Quorum reads your code hosts and clouds every hour, traces how each exposure is reached and opens the smallest change that closes it. Your reviewers decide what merges.
Every fix is a pull request you can read in a minute
Here is an over-broad IAM role narrowed to the actions it used in the last 90 days, written in the Terraform that already owns it.
Why Quorum opened this
Role ci-deploy has s3:* on every bucket but used four actions in the last 90 days, all on pellwood-builds.
Reviewers
Findings, ranked by reachability
Each finding carries the path that makes it dangerous: the public log, the open port, the route that takes user input. Reachable findings come first, and a finding with no path never becomes a pull request on its own.
Sources
12 integrations
Ranking
Reachability, then severity
Default view
Open and reachable

Fix pull requests in your code style
Quorum changes the fewest lines it can, follows the naming and formatting already in the file, and runs your own CI before anyone is asked to review.
Median diff
6 lines
Checks
Your CI, before review
Branch
quorum/ prefix

Merge rules you set per fix type
Pick how many approvals each kind of fix needs and from which team. Rules are enforced by branch protection in your code host, so they hold even if Quorum makes a mistake.
Approvals
1 to 5 per rule
Enforced by
Branch protection
Auto-merge
Not available

An hourly scan with a full record
Scans read only what changed since the last run, so an hourly scan takes about four minutes. Every scan, finding, approval and merge is kept and exportable for your auditor.
Frequency
Hourly on Team
Typical run
4 minutes
History
13 months

Where each fix lands
Quorum writes the change where your team would: in the file or module that owns the resource.
The limits we built in on purpose
A tool with access to your repos and clouds should be boring about what it does with it.
It waits for your quorum
A fix merges when the approvals your merge rules ask for are in. There is no auto-merge setting to switch on.
It changes code, not consoles
Cloud fixes land in Terraform or your other infrastructure code, so every change has a diff and a reviewer.
It keeps findings, not source
Code is read at scan time and dropped when the scan ends. Findings metadata is kept for 13 months, and you can delete it.
Run a free scan on one repo
Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.