure config scanning is not configured for this repository.

Since previous release

  • 2 new
  • 1 fixed
  • 11 persisting

Accepted risks

Wildcard CORS origin on /public/status

Accepted by Security Lead · expires 2026-08-04

Assigned owners

  • SQL injection in refund handler

    @payments-team · due 2026-07-29

  • Missing rate limit on /api/v2/login

    @platform-security · due 2026-08-07

Fix verification

  • 1 verified resolved
  • 1 still present
  • 1 queued

Human accountability

Awaiting sign-off. The accountable owner can approve this recommendation, override it with a documented reason, accept a risk for a defined period, or request verification after a fix.

Audit trail · 4 recorded events — policy evaluated, decision recorded, risk accepted, owner assigned.

  • BLOCK
  • WARN
  • INFO

Bring the release your team is deciding now.

We’ll use your repository or staging API to show how the decision is reached.

Book a Technical Walkthrough