How Thatch Stays at Zero Critical Vulnerabilities While AI Accelerates Software Development

Zero critical vulnerabilities

Prevented introduction of critical vulnerabilities while code velocity doubled.

Doubled security coverage

Doubled the security team’s efficiency, with continuous security coverage across the codebase and every pull request.

Developers own remediation

Most findings resolved directly by developers, giving security more time for prevention and platform improvements.


depthfirst helps us make sure that the quality bar stays high, and that our developers do not introduce new high and critical vulnerabilities.

Bart de Water Software Engineer, Infrastructure & Security at Thatch

A Flexible Health Budget for Every Employee

Thatch replaces one-size-fits-all group health plans with a flexible health budget for every employee. Its platform handles payroll information, health-plan selections, and other sensitive data at the intersection of healthcare and financial services. Security is built into how the company ships software, including a production-readiness process that new services must complete before going live.

As Thatch grew, its security team had more code to oversee. They could not sustainably review every change by hand, and adding AppSec headcount at the same rate was not a practical answer.

Before depthfirst, Thatch had static analysis, but identifying potential issues was only part of the problem. As code volume grew, the security team still had to spend significant time validating findings and deciding what actually required attention.

Is this actually exploitable? Are there actual risks from this code? That’s the expensive piece, and depthfirst is excellent at answering that.

Allan Reyes Software Engineer, Infrastructure & Security at Thatch

Continuous Coverage That Improves Over Time

Thatch uses depthfirst for recurring code scans and pull request review, giving the security team coverage across existing code while catching new vulnerabilities before they reach production. Thatch estimates that they would have had to double the size of the team to achieve the same coverage without depthfirst.

depthfirst helps Thatch focus on real vulnerabilities by providing proof of the exploitability conditions of its findings. Over time, feedback from developers and additional context from the security team help refine depthfirst’s knowledge, allowing it to better account for Thatch-specific architecture, business logic, and accepted patterns.

For example, it can identify when new functionality is missing an authorization check that Thatch consistently applies elsewhere, or flag a logic error when the implementation does not match the behavior described in the pull request.

Developers Resolve Most Findings in the Pull Request

depthfirst scans every pull request and comments when it finds an issue, putting security feedback directly in the workflow where developers already review and change code. When it flags an issue, the developer who owns the change usually investigates and fixes it directly. The security team gets involved primarily for high-severity findings or when a developer asks for help.

depthfirst helps developers securely write and review each others’ code and helps the security team focus on the most important issues.

Allan Reyes Software Engineer, Infrastructure & Security at Thatch

That keeps routine remediation with the engineer who has the most context on the change, while preserving security-team attention for issues that require deeper investigation or business-risk judgment. Over time, developers have built trust in depthfirst’s findings, and reviewers encourage PR authors to address them.

Security Spends More Time Preventing Vulnerabilities Instead of Remediating Them

Continuous scanning and developer-owned remediation have changed where Thatch’s security team spends its time. Instead of spending as much time finding, validating, and responding to individual vulnerabilities, the team can invest more in preventive controls and platform improvements that reduce risk before issues reach production.

Some of those controls are implemented directly in depthfirst. Thatch uses deterministic rules for requirements that need to be enforced consistently and natural-language rules for broader security guidance, allowing the security team to apply what it learns consistently across code scans and pull requests.

We extended our AppSec program with depthfirst. Now we have an AppSec agent that covers our codebase and PRs day and night, which freed us up to work on higher leverage security initiatives.

Allan Reyes Software Engineer, Infrastructure & Security at Thatch

Zero Open Critical Vulnerabilities as the Codebase Grows

Thatch has reduced its open critical vulnerability count to zero with depthfirst. They continue to use human penetration testing as part of its security and compliance program, and its most recent test returned only five low or medium findings.

depthfirst’s coverage was tested when Thatch brought on another customer base and code volume spiked over several days.

Having depthfirst in place and operational during this high-intensity time proved to be a great decision. It allowed us to scale our team and ensure that the code quality, safety, and velocity were kept high.

Allan Reyes Software Engineer, Infrastructure & Security at Thatch

With depthfirst, Thatch now maintains security coverage as engineering output grows without requiring its security team to manually review every change. Critical vulnerabilities are at zero, developers resolve most findings where they already work, and security engineers can spend more of their time building the controls that keep new vulnerabilities from reaching production.