Quick
- CI/CD pipelines
- Pull request validation
- Rapid smoke tests
Standard
- Regular security assessments
- Pre-release validation
- Development milestones
Deep
- Comprehensive security audits
- Pre-production reviews
- Critical application assessments
semgrep, AST structural search, secrets, supply-chain checks) and then systematically validates top candidates dynamically.
Deep mode is the default. It explores edge cases, chained vulnerabilities, and complex attack paths.