Why Quorum opened this
A live Stripe secret was committed in a41c9e2 on Sep 12 and is readable in the public build log for run 3318.
Reviewers
Quorum scans your repos and cloud accounts every hour, writes the fix for each exposure it can reach, and waits for two of your reviewers.
Free for two repos. No card.








A findings list your team can actually finish
Quorum ranks what an attacker can reach, writes the change, and keeps a record of every scan.
Findings ranked by what can be reached
Every finding shows how it is reached: a public build log, an open port, a route that takes user input. The ones with a path come first, and each has its fix pull request beside it.

The fix arrives as a diff you already know how to review
Quorum changes the fewest lines it can, in the style your code already uses, and runs your own CI before it asks anyone to look. A lodash bump is two lines. A leaked key is one.

A scan every hour, and a record of each one
Hourly scans finish in about four minutes for a typical account. Every run, finding, approval and merge is kept for 13 months, ready for the auditor who asks.

Six exposures Quorum fixes with a pull request
Everything else waits in the findings list with its evidence, until you decide.
Exposure and what the pull request changes
Median time to merge
Leaked secrets
Moves the value into your secrets manager, replaces the line with a reference and adds a CI check for live key patterns.
22 min
Public storage
Removes the public statement and turns on the public access block, in the Terraform that owns the bucket.
31 min
Open ports
Narrows the security group rule to your office and VPN ranges, with the old rule kept in the description.
44 min
Reachable vulnerable packages
Bumps to the nearest fixed version, only when your code calls the vulnerable function.
1 h 12 min
Over-broad IAM
Replaces wildcards with the actions the role actually used in the last 90 days.
2 h 05 min
Expiring certificates
Renews or rotates the certificate 14 days before it expires.
17 min
Medians across 312 teams, June to August 2026. Demo figures.
From read-only access to a merged fix in three steps
Setup takes about ten minutes. After that the only thing Quorum asks of your team is a review.
Connect with read-only access
Install the GitHub, GitLab or Bitbucket app and add a read-only role for each cloud account. Quorum cannot push to your default branch or change anything in your cloud.
About 10 minutes
Quorum scans every hour
It reads what changed since the last run, traces how each exposure is reached and writes the smallest fix it can.
4 minutes a scan
Your reviewers decide
The fix arrives as a pull request with your checks already run. It merges when your quorum approves, and not before.
22 minutes to merge, median
Quorum never merges on its own
You set the quorum per fix type: how many approvals, and from which team. Rules are enforced through branch protection in your code host, so Quorum could not skip them if it tried. There is no auto-merge setting to turn on.

Reads the tools you already run
Twelve integrations. Every one is read-only, apart from the pull requests themselves.

GitHub
Opens fix pull requests on github.com and GitHub Enterprise Server 3.12 and later.

GitLab
Opens merge requests on GitLab.com and self-managed GitLab 16.0 and later.

Bitbucket
Opens pull requests on Bitbucket Cloud workspaces, with Pipelines checks.

AWS
Reads S3, IAM, EC2 security groups, Lambda and CloudTrail across every region.

Google Cloud
Reads Cloud Storage, IAM, firewall rules and Cloud Run services per project.

Microsoft Azure
Reads storage accounts, network security groups and role assignments per subscription.
What platform teams say after the first month
“The two-approval rule is why security signed off. Nothing lands in our Terraform unless two of us have read it.”
Dev Okafor
Engineering manager, Pellwood, Denver
Critical fixes merged in 22 minutes, median
“Our auditor asked for evidence of vulnerability management. I exported a date range and that was the whole conversation.”
Hana Lindqvist
Head of security, Brightwork Freight, Chicago
One export, no follow-up requests
Priced per developer, starting free
Only developers who commit to a connected repo in a month count. Bots, viewers and quiet contractors are free.
For a side project or a first look at what you expose.
- Two repos and one cloud account
- A daily scan
- Fix pull requests for leaked secrets and public storage
- Email support
For product teams of 5 to 150 developers who want every exposure fixed, not filed.
- Unlimited repos and three cloud accounts
- A scan every hour
- Fix pull requests for all six exposure types
- Merge rules: pick your quorum per fix type
- Slack threads for every fix
- 13 months of scan history
Over 150 developers, or an auditor who asks for everything.
Shipped in the last month
A release every two weeks, written up in plain words.
Version 2.14
Merge rules per fix type
Pick how many approvals each kind of fix needs, and from which team.
Version 2.13
Reachability for Python services
Quorum now traces calls from Flask, Django and FastAPI routes to vulnerable packages.
Version 2.12
Quiet hours
Fixes found overnight open as drafts and post one summary in the morning.
Before you connect a repo
Straight answers to what security teams ask us first.
Run a free scan on one repo
Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.