ASPM Dashboard
Security findings at Finastra lived in disconnected tools — GitHub CodeQL, SCA, container scanning — so there was no single view of application security posture, and maturity conversations ran on anecdotes.
A single pane of glass — Go backend, React frontend — that aggregates CodeQL, SCA, and container-scanning results, computes a maturity score enriched with SAMM assessments, API security posture, WAF coverage, and other static signals, and answers teams' posture questions through a RAG assistant grounded in platform data and documentation.
Built with / Go / React / RAG / Vector DB
Signals / GitHub CodeQL / SCA / Container scanning / SAMM / API security posture / WAF coverage