How Cal.com Rebuilt AppSec After Going Closed Source
How Cal.com consolidated noisy security tooling into one continuous, context-aware pull request security program with Gecko.
Gecko Security

You’ve probably run Semgrep or Snyk and felt pretty good about the results. But here’s the problem: they can’t tell you if your authorization logic is broken. There’s no signature for a missing permission check, no taint flow for an IDOR vulnerability hiding in your service mesh. AI vulnerability scanning that actually reasons about code semantics is what catches these. We ranked every tool by whether it can find what pattern matching fundamentally can’t.
TLDR:
Traditional security scanners work by matching patterns. They look for known signatures, track data flows through taint analysis, and flag code that resembles something dangerous. For injection attacks, that approach works. For business logic vulnerabilities, it falls apart completely.
AI-powered application security testing takes a different approach. Instead of matching patterns, it builds semantic understanding of how an application actually works, then reasons about where that behavior diverges from what was intended. It traces data across service boundaries, infers authorization policies from context, and identifies attack chains that span multiple components.
Why does this matter? According to OWASP’s 2025 Top 10, broken access control affects 100% of tested applications across a sample of nearly 500,000. Every single one. That stat should make you stop and think about what your current tooling is actually catching.
Pattern matchers can’t detect missing authorization checks because there’s no pattern to match. There’s no malicious payload, no dangerous function call. There’s just logic that doesn’t do what it should. Detecting that requires understanding what the code is supposed to do, and that requires reasoning, not rules.
That’s the core of what AI-powered appsec delivers: semantic code analysis that understands intent, beyond syntax.
Not all “AI security testing” tools are the same. Some bolt an LLM onto existing taint analysis. Others use AI to summarize findings from the same pattern-matching engine they’ve always had. The label doesn’t tell you much.
To cut through the noise, we ranked tools across six criteria:
That last point matters more than it used to. As of March 2026, at least 35 CVEs traced back to AI-generated code were disclosed in a single month. Vibe coding ships logic fast, but the logic is often wrong in ways that only semantic analysis catches.
Tools that score well here go beyond syntax. They reason about intent.
Gecko Security is an AI-native security testing tool built by former British Intelligence and Austrian Military cyber researchers. Where other tools layer AI onto existing pattern matchers, Gecko builds a semantic model of your application from the ground up using a Code Property Graph and compiler-accurate indexing instead of AST parsing.
That distinction is what lets it catch what others miss.
Gecko traces call chains across microservices by parsing API contracts, protobuf schemas, OpenAPI specs, and AsyncAPI definitions. It maps authentication and authorization mechanisms across the entire graph, then uses LLMs to reason about whether the security intent is actually enforced.
When it finds something, it generates a working proof-of-concept exploit to confirm it’s real. That’s how it achieves 50% fewer false positives.
In eight months of research scanning, Gecko found 30+ CVEs across major open source projects including Cal.com, Ollama, and N8N. The Cal.com findings included a three-bug account takeover chain that had slipped past existing tooling and manual penetration testing.
No build is required, and it works across polyglot architectures. Developer-ready fixes come alongside every finding.
Snyk is a well-regarded tool for software composition analysis. If your priority is supply chain security and knowing which open source dependencies carry known CVEs, it does that job well.
Here is what Snyk covers:
Good for teams that need fast visibility into third-party package risk. Less useful for anything happening inside your own code.
Snyk has no semantic understanding of how your application behaves. It cannot detect a missing authorization check, an IDOR vulnerability, or a privilege escalation bug buried in your service-to-service logic. Those gaps are simply outside what Snyk was built to do. Think of it as complementary, not a full appsec solution.
Semgrep is an open source SAST tool built on pattern matching. It parses Abstract Syntax Trees within individual files and flags code that matches known vulnerability signatures.
Solid choice for catching syntactic vulnerabilities like SQL injection and XSS in contained codebases, but it misses authorization bypasses by design.
The limitation is structural. Pattern matching cannot determine whether your authorization logic is correct. Semgrep operates at the file level, so it cannot trace a vulnerability that starts at an API gateway and surfaces in a downstream data service. Broken access control, IDOR, privilege escalation: all invisible to it by design.
Injection attacks now rank 5th on OWASP. Semgrep is well-suited for that problem. Other tools target the one sitting at number 1.
DryRun Security offers AI-powered pull request review agents that provide contextual security feedback on code changes as they happen.
Good for teams wanting to catch simple mistakes before they ship.
The scope is the constraint. PR review agents only see the diff. They miss vulnerabilities that span services, live in existing production code, or require whole-system reasoning to surface. Broken access control across a microservice architecture won’t show up in a changed file.
DryRun prevents new issues going forward. It won’t find what’s already threatening your production environment.
Nullify.ai is an AI-enhanced security testing tool that pulls organizational context from a vault of documentation, policies, and bug bounty reports to inform how it reasons about vulnerabilities.
Here’s where the approach has real value, and where it runs into trouble.
This works well for organizations with mature documentation practices where policies and threat models are actively maintained.
The constraint is the docs themselves. Code changes constantly. Documentation rarely keeps pace, missing vulnerabilities like arbitrary file writes. When the two diverge, Nullify’s reasoning operates on outdated context. There’s no compiler-accurate semantic indexing, and no ability to trace authorization logic across microservices through code-level analysis.
Documentation-based reasoning assumes your docs are accurate. That’s a big assumption in any codebase moving fast.
Corgea is a remediation-first tool. It integrates with existing SAST and SCA scanners to auto-generate fixes for vulnerabilities those upstream tools already flagged.
Here is what that looks like in practice:
The core limitation is dependency. Corgea fixes what upstream scanners find. If your SAST misses broken access control or IDOR (and pattern-based tools do, systematically), Corgea never sees them. Issues like missing signature verification slip through entirely. No proprietary detection engine means no ability to surface business logic flaws independently.
Corgea fixes what you already know about.
MindFort runs a fleet of autonomous AI agents that continuously probe your external attack surface with attacker-style reasoning. Where static analysis tools inspect code, MindFort operates against live environments, testing apps, APIs, and infrastructure around the clock without stopping at the first finding.
Here is what MindFort covers:
Strong fit for teams that want a continuous offensive testing layer against their live environment, the closest thing to having an always-on red team.
The table below maps each tool against the capabilities that matter most for catching business logic vulnerabilities.
| Capability | Gecko Security | Snyk | Semgrep | DryRun Security | Nullify.ai | Corgea | MindFort |
|---|---|---|---|---|---|---|---|
| Business Logic Detection | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Broken Access Control Detection | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Cross-Service Analysis | Yes | Yes | No | No | No | No | Yes |
| Semantic Code Understanding | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Infrastructure Context Integration | Yes | No | No | No | Yes | No | Yes |
| Proof-of-Concept Generation | Yes | No | No | No | No | No | Yes |
| Proprietary Detection Engine | Yes | Yes | Yes | Yes | No | Yes | Yes |
| Whole-Codebase Threat Modeling | Yes | No | No | Yes | No | No | No |
| Multi-Step Vulnerability Chaining | Yes | No | No | No | No | No | Yes |
The pattern is hard to ignore. Every tool in this list solves a real problem. The gap is that none of them were built to reason about whether your authorization logic is actually correct.
Gecko was built to find the vulnerabilities that every other tool in this list misses. Dependency scanning, PR review, and remediation workflows are real problems worth solving, but none of them answer the question that matters most: is your authorization logic actually correct?
Semantic indexing, compiler-accurate code analysis, and LLM reasoning over full call chains across every service boundary is how Gecko finds the account takeovers and privilege escalations that slip past everything else.
30+ CVEs in eight months. 50% fewer false positives. Findings that previously only surfaced in manual penetration testing, including attack vectors skill scanners miss.
You can try Gecko free at app.gecko.security.
The difference between AI vulnerability scanning and traditional SAST comes down to one question: does the tool understand what your code is supposed to do, or just what it looks like? Business logic flaws, broken access control, and cross-service authorization bugs require reasoning about intent, not matching patterns. Most teams hit these gaps in production or during penetration testing, long after the code shipped. If you’re ready to see what semantic analysis finds in your codebase, schedule 30 minutes with us.

Artemiy Malyshau
Co-founder & CTO
Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.
The latest news, technologies, and resources from our team.
How Cal.com consolidated noisy security tooling into one continuous, context-aware pull request security program with Gecko.
Gecko Security
Authorization bypass in n8n’s dynamic-credentials OAuth endpoints allows any authenticated user to operate on another user’s OAuth credential by supplying its ID, enabling unauthorized OAuth rebinding and revocation.
Artemiy Malyshau
An IDOR vulnerability in n8n’s public variables API allows authenticated users to read project variables outside their authorized scope, exposing secrets across project boundaries.
Artemiy Malyshau
Learn API scanning for automated security testing. Find vulnerabilities from broken authentication to business logic flaws in your endpoints.
Artemiy Malyshau
A complete guide to automated pentest tools and best practices. Learn what works, what doesn’t, and how to implement continuous security testing.
Artemiy Malyshau
Compare the 14 best AI security tools. Features, pricing, and detailed comparisons to find vulnerabilities in code and secure AI systems.
Artemiy Malyshau
Occasional updates, new content, and insights. No spam; unsubscribe anytime.