See which vulnerabilities actually matter.
Farion evaluates vulnerabilities in the context of real application paths, data flows, and dependencies — turning scanner findings into traceable decisions, evidence, and concrete fixes.
| Route Path | Exploitability | SCA | SAST | DAST | |
|---|---|---|---|---|---|
APIGET/api/restaurants/…/menu | 5 | 1 | 0 | ||
APIGET/api/orders/…/track | 1 | 0 | 0 | ||
APIPOST/api/auth/login | 7 | 2 | 2 | ||
Open redirect past a host allowlistCWE-601: URL Redirection to Untrusted Site ('Open Redirect') SCA high Applications that parse an external URL with UriComponentsBuilder, validate its host and then use it may be vulnerable to open redirect or SSRF. | |||||
APIPOST/api/orders | 1 | 1 | 0 | ||
APIGET/api/users | 7 | 2 | 1 | ||
APIGET/api/search/export | 1 | 0 | 0 | ||
APIGET/api/restaurants/feed | 5 | 0 | 1 | ||
APIPUT/api/users/:id | 5 | 1 | 0 | ||
APIGET/api/restaurants/:id | 1 | 0 | 0 | ||
APIGET/api/orders | 1 | 0 | 0 | ||
APIGET/api/admin/dashboard | 2 | 0 | 0 | ||
APIGET/api/users/…/profile | 2 | 1 | 0 | ||
APIPOST/api/auth/reset-password | 3 | 1 | 0 | ||
APIGET/api/health | 0 | 0 | 0 | ||
APIPOST/api/payments/checkout | 3 | 1 | 0 | ||
APIGET/api/config/features | 1 | 0 | 0 | ||
APIDELETE/api/users/:id | 4 | 1 | 0 | ||
APIPUT/api/orders/…/status | 1 | 0 | 0 | ||
Software supply chain security has changed.
AI is shortening the window between vulnerability disclosure and exploitation. At the same time, the CRA and NIS2 raise requirements for vulnerability management and software supply chain security. Organizations within scope must systematically assess risks, address them appropriately and maintain a clear record of their actions.
Which vulnerabilities expose your application to attack? And how do you demonstrate that you have acted appropriately?
Which components make up
Farion identifies direct and transitive dependencies and their versions to build an SBOM. This provides the foundation for matching known vulnerabilities and analyzing their relevance.
1,240
libraries
Which dependencies are
Farion's own vulnerability database matches components against known security issues. Vendor advisories and technical details identify the affected versions and functions.
420
findings
Which application paths lead to
Farion connects application entry points with call paths in your code. The analysis examines which routes or handlers can reach the affected function in a dependency.
FARION DATA FLOW ENGINE180
reachable findings
Which inputs reach
Farion tracks values across functions and files into the affected dependency. The analysis examines which arguments an attacker can influence and how validation or sanitization affects that path.
FARION DATA FLOW ENGINE58
findings with relevant data flows
Under what conditions can it be
Farion brings together code evidence, vendor advisories, technical attack prerequisites and current exploitation signals. Specialized AI assesses the evidence and explains which findings should take priority.
FARION SECURITY AI7
prioritized findings
Priorities you can justify.
7
prioritized findings in this example
Farion identifies which vulnerabilities should take priority based on application context and the threat landscape. You receive the technical evidence to plan targeted remediation and explain the reasoning behind your decisions.
360° application security. One platform.
Built on the Farion Data Flow Engine and Exploitability AI, Farion brings vulnerability detection, AI-based prioritization and end-to-end vulnerability management together with deployment tracking and license monitoring across your SBOM.
Farion Exploitability AI combines code evidence, Farion's own threat intelligence and technical exploit context. Every assessment stays connected to its reasoning and the underlying analysis results.
Explore exploitability analysisRoute analysis with AI analysis, patch and data flow · Illustrative product view with example dataBuilt for AI-era application security. Not adapted to it.
Most modern AppSec products still rely on architectures designed long before generative AI existed: a legacy SAST or SCA engine, heuristic prioritization, and an external language model bolted on to summarize the findings. The AI is a post-processing step, not part of the security engine — so it inherits every limitation of the scanner underneath it. Farion was built the other way around.
Native analysis in JavaScript/TypeScript, Python, Go, Rust, C, C++, C#, Java and Kotlin
Compiler-grade analysis per language — SSA-based, context- and field-sensitive.
Our security SLMs, hosted in Germany
Specialized security small language models. Customer code is never used for model training.
Dedicated & on-premises deployment
Run Farion fully isolated behind your own perimeter — built for regulated environments.
Certified in 2026 as a research and development project by the Bescheinigungsstelle Forschungszulage (BSFZ), the German research-allowance certification body
“Hybrid analysis method for the AI-assisted assessment of the exploitability of software vulnerabilities”Farion Dataflow Engine
Farion Security Scanner
Farion Security AI
Findings
Farion ThreatIntel Database
Built on enterprise experience.
Farion is developed by Nexode Consulting. The platform draws on years of security and DevSecOps consulting engagements for organizations such as Bundesdruckerei, Arvato and CARIAD (Nexode consulting engagements). This experience shapes our approach to application security, compliance and data sovereignty.
Farion was built for these requirements, with proprietary analysis technology and its own security AI. It is available as a cloud service and for on-premises or air-gapped deployment.
What our customers say
We've got the answers
- Active Verification is an optional capability that dynamically exercises your running application to confirm findings against a real target — for customers with a suitable test environment.
- Target ownership must be verified (DNS TXT, HTTP token, or repo-to-domain proof).
- You explicitly confirm authorization before each run.
- Rate limits and safe-mode presets are enforced by default.
- Full audit logs track who ran what, when, and against which target.
- Active Verification is available as an add-on for the Growth plan and included in the Enterprise plan.
The standard Farion hosted service processes and stores data in Farion-operated infrastructure in Germany (AWS Frankfurt, eu-central-1). Enterprise customers can agree dedicated deployment options within the EU or an on-premises deployment to suit their operating requirements.
- Shared SaaS: Hosted in Germany, tenant-isolated.
- Dedicated: From 100 contributors on most Kubernetes clusters — in your cloud or your data centre (cloud-native stack).
- On-premises and air-gapped: On the Enterprise plan.
AI AutoFix creates pull requests with suggested changes for detected vulnerabilities. Each PR explains the vulnerability and the reasoning behind the proposed fix. Your team reviews the changes before merge and deployment. Monthly allowances: 2 (Free), 10 (Startup), 50 (Growth) or custom (Enterprise).
Yes. Every new workspace starts with a 14-day free trial of the Growth plan: all features and up to 10 contributors, on your own code, no credit card required. When it ends you choose Startup, Growth or Enterprise, or continue on the Free plan; scanning pauses until you do, and everything you found stays.
Vulnerability handling obligations from 11 December 2027
Address vulnerabilities. Document your response for the CRA.
From 11 December 2027, manufacturers within scope must handle vulnerabilities throughout the support period: keep an SBOM, address vulnerabilities without undue delay and document what was done (Annex I Part II). Farion supports this with SBOMs, reasoned exploitability assessments and a documented remediation history through to deployment. Reporting an actively exploited vulnerability under Article 14 remains the manufacturer's own obligation; Farion's records support it but do not perform it.
