New 2026.5.25

Plexicus 2026.5.25: Smarter Filters, AI Remediation & Reliability Improvements

Try AI remediation without a connected SCM, enjoy smarter filters, and experience a faster, more reliable platform across the board.

🚀 What’s New

  • Azure DevOps Support: You can now connect Azure DevOps repositories to Plexicus — scan, triage, and remediate findings directly alongside your GitHub, GitLab, and Bitbucket projects.
  • AI Remediation in Sandbox: Explore AI-powered fix suggestions in sandbox mode without needing to connect a repository first. Great for evaluating Plexicus before going live.
  • All Integrations in One Place: We’ve unified all third-party integrations under a single Settings page so you spend less time hunting for configuration options.
  • Smarter Login Experience: OAuth sign-in options now appear only when they’re relevant to your account setup, keeping the login screen clean and uncluttered.

🛠 Improvements

  • Access Control: We’ve rolled out the foundations of a more flexible, fine-grained permissions model — giving your team better control over who can see and do what inside Plexicus.
  • Compliance Readiness: Ongoing groundwork to support additional compliance frameworks — more details coming in future releases.
  • Upgrade Flow: Clicking the upgrade button now opens pricing in a new tab so you never lose your place in the app.

🔧 Fixes

  • Faster Startup for Large Organizations: Some organizations with a large number of users were experiencing significant delays — or outright failures — when the platform started up. The platform now becomes available in seconds, regardless of your organization’s size. All your access permissions remain fully enforced throughout.
  • Applying filters or hitting Refresh now reliably reloads the correct results — no more stale data appearing after a search.
  • Downloading your repository list as a CSV no longer returns an error.
  • The close button on finding details now correctly takes you back to the findings list, even when accessed via a direct link.
  • Starting a bulk repository scan during onboarding no longer fails unexpectedly.
  • Fixed cases where the AI remediation panel could show an incorrect status or fail to load altogether.
  • OAuth error messages are now clearer when something goes wrong during sign-in.
  • Added security protections to prevent the platform from being embedded in unauthorized third-party pages.
Qualification

Check whether AI Swarm Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

0 / 280

No commitment. If you don't fit, we'll tell you.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Private Round For investors