
Stronger security posture
Security developers remediated 130+ complex vulnerabilities surfaced by depthfirst’s General Security Intelligence in a few weeks.
Lower load for security
Security developers acted on 76% of General Security Intelligence’s recommendations, reflecting high signal quality.
Faster remediation
Moveworks ships code faster with one-click fixes for existing vulnerabilities and with an AI security engineer’s code suggestions on every pull request
Depthfirst has fundamentally changed how we think about code security and quality at Moveworks. They not only find code defects and complex threats; their PR reviewer proposes concrete code changes developers can apply directly in the pull request, making remediation fast and frictionless.
Company Name
Moveworks
Industry
Employees

Stay up to date on depthfirst.
Moveworks is an AI Assistant platform used by employees at hundreds of enterprises. They work with 10% of the Fortune 50 and 10% of the Fortune 500 companies, as well as tech leaders like GitHub, Snowflake, and Databricks. This means their security and engineering teams face stringent requirements from some of the world’s most demanding customers.
Like many software companies that ship code quickly, Moveworks used a code scanner to help secure their code without compromising on velocity. At least, that’s what it was supposed to do.
In reality, it did neither. It buried developers and security engineers in false positives and gave developers nonactionable remediation advice. Security was spending too much time triaging alerts that didn’t matter, and developers were losing hours going back and forth on vague findings instead of shipping product. Security needed to focus on real vulnerabilities, and developers needed something that would tell them how to remediate problems, instead of forcing them to figure it out from scratch.
Over time, that friction added up and Moveworks decided to take action. Security struggled to trust the scanner’s output because of the constant noise, and developers began to see security reviews as a tax on their productivity rather than a partner in shipping safer code, making it clear they needed a different approach to code security.
That’s when Hassan Ali, Head of Application Security at Moveworks, started looking for a new solution. As a security expert, he knew the ultimate goal of any security program is to find and remediate as many true vulnerabilities as possible, and that a code scanner alone would inevitably miss important ones. So instead of only considering scanners, he expanded the search to a full security platform.
That’s when Hassan came across depthfirst and decided to put it through a Proof of Concept: a two-week sprint where depthfirst ran on Moveworks’ main repo. Hassan evaluated depthfirst on:
On coverage, depthfirst excelled by analyzing Moveworks’ applications, dependencies, containers, and infrastructure. However, where it really stood out was in the balance between vulnerabilities found and false positives flagged. This tradeoff is one that security leaders have largely had to accept until now.
Tight detection criteria can reduce false positives, but they also cause tools to miss real vulnerabilities. Looser, more sensitive criteria might find more issues, but usually create an unmanageable number of false positives that all look like critical vulnerabilities.
depthfirst delivered in the POC because it performed exceptionally well on both sides of the tradeoff. It identified complex vulnerabilities that had gone undetected while raising an order of magnitude fewer findings than the team was used to seeing. depthfirst also provided a report of potential alerts it marked as false positives, with explanations for each decision, giving the security team confidence that coverage was thorough even when alerts were suppressed.
This outstanding signal-to-noise ratio, combined with broad coverage, convinced Hassan that depthfirst was the right partner to help secure Moveworks.
depthfirst’s General Security Intelligence is an AI security platform that analyzes a company’s entire codebase, infrastructure, and business logic to understand how it is supposed to operate. This deep context allows it to detect complex vulnerabilities that point solutions and rule-based scanners typically miss and recommend fixes that actually work.
Fast implementation
Implementing General Security Intelligence at Moveworks was lightweight. The team onboarded in about ten minutes by granting permissions to depthfirst’s GitHub app and connecting their artifact repository. No long rollout projects or complex rule tuning required meant that Hassan’s team could start realizing value almost instantly.
How Moveworks uses depthfirst’s General Security Intelligence
Today, General Security Intelligence has become an integral part of Moveworks’ security program and developer workflows:
“depthfirst catches business logic issues because it uses LLM-based detection. For example, it can detect missing authorization or validation checks that rule-based SAST engines or other code detection engines just won’t pick up.” - Hassan Ali, Head of Application Security, Moveworks
By moving to General Security Intelligence, Moveworks strengthened its security posture without slowing down engineering.
“This is really cool, it is detecting not just security issues, but code quality issues too. It is making me write better code.”- Moveworks developer
“I cannot believe it is actually picking up the PR description, correlating that with the code I changed, and putting two and two together to flag issues.” - Moveworks developer
A recent example of General Security Intelligence’s impact came when the Shai-Hulud 2.0 npm supply chain attack was disclosed (November 2025), a self-propagating campaign that compromised hundreds of npm packages and tens of thousands of GitHub repositories in order to steal developer credentials and other secrets. Because General Security Intelligence had visibility into Moveworks’ codebase and dependencies, it helped the team quickly verify that they were not affected, without a time-consuming manual audit across services and pipelines.

Start finding critical vulnerabilities in minutes
Link your Github repository with three clicks.