Our SWE-in-a-team benchmark research is ready.Read the results.
Security review
Early access

Find the vulnerabilities that matter, with proof and a fix

SHIP reviews your code for vulnerabilities and tries each finding against a running preview before reporting it. A real finding comes back with its proof and a fix as a pull request.

For
Engineering teams without a dedicated security engineer.
Instead of
A scanner report full of findings nobody has time to verify.

Runs today: Run a security lane on one pull request with ship delegate pr --prompt-file, or schedule the security advisory triage automation.

Answer 4 questions. SHIP emails you when it opens to you.

Terminal
ship delegate pr SHIP-412 --prompt-file security-review.md
Run a security lane on one pull request today, with instructions you write in security-review.md. A lane on every pull request is in early access.
How it works

Review, prove, then fix

Step 1

Point a security lane at your code

Add a security lane to every pull request, or run it across the whole repository on a schedule. Write what it checks in plain words, from auth and injection to rules specific to your codebase.

Step 2

Prove each finding before it reaches you

The Tester tries each finding against a preview deployment of your app. A finding it cannot reproduce is marked unconfirmed instead of raised.

Step 3

Get the fix as a pull request

A confirmed finding goes to a Builder that writes the patch. Your CI, a code review and the same exploit attempt run again before the pull request is ready.

Capabilities

Keep the review inside your own boundary

Judge advisories against your own code

The security advisory triage automation runs your package manager's audit, judges whether each advisory's vulnerable code is reachable in your codebase, and patches the reachable ones.

Run the review on a different model from the author

Pick the harness and model for the security lane, so a second model reviews what the first one wrote.

Bring the findings your scanner already raised

Paste a scanner's findings into an issue and assign it to SHIP, and the agents fix them as a tested pull request.

Hold provider keys out of the sandbox

Agents run in isolated sandboxes on short-lived, scoped tokens, and your provider keys never enter them.

See what each review cost

Every review reports its duration and its cost, priced on the model that actually served it.

Comparison

Compare SHIP with Devin for Security

What each product's own pages say. Last reviewed October 2, 2026; check the vendor's page before you buy.
Devin
  • Describes Devin for Security as finding vulnerabilities, validating that they are exploitable at runtime, and shipping remediation pull requests. Devin for Security
  • Reproduces exploits in isolated sandboxes before surfacing findings to teams. Devin for Security
  • Lets teams bring their own scanner and connect existing tools through its API. Devin for Security
SHIPIn early access
  • Proves each finding against a preview of your own app, deployed by your own pipeline.
  • Runs the security lane on the harness and model you choose, on your own keys.
Available now
  • Bills per mission: one credit covers one mission of up to 3 agent-hours, and your own provider bills model usage. Key facts
FAQ

Frequently asked questions

Is SHIP's security review available today?

Partly. A security lane on every pull request, with each finding proven on a preview, is in early access. Today, run a security lane on one pull request with ship delegate pr --prompt-file, or schedule the security advisory triage automation.

Run a lane

Does SHIP replace a penetration test or an audit?

No. SHIP catches and fixes what a code review and a running preview can show, so keep the penetration tests and audits your customers and certifications require.

Can a fix change my CI configuration?

No, not unless a person asked for it. A change under .github/workflows is blocked before it is pushed, and every fix still has to pass your CI and a code review.

When is Devin the better fit?

Devin fits a team that wants a dedicated security agent available today, one that runs many investigation agents in parallel across the codebase and can use the scanners it already has, as Devin's own page describes. SHIP fits when security review should sit in the same loop as the rest of your pull requests, on the harness and model you choose.

Start a security lane on your next pull request

Join early access and choose what the security lane checks.

Join the early-access list

Answer 4 questions. SHIP emails you when it opens to you.