Overview
Gecko analyses source code alongside infrastructure configuration, design documentation, and runtime data. Because it resolves how the system is built and deployed, it detects business logic flaws and broken authentication and authorisation chains that pattern based static analysis cannot represent, and it suppresses findings that are not reachable. Related issues are chained into full attack paths, so two low severity findings that combine into an account takeover are scored accordingly rather than reported separately. Security teams can define policies as natural language rules, which Gecko enforces across every repository. Deep multi repository scans run continuously, while pull request checks run on every commit and can block merges by severity.
Findings are assigned to the developer who introduced the issue, with a validated proof of concept attached, which removes the manual triage step. Gecko generates the fix, runs the test suite against it, refactors when tests fail, and opens it as a pull request in the style of the surrounding codebase. Developers refine the patch through comments on the pull request, and Gecko retains that feedback for subsequent findings. Gecko also groups related findings back to their common design decision, fixes the root cause once, and scans the rest of the organisation for variants of the same pattern. Gecko supports GitHub, GitLab, Jira, Linear, and Slack, SSO via SAML or OIDC with SCIM provisioning, and a documented v1 API. Gecko is SOC 2 compliant.
Highlights
- Detects business logic flaws and multi step vulnerabilities. Gecko builds a semantic graph across your code, infrastructure, and services, resolving how data actually flows between trust boundaries to find broken authentication and authorisation chains.
- Validates every finding before it reaches a developer. Each one ships with a working proof of concept and is ranked by whether it is reachable in production and what data it touches, with chained issues scored together as full attack paths.
- Remediates at scale rather than one bug at a time. Gecko writes the fix, tests it, and opens a pull request in the style of your codebase. It then traces groups of findings back to the design decision behind them and removes every variant across the organisation.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Contributing Dev Seat | Access for one contributing developer | $0.01 |
The following dimensions are not included in the contract terms, which will be charged based on your usage.
Dimension | Description | Cost/unit |
|---|---|---|
Additional Developer Seat | Seat added beyond the contracted amount | $0.01 |
Custom Usage Fee | Custom charges agreed with your account team | $0.01 |
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Gecko Security offers support via email at gecko@gecko.security . Our team is available Monday-Friday, 9am-6pm EST, with response times within 24 hours for standard issues and 4 hours for critical issues. Enterprise customers receive priority support with dedicated SLAs and a named support contact.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.