AI Code Security Guardian Demo

A product that connects the whole process in one workflow: finding security issues in code, reviewing them with AI and people together, deciding according to your organization's policy, and verifying again after the fix.

In development Result screens built with sample data. No real customer data is shown, and the released product may look different.

  1. Dashboard
  2. Project results
  3. Finding detail
  4. AI review

Security findings by project

Based on the last completed scan. The same issue is counted once.

ProjectSecretsSecure codingOpen source vulnsLicensesTotalLast scanAI false positives
payment-api1741132026-10-10 09:052
partner-portal052072026-10-09 18:421
batch-settlement2361122026-10-08 11:200

In this demo, you can open the results of the payment-api project.

Dashboard / payment-api

payment-api

13 open findings · Findings from the same rule are grouped together.

SQL query built by string concatenationCWE-89HIGH2
Sensitive data written to logsCWE-532MEDIUM3
  • src/main/java/com/sample/payment/PaymentService.java:112
  • src/main/java/com/sample/payment/log/LogMasking.java:21 AI: likely false positive
  • src/main/java/com/sample/payment/card/CardController.java:88
Path traversalCWE-22HIGH1
  • src/main/java/com/sample/payment/file/FileController.java:57 AI: likely false positive
Predictable random valuesCWE-330MEDIUM1
  • src/main/java/com/sample/payment/auth/TokenGenerator.java:19
log4j-core remote code executionCVE-2021-44228CRITICAL1
  • org.apache.logging.log4j:log4j-core 2.14.1 · Upgrade to 2.17.1 or later
spring-beans remote code executionCVE-2022-22965CRITICAL1
  • org.springframework:spring-beans 5.3.17 · Upgrade to 5.3.18 or later
commons-text string interpolation remote code executionCVE-2022-42889CRITICAL1
  • org.apache.commons:commons-text 1.9 · Upgrade to 1.10.0 or later
jackson-databind denial of service via deep nestingCVE-2020-36518HIGH1
  • com.fasterxml.jackson.core:jackson-databind 2.13.1 · Upgrade to 2.13.2.1 or later
Exposed cloud access keyCRITICAL1
  • src/main/resources/application-prod.yml:12 · Shown masked AKIA••••••••
Strong copyleft componentAGPL-3.0HIGH1
  • com.itextpdf:kernel 7.2.5 · Depending on how the service is offered, source disclosure may be required. Legal review is recommended.

In this demo, you can open the detail of OrderRepository.java:48.

Dashboard / payment-api / Finding

SQL query built by string concatenation

src/main/java/com/sample/payment/order/OrderRepository.java:48

Location

46public List<Order> findByCustomer(String customerId) {
47    // Orders by customer
48    String sql = "SELECT * FROM orders WHERE customer_id = '" + customerId + "'";49    return jdbcTemplate.query(sql, orderMapper);
50}

Why it matters

When external input is concatenated into a SQL statement, an attacker can inject SQL into that input to read other customers' orders or change data.

How to fix it

Pass values as bind parameters (?) instead of concatenating strings. The statement and the values stay separate, so input is never interpreted as SQL.

Summary

Severity
HIGH
Category
Secure coding
Type
CWE-89 SQL injection
Status
New
First seen
2026-10-10
AI reviewTrue positive

customerId flows from the request into the SQL statement without validation. This location can be exploited.

Suggested fix

- String sql = "SELECT * FROM orders WHERE customer_id = '" + customerId + "'";
- return jdbcTemplate.query(sql, orderMapper);
+ String sql = "SELECT * FROM orders WHERE customer_id = ?";
+ return jdbcTemplate.query(sql, orderMapper, customerId);

AI judgments are suggestions. A reviewer makes the final call.

AI false positives

Findings that AI judged likely to be false positives. Once a reviewer confirms them against the evidence, they are removed from the counts.

SelectProjectFindingAI evidence
payment-apiSensitive data written to logs
LogMasking.java:21
The card number is masked to the first 6 and last 4 digits before logging.
payment-apiPath traversal
FileController.java:57
The file name is checked against an allowlist before it is used in a path.
partner-portalUnsanitized HTML insertion
NoticeView.tsx:34
The HTML is sanitized to allowed tags before insertion.