LeonidusbyPisteyo

Features

Leonidus covers the full loop: find the problem, explain the fix, prove the posture. Here's what that means in practice.

Scanning

Static code analysis

Every scan runs industry-standard SAST rules plus Leonidus's own rule set, tuned against real detection gaps.

Secret detection

API keys, tokens, and credentials found in source and configuration before they leak.

Dependency & container scanning

Known CVEs in packages and images, with severity, exploitability, and upgrade paths.

URL pen-testing (DAST)

Point Leonidus at a running app: TLS posture, security headers, exposed endpoints, and known vulnerabilities — with domain-ownership checks built in.

Scheduled scans

Cron-style schedules per repo or URL, with change-only notifications so quiet weeks stay quiet.

Triage & remediation

AI triage on every finding

Each finding gets a plain-language 'why this is bad' and 'what to do right now', so fixes don't wait on a security specialist.

Fingerprinted findings

The same vulnerability keeps the same identity across rescans — history, suppressions, and diffs stay accurate.

SLA tracking & assignment

Findings carry owners and due dates computed from severity. Breaches surface automatically.

Suppression rules with audit trails

Silence a false positive with a justification and an expiry — never with a shrug.

Compliance

160+ frameworks

SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, FedRAMP, NIST, state privacy laws, and more — each broken into controls with remediation guidance.

Scan-to-control mapping

Automatable controls are evaluated from real scan evidence, not questionnaires.

Assessments with two-tier review

Point-in-time posture snapshots reviewed first by AI, then by a human — with gaps called out per control.

Policies, vendors, access reviews

The rest of the audit binder lives here too: policy attestation, vendor risk tiers, and periodic access reviews.

Pipeline & integrations

Pre-deployment gate

One API call returns pass, warn, or block against your policy. Wire it into CI and stop shipping known-bad builds.

GitHub PR scanning

Webhook-triggered scans on every pull request, with results posted back as a comment.

REST API + MCP server

Everything the UI does, the API does. The remote MCP server brings scans into Claude Code, Cursor, and any MCP client.

Reports & exports

Executive PDF reports, SARIF for your tooling, SBOM exports, and compliance matrices in XLSX.

See it on your own code

Start scanning