Stronger security posture
depthfirst’s General Security Intelligence surfaced and helped Persona remediate hard-to-find vulnerabilities in weeks, directly improving the security of their software.
Lower load for security
With a dramatically better signal-to-noise ratio, Persona acted on more than 70% of recommendations, letting security engineers focus on real risks instead of triaging noise.
2x security coverage while speeding up development
One-click fixes for existing vulnerabilities across code, dependencies and containers 2x’d Persona’s security coverage while increasing development velocity with PR reviews
“Since adopting General Security Intelligence and introducing its context-aware code reviewer into our workflow, we’ve increased our code-security coverage by 2x. Its ability to learn from our patterns, understand application semantics, and continuously refine recommendations has been invaluable. To date, we have addressed more than 70% of agent recommendations which has significantly strengthened our overall security posture”
Company Name
Persona
Industry
Employees

Stay up to date on depthfirst.
Persona is a leader in the identity verification space with a mission to humanize online identity. They help companies like OpenAI, LinkedIn and Rippling verify that their users are who they say they are.
Persona’s engineering team ships fast, and with safety at the core of their mission and product, they wanted to be proactive about securing a rapidly growing codebase. They knew that even the best teams have to face the risk of vulnerable code slipping through as they scale. When that happens, it disrupts the roadmap and slows product momentum because developers have to stop and fix issues in code they shipped weeks earlier.
At the same time, they knew that pull request security reviews can easily kill momentum if they are too heavy-handed. Traditional code scanners are not a great answer either, because they flood teams with false positives and only provide a superficial view of what is really going on in the code.
Persona also understood that this was not a unique problem with their team or stack, but a structural challenge for any organization that ships software quickly. Modern engineering teams are adopting micro-services, pulling in more dependencies and accelerating release cycles, while many traditional security tools were not designed for this pace. Persona needed a security solution that could match this pace and protect their expanding codebase without compromising development speed.
With recent advancements in AI, Persona’s first instinct was to build rather than buy. The team decided to experiment with an in-house pull request security scanner using an LLM, leveraging their own deep understanding of the product and codebase to create a security reviewer tailored to Persona.
Early results were encouraging and confirmed that AI could meaningfully augment their security program. However, turning a promising prototype into a reliable, high-fidelity security solution proved far more complex than expected. Over time, the internal tool struggled with:
As Persona’s product and engineering organization grew, maintaining and evolving the in-house scanner became a significant resource drain. The engineering and security teams needed a comprehensive solution that could deliver the same level of contextual understanding they were aiming for, while balancing trust and shipping velocity without requiring dedicated in-house ownership.
When Persona compared their in-house scanner against depthfirst, the difference was clear. Having built and tested their own AI-powered scanner, the team had a clear view of what a context-aware security reviewer needed to do and where the hard problems were. That experience helped them recognize that depthfirst’s approach with General Security Intelligence could perform very well: an AI-native security platform focused on a deep understanding of a company’s code, business logic and infrastructure.
Trying depthfirst was an easy decision, especially because it was so simple to get started. Persona onboarded in minutes by installing depthfirst’s GitHub App and granting repository permissions across their libraries. With that in place, they could run General Security Intelligence side by side with their internal tool on real pull requests and production code.
In comparison, the Persona team saw:
This combination of broader detection and higher precision convinced Persona’s security leadership that depthfirst was the right partner to support their engineering teams.
Depthfirst’s General Security Intelligence is an AI security platform that analyzes a company’s entire codebase, infrastructure, and business logic to understand how it is supposed to operate. This deep context allows it to detect vulnerabilities across code, dependencies, secrets, and infrastructure that point solutions typically miss and recommend fixes that actually work.
At Persona, that context turns into meaningful, actionable insights embedded directly in existing development workflows. With General Security Intelligence reviewing code in pull requests, every engineer gets an always on, 24/7 security engineer that works with them inside the tools they already use instead of slowing them down from the outside.
Today, depthfirst’s General Security Intelligence is embedded directly into Persona’s development workflow:
By adopting General Security Intelligence, Persona strengthened its security posture without sacrificing the speed or agility of its engineering organization.

Start finding critical vulnerabilities in minutes
Link your Github repository with three clicks.