AppSecNews
ASPM Commercial Growing

Jit

by Jit

An orchestration layer that runs a curated set of open source security scanners in CI, delivers results in pull requests, and manages the plans as code.

Visit jit.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Jit in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current set of orchestrated open source scanners: verify against vendor documentation
  • Language coverage follows the underlying scanners, confirm the current list

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Jit does not write its own analysis engines. It orchestrates established open source scanners, tools in the mould of Semgrep, Gitleaks, Trivy, KICS, npm audit and OWASP ZAP, wiring them into your CI so that each pull request is checked by an appropriate subset. The selection and configuration are expressed as a plan stored in a repository, so which controls apply to which code is version-controlled and reviewable rather than clicked into a console.

The product's actual contribution is the layer around those scanners: consistent configuration, deduplicated results, findings delivered as pull request comments scoped to the lines just changed, and a plan model mapping controls to recognizable objectives such as OWASP Top 10 coverage or SOC 2 evidence. Because only changed code is gated by default, teams can adopt it without first clearing a historical backlog, which is the usual reason scanning rollouts stall.

Where it fits

This lives entirely on the pull request and in CI, and it is aimed at engineering teams without a dedicated security function, or at a small security team trying to get consistent coverage across many repositories without configuring each one. Onboarding is a source control app installation plus plan selection. You need a CI setup it supports and a team willing to treat PR comments as blocking, otherwise findings accumulate unread like any other channel.

Strengths

  • Delegating detection to well-known open source engines means the underlying analysis is inspectable and the results are not a black box.
  • Plans as code make security control coverage a reviewable artifact rather than tribal knowledge in a console.
  • Gating on changed code rather than the whole repository makes adoption practical in codebases with existing debt.
  • Framework-oriented plans give a defensible answer to auditors about which controls run where.

Limitations

  • You inherit the strengths and weaknesses of the underlying open source tools, including their false positive characteristics, and the wrapper cannot fix a weak detection engine.
  • Since the scanners themselves are free, the value on offer is orchestration and workflow, which a team with platform engineering capacity can approximate with their own CI templates.
  • Coverage is oriented to the pull request, so it is not a good fit for portfolio-wide posture questions, runtime context or aggregating findings from commercial scanners you already own.

Who it suits

Good for fast-moving product engineering organizations that want consistent security coverage in CI without hiring for it or maintaining scanner configuration themselves. It is a weak fit for enterprises with an existing commercial scanner estate and a mandate to correlate across it, and for teams whose platform group would rather own the CI configuration directly.

Used Jit? Recommend it under your own name and title.

Recommend this tool