Step 1
Point a security lane at your code
Add a security lane to every pull request, or run it across the whole repository on a schedule. Write what it checks in plain words, from auth and injection to rules specific to your codebase.
SHIP reviews your code for vulnerabilities and tries each finding against a running preview before reporting it. A real finding comes back with its proof and a fix as a pull request.
Runs today: Run a security lane on one pull request with ship delegate pr --prompt-file, or schedule the security advisory triage automation.
Answer 4 questions. SHIP emails you when it opens to you.
ship delegate pr SHIP-412 --prompt-file security-review.mdStep 1
Add a security lane to every pull request, or run it across the whole repository on a schedule. Write what it checks in plain words, from auth and injection to rules specific to your codebase.
Step 2
The Tester tries each finding against a preview deployment of your app. A finding it cannot reproduce is marked unconfirmed instead of raised.
Step 3
A confirmed finding goes to a Builder that writes the patch. Your CI, a code review and the same exploit attempt run again before the pull request is ready.
The security advisory triage automation runs your package manager's audit, judges whether each advisory's vulnerable code is reachable in your codebase, and patches the reachable ones.
Pick the harness and model for the security lane, so a second model reviews what the first one wrote.
Paste a scanner's findings into an issue and assign it to SHIP, and the agents fix them as a tested pull request.
Agents run in isolated sandboxes on short-lived, scoped tokens, and your provider keys never enter them.
Every review reports its duration and its cost, priced on the model that actually served it.
| Devin |
|
|---|---|
| SHIP | In early access
|
Partly. A security lane on every pull request, with each finding proven on a preview, is in early access. Today, run a security lane on one pull request with ship delegate pr --prompt-file, or schedule the security advisory triage automation.
No. SHIP catches and fixes what a code review and a running preview can show, so keep the penetration tests and audits your customers and certifications require.
No, not unless a person asked for it. A change under .github/workflows is blocked before it is pushed, and every fix still has to pass your CI and a code review.
Devin fits a team that wants a dedicated security agent available today, one that runs many investigation agents in parallel across the codebase and can use the scanners it already has, as Devin's own page describes. SHIP fits when security review should sit in the same loop as the rest of your pull requests, on the harness and model you choose.
Join early access and choose what the security lane checks.
Answer 4 questions. SHIP emails you when it opens to you.