GScan
Security & Compliance
Most scanners check one thing. GScan runs six security analyses and your quality checks in a single pass, over your whole repository, then hands back every finding scored, standards-tagged, and ready to fix, with the trend since your last scan.
Secrets, dependencies, code, infrastructure, SBOM, and end-of-life, plus complexity and duplication. One branch scan. One report.
No tool sprawlEvery issue carries a CWE, OWASP category, and CVSS score, a code snippet, remediation, and a deep-link to the exact lines.
Scored and sourcedEach category is compared to your last scan, so you see whether risk is climbing or falling, commit by commit.
Regression, caughtReads through GKS, writes back only through your keys. Cloud, VPC, or on-prem. Your source never leaves your boundary.
Your data stays yoursNot a raw tool dump. One report: six security analyses and your quality checks, each finding scored, tagged, and ready to fix, with the deltas since your last scan.
GScan doesn't just say "possible issue." Each finding carries a severity and CVSS score, the CWE and OWASP category, the exact file and lines, a code snippet, and remediation you can apply, with a deep-link straight to the source.
CWE, OWASP, and a CVSS score on every security finding, so it maps to the frameworks your auditors already use.
Each finding ships with a concrete fix and reference links, not a bare rule ID to go and google.
One click to the exact lines in GitHub, GitLab, Bitbucket, or Azure DevOps.
GScan inventories every dependency, resolves its license and copyleft exposure, and flags what's vulnerable or end-of-life, the risk that lives in code you never wrote.
Every scan is compared to the last. Findings carry deltas, mitigations are time-boxed, and false positives stay dismissed, so the report reflects real, current risk, not noise you already triaged.
A vulnerability caught in a scheduled scan costs a fix. The same vulnerability caught in production costs an incident, a disclosure, and trust you don't get back.
GScan surfaces the risk. Your team decides what ships.
GScan never touches your systems directly. It reads through GKS, the governed knowledge layer you control, and writes findings back only through your keys.
On a scan, GScan requests what it needs: your branch source, dependency manifests, and infrastructure config.
GKS checks policy at intake, releasing only what this scan is authorized to read.
Scoped context: the branch, its dependencies, and IaC, nothing beyond it, for the analyses you enabled.
A scored, tagged report lands in Garth, written back to your environment through your key.
Garth Universe is the control plane. Choose which repos GScan watches, pick which analyses run, scope files in or out, set the schedule, and route it through your own model keys.
Agents never touch your systems directly. Everything reads through GKS, the governed boundary you control, and every action writes back only through your keys.
GKS ingests only the sources you authorize. Nothing you have not connected ever enters.
Each scan gets the exact source, dependencies, and config it needs, filtered at intake, and nothing beyond it.
Agents read from GKS, never your host systems. Misuse stops at the boundary, not inside your stack.
When an agent writes findings back to a system, it goes through credentials you provision, scope, and revoke at will.
GKS runs in Garth Cloud. Your systems stream in over an encrypted, governed channel. Fastest to start, nothing to host.
Point tools each read one signal. GScan grounds security and quality on the same shared brain as review, release, and ROI, so it sees what none of them can.
| Capability | GScan | Snyk | Semgrep | GitHub AS |
|---|---|---|---|---|
| Security & quality in one branch pass | ✓ | ~ | ~ | ~ |
| Secrets + SCA + SAST + IaC + SBOM + EOL, unified | ✓ | ~ | ~ | ~ |
| SBOM with license & copyleft policy | ✓ | ~ | – | ~ |
| Scan-over-scan trend deltas per category | ✓ | ~ | – | – |
| Time-boxed mitigations with audit trail | ✓ | ~ | – | ~ |
| Governed data boundary · VPC / on-prem | ✓ | ~ | ~ | – |
| One shared brain across review, security & release | ✓ | – | – | – |
The wedge is competitive. The platform is not.
Most teams pay for a secrets tool, an SCA tool, a SAST tool, an IaC tool, and an SBOM tool, then pay engineers to reconcile them. Move the sliders to your team and see the return.
Illustrative model. Assumes GScan replaces your standalone scanning tools and absorbs ~70% of the time spent reconciling their separate reports into one. GScan priced at the $10/dev blended Standard rate. Security-tooling scope only; real value is typically higher across the wider workflow.
GScan bills on active developers, a contributor active in the trailing 30 days. Dormant seats are never charged. Discounted when bundled into the Garth Suite.
Building with the first cohort? Design-partner rates, plus a 3-week all-features trial with your own key. Bring your own model key and the price drops further.
Every plan includes GKS (the knowledge backbone), GAssist, and G-IDE. Bundle GScan into the Garth Suite and it always prices below licensing it apart.
Start a 3-week, all-features pilot with your own model key: GScan running six security analyses and your quality checks across your real repositories, in one report.