Exposure scanning that opens the fix as a pull request.

Exposure scanning that opens the fix as a pull request.

Quorum scans your repos and cloud accounts every hour, writes the fix for each exposure it can reach, and waits for two of your reviewers.

Free for two repos. No card.

Reads the code hosts and clouds you already run. Nothing to install on your servers.

Reads the code hosts and clouds you already run. Nothing to install on your servers.

GitHub logo
GitLab logo
Bitbucket logo
Amazon Web Services logo
Google Cloud logo
Microsoft Azure logo
Cloudflare logo
Terraform logo

A findings list your team can actually finish

Quorum ranks what an attacker can reach, writes the change, and keeps a record of every scan.

Findings ranked by what can be reached

Every finding shows how it is reached: a public build log, an open port, a route that takes user input. The ones with a path come first, and each has its fix pull request beside it.

Quorum findings list ranked by reachability, each with its fix pull request

The fix arrives as a diff you already know how to review

Quorum changes the fewest lines it can, in the style your code already uses, and runs your own CI before it asks anyone to look. A lodash bump is two lines. A leaked key is one.

Quorum dependency fix pull request with the reachable call path

A scan every hour, and a record of each one

Hourly scans finish in about four minutes for a typical account. Every run, finding, approval and merge is kept for 13 months, ready for the auditor who asks.

Quorum scans page with open findings falling from 61 to 14 over 30 days

Six exposures Quorum fixes with a pull request

Everything else waits in the findings list with its evidence, until you decide.

Exposure and what the pull request changes

Median time to merge

Leaked secrets

Moves the value into your secrets manager, replaces the line with a reference and adds a CI check for live key patterns.

22 min

Public storage

Removes the public statement and turns on the public access block, in the Terraform that owns the bucket.

31 min

Open ports

Narrows the security group rule to your office and VPN ranges, with the old rule kept in the description.

44 min

Reachable vulnerable packages

Bumps to the nearest fixed version, only when your code calls the vulnerable function.

1 h 12 min

Over-broad IAM

Replaces wildcards with the actions the role actually used in the last 90 days.

2 h 05 min

Expiring certificates

Renews or rotates the certificate 14 days before it expires.

17 min

Medians across 312 teams, June to August 2026. Demo figures.

From read-only access to a merged fix in three steps

Setup takes about ten minutes. After that the only thing Quorum asks of your team is a review.

Connect with read-only access

Install the GitHub, GitLab or Bitbucket app and add a read-only role for each cloud account. Quorum cannot push to your default branch or change anything in your cloud.

About 10 minutes

Quorum scans every hour

It reads what changed since the last run, traces how each exposure is reached and writes the smallest fix it can.

4 minutes a scan

Your reviewers decide

The fix arrives as a pull request with your checks already run. It merges when your quorum approves, and not before.

22 minutes to merge, median

Quorum never merges on its own

You set the quorum per fix type: how many approvals, and from which team. Rules are enforced through branch protection in your code host, so Quorum could not skip them if it tried. There is no auto-merge setting to turn on.

Quorum merge rules: required approvals per fix type, auto-merge always off

What platform teams say after the first month

“We had 212 open findings and a board nobody opened. Quorum opened 19 pull requests in the first week and we merged 17 of them.”

Rachel Ortega

Staff platform engineer, Tallis Health, Nashville

17 of 19 merged in week one

“We had 212 open findings and a board nobody opened. Quorum opened 19 pull requests in the first week and we merged 17 of them.”

Rachel Ortega

Staff platform engineer, Tallis Health, Nashville

17 of 19 merged in week one

“The two-approval rule is why security signed off. Nothing lands in our Terraform unless two of us have read it.”

Dev Okafor

Engineering manager, Pellwood, Denver

Critical fixes merged in 22 minutes, median

“Our auditor asked for evidence of vulnerability management. I exported a date range and that was the whole conversation.”

Hana Lindqvist

Head of security, Brightwork Freight, Chicago

One export, no follow-up requests

Priced per developer, starting free

Only developers who commit to a connected repo in a month count. Bots, viewers and quiet contractors are free.

Yearly billing gives you two months free.
Free

For a side project or a first look at what you expose.

$0
for two repos, with no time limit
  • Two repos and one cloud account
  • A daily scan
  • Fix pull requests for leaked secrets and public storage
  • Email support
Team

For product teams of 5 to 150 developers who want every exposure fixed, not filed.

Most teams pick this
$24
per developer a month, billed yearly
  • Unlimited repos and three cloud accounts
  • A scan every hour
  • Fix pull requests for all six exposure types
  • Merge rules: pick your quorum per fix type
  • Slack threads for every fix
  • 13 months of scan history
Run a free scanEvery plan starts with a free scan of one repo.
Business

Over 150 developers, or an auditor who asks for everything.

SSO and SCIM · A scanner that runs in your cloud · Audit exports · 99.9% uptime SLA

Before you connect a repo

Straight answers to what security teams ask us first.

Only to open pull requests. The GitHub app asks for read access to code and metadata plus pull request write. It cannot push to your default branch, change branch protection or merge anything. Cloud accounts connect through a read-only role.

Quorum opens a pull request only when it can show how the exposure is reached: a public log, an open port, a function that takes user input. Everything else waits in the findings list. Teams in their first month merge a median of 83 percent of the pull requests Quorum opens.

The fix runs through your own CI like any other branch. If a check fails, Quorum marks the pull request as blocked, posts the failing output in the thread and does not ask anyone for review until it passes.

Per developer who commits to a connected repo in a month, billed yearly or monthly. Bots, read-only viewers and contractors with no commits that month are free. The Free plan covers two repos with no time limit.

Scans run in a runner inside your own cloud account or in our US region, your choice. Source code is never stored after a scan finishes. Findings metadata is kept for 13 months and can be deleted from Settings.

Yes. GitLab (cloud, or self-managed 16.0 and later) and Bitbucket Cloud get merge requests the same way. In a monorepo Quorum opens one pull request per owning team, read from your CODEOWNERS file.

Run a free scan on one repo

Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.