What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Split between first-party scanning and third-party ingestion: confirm current scope with vendor
- Self-hosted deployment availability: verify
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Legit Security starts by discovering the software factory itself. It connects to source control, CI systems, artifact registries and related infrastructure, then builds an inventory of every repository, pipeline, build server, runner and integration in use, including the ones nobody remembered were there. Against that inventory it evaluates configuration: unprotected default branches, pipelines that can be edited without review, overly permissive tokens, self-hosted runners exposed to untrusted workloads, unsigned artifacts, dependencies pulled from unverified sources.
Around that spine it adds application-level coverage: secret detection across repository history, dependency and SBOM analysis, static analysis, and ingestion of findings from scanners you already run. Because the pipeline inventory exists first, findings arrive with provenance attached, so a vulnerable artifact can be traced to the build that produced it and the repository and commit behind it. That lineage is what distinguishes this from a plain findings aggregator.
Where it fits
This operates above and across the pipeline, not as a build step. The buyer is typically a security or platform engineering leader who needs to answer questions about the integrity of the delivery process, often because of a supply chain framework such as SLSA, an SSDF attestation requirement or a customer security questionnaire. It requires broad read access to your development infrastructure, and it becomes useful once you have enough independent pipelines that no single person knows how they are all configured.
Strengths
- Automatic discovery of build infrastructure surfaces shadow pipelines and orphaned runners that inventory spreadsheets always miss.
- Artifact-to-commit lineage answers provenance questions directly rather than by reconstruction after an incident.
- Maps findings to supply chain frameworks and attestation requirements, which is a real reporting need for vendors selling into regulated buyers.
- Works alongside existing scanners rather than demanding you replace them.
Limitations
- Requires extensive, privileged read access across source control and CI, which needs its own review and is a hard sell in some organizations.
- Pipeline posture findings often land with platform engineering rather than with the security team that bought the tool, so remediation depends on a cross-team relationship that must exist first.
- The application scanning layer is not as deep as dedicated SAST or SCA products, so the platform is best treated as a posture and provenance layer rather than a scanner replacement.
Who it suits
Well matched to organizations with many teams, many pipelines and an explicit supply chain integrity requirement, whether driven by regulation, customer contracts or a recent industry incident. It is unnecessary for a small team with one repository and one pipeline, where the entire attack surface it examines can be reviewed manually in an afternoon.
Used Legit Security? Recommend it under your own name and title.
Recommend this tool