Every integration is read-only, apart from the pull requests Quorum opens in your code host.

GitHub
Opens fix pull requests on github.com and GitHub Enterprise Server 3.12 and later.
4 minutes

GitLab
Opens merge requests on GitLab.com and self-managed GitLab 16.0 and later.
6 minutes

Bitbucket
Opens pull requests on Bitbucket Cloud workspaces, with Pipelines checks.
5 minutes

AWS
Reads S3, IAM, EC2 security groups, Lambda and CloudTrail across every region.
8 minutes

Google Cloud
Reads Cloud Storage, IAM, firewall rules and Cloud Run services per project.
7 minutes

Microsoft Azure
Reads storage accounts, network security groups and role assignments per subscription.
9 minutes

Cloudflare
Checks DNS records, TLS certificates and Access policies on every zone.
3 minutes

Terraform
Writes the fix in your Terraform, so the change lands in code as well as in the cloud.
2 minutes

Kubernetes
Finds privileged pods, public services and plaintext secrets in manifests and Helm charts.
5 minutes

npm
Checks every package-lock.json and pnpm-lock.yaml for vulnerable packages your code actually calls.
No setup

Slack
Posts one thread per fix and closes it when the pull request merges.
2 minutes

Linear
Links each fix pull request to an issue for teams that plan security work in Linear.
3 minutes
Missing a tool you use?
We add one integration a month, in the order customers ask for them. Tell us what you run.
Run a free scan on one repo
Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.