The most cyber-capable open model, for defenders. Try now >>

Code Security Integrations

VIDOC lives where your code does.
No extra dashboard to check

GitHub logo
GitLab logo
Slack logo
Linear logo
Cursor logo
Claude logo

Built into your source control and CI/CD

From pull request to release, VIDOC covers your whole workflow

How does VIDOC fit into CI/CD?
VIDOC works inside the tools your engineers already use, with no extra dashboard to check
GitHub integration
Reviews every pull request on open and on each new commit. Inline comments, check runs, commands and feedback in the threadConnects through the VIDOC GitHub App. GitHub.com; GitHub Enterprise Server isn't supported yet.
GitLab integration
Merge request reviews, inline comments, commit status, commands and feedbackGitLab.com and self-managed GitLab, with a self-hosted VIDOC.
Bitbucket integration
Pull request reviews, inline comments and build statusCloud and Data Center, with a self-hosted VIDOC. Comment commands aren't available on Bitbucket.
Pipeline scans
Add vidoc ci to GitHub Actions, GitLab CI or Bitbucket Pipelines. It scans the files your branch changed and lists the branch's validated issues by severity
Security gate for merges
Fail the build when critical or high vulnerabilities are still open on the branch. A short script checks the scan through the API, and you choose the severity threshold
CLI and REST API
Scan a local repository from your terminal and export a PDF security report. Use the REST API to start scans and manage findings from your own scripts

Supported languages
and technologies

Find security issues across your application code and infrastructure configurations

Java
JavaScript
TypeScript
Python
Go
C
C++
C#
PHP
Kotlin
Rust
Swift
Ruby
Scala
Dart
Terraform
Pulumi
Dockerfile
Jenkinsfile
CI files
Kubernetes
And many more

Reply to VIDOC, it learns

Tell VIDOC why a finding doesn't apply - in Slack, in the PR, in plain English. It remembers per repo and per team. No YAML, no triage dashboard

Slack

Mention VIDOC in a channel to ask about your code and findings, change a finding's status, or teach it a fact about your system. Every weekday, it posts a digest with the one issue to fix first. Available on Vidoc Cloud.

Slack#security · thread
#securityposted by VIDOC
vidoc
vidocAPP12:04 PM

Open redirect via returnTo on /auth/callback

Severity: Medium · verified
└── 2 replies· just now
MC
Maria Costa12:11 PM
@vidoc returnTo is allowlisted to our own domains in auth middleware - external redirects are dropped.
vidoc
vidocAPP12:12 PM

Got it, Maria - learned. I won't flag this for payments-api again.

Memory updated

Open redirect on allowlisted returnTo → suppressed for payments-api

Works with on-premise environments

Running GitLab self-managed or Bitbucket Data Center? Deploy VIDOC on-premise alongside them. Discuss your setup with us

Talk to a human

Frequently Asked Questions