A scanner can identify a pattern without understanding whether the code path is reachable or protected elsewhere. SourceScan combines expert-directed command-line analysis with a web dashboard for findings, ownership, decisions, remediation, and dated retest records.
Assistance without surrendering judgment
Supported models can organize code context and surface candidate weaknesses. Reviewers trace the affected path, examine trust boundaries and compensating controls, and decide whether the result should be accepted. Source handling and model boundaries are agreed before analysis begins.
- Expert-directed analysis near the repository workflow
- AI-assisted organization of code context and candidates
- Human validation of reachability and consequence
- Finding assignment, developer response, exception, and retest tracking
One record from candidate to retest
The dashboard retains affected components, evidence, priority, ownership, remediation notes, risk decisions, and validation status. Leaders can see open material findings without treating unreviewed scanner volume as confirmed exposure.
Release-specific support
Languages, repository connections, deployment options, and model support vary by release. GDF confirms current availability and data-handling requirements before a codebase is connected.