Features
Leonidus covers the full loop: find the problem, explain the fix, prove the posture. Here's what that means in practice.
Scanning
Static code analysis
Every scan runs industry-standard SAST rules plus Leonidus's own rule set, tuned against real detection gaps.
Secret detection
API keys, tokens, and credentials found in source and configuration before they leak.
Dependency & container scanning
Known CVEs in packages and images, with severity, exploitability, and upgrade paths.
URL pen-testing (DAST)
Point Leonidus at a running app: TLS posture, security headers, exposed endpoints, and known vulnerabilities — with domain-ownership checks built in.
Scheduled scans
Cron-style schedules per repo or URL, with change-only notifications so quiet weeks stay quiet.
Triage & remediation
AI triage on every finding
Each finding gets a plain-language 'why this is bad' and 'what to do right now', so fixes don't wait on a security specialist.
Fingerprinted findings
The same vulnerability keeps the same identity across rescans — history, suppressions, and diffs stay accurate.
SLA tracking & assignment
Findings carry owners and due dates computed from severity. Breaches surface automatically.
Suppression rules with audit trails
Silence a false positive with a justification and an expiry — never with a shrug.
Compliance
160+ frameworks
SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, FedRAMP, NIST, state privacy laws, and more — each broken into controls with remediation guidance.
Scan-to-control mapping
Automatable controls are evaluated from real scan evidence, not questionnaires.
Assessments with two-tier review
Point-in-time posture snapshots reviewed first by AI, then by a human — with gaps called out per control.
Policies, vendors, access reviews
The rest of the audit binder lives here too: policy attestation, vendor risk tiers, and periodic access reviews.
Pipeline & integrations
Pre-deployment gate
One API call returns pass, warn, or block against your policy. Wire it into CI and stop shipping known-bad builds.
GitHub PR scanning
Webhook-triggered scans on every pull request, with results posted back as a comment.
REST API + MCP server
Everything the UI does, the API does. The remote MCP server brings scans into Claude Code, Cursor, and any MCP client.
Reports & exports
Executive PDF reports, SARIF for your tooling, SBOM exports, and compliance matrices in XLSX.