Engineering control tower
See every repo.
Fix what matters first.
Northgate watches the code your teams ship, scans each push for real vulnerabilities, and ranks every finding by security, reliability, cost and ownership. One queue tells you what to fix today. The agent add-on can open the fix as a pull request for a human to merge.
See it run
The same tower, in the browser or the terminal.
Recorded on a sample 131-repository estate. Leads use the dashboard, engineers use the CLI, and both read from the same API.
northgate loginnorthgate overviewnorthgate securitynorthgate prioritize--json
The fix-first queue
Four scanners give you four lists. Northgate gives you one.
Security tools rank by severity. Cost tools rank by spend. Nobody tells you which single change clears the most risk for the least effort. Northgate fuses every engine into one score per finding, so the top of the queue is the work that moves the most.
Findings come from semantic static analysis, dependency CVEs from the OSV database, license checks, CI/CD run data and cloud spend. Each one lands in the same ranked list.
| # | Finding | Severity | Repos | Score |
|---|---|---|---|---|
| 1 | Middleware authorization bypass in web framework one version bump · clears 3 criticals |
Critical | 3 | 0.91 |
| 2 | Shell injection in CI workflow input .github/workflows/release.yml |
Critical | 1 | 0.84 |
| 3 | Remote code execution in test runner dependency devDependency · CI exposed |
High | 2 | 0.72 |
| 4 | Idle build minutes on unowned service $7,625 / mo · no active owner |
Medium | 1 | 0.58 |
Example queue, drawn from a real scan of an eight-repository estate.
The platform
One tower over the whole estate.
Live control tower
Every push, as it happens
Webhooks stream commits, new repositories and merges into one feed, attributed to the person behind them. Each push can trigger a re-scan that shows its security effect on the spot.
Security posture
Real findings with evidence
Semantic static analysis, known CVEs in dependencies, and license compliance, with the offending line pulled from your own source and test code filtered out.
Remediation queue
A single ranked list
Security, reliability, cost and ownership fused into one score. Your leads stop arguing about priorities and start closing the top item.
FinOps
What each repo costs
Pipeline spend from real CI run minutes, duplicate services grouped into clusters, and a reclaim estimate for the waste you can retire.
Migration cockpit
Waves, blockers, progress
Track every repository through migration with a state machine, assign waves, and see exactly what blocks each one from moving.
Trends and drill-in
Posture over time
Scheduled snapshots chart debt and security scores week over week. Open any repository to see its findings, owners, pipelines and history.
Agent add-on · fix by pull request
From finding to fix, with a person holding the merge button.
The agent reads the source, writes the patch, and opens a pull request on a new branch. It never pushes to your default branch and never merges on its own.
Triage
The agent works the top of the queue and spots shared root causes, such as one dependency bump that closes several criticals.
Patch
It fetches the affected files, targets the right manifest even in a monorepo, and prepares the smallest change that resolves the finding.
Open PR
A branch and pull request appear in your repository with the finding, the reasoning and the diff. The action is written to the audit log.
Review and merge
Your engineer reviews it like any other PR. Nothing reaches production until they approve it.
Built for the security review
Your code stays yours.
Northgate is designed to pass a CISO's questions before the first demo. It deploys as one container inside your environment and refuses to start in production with unsafe settings.
-
Private repositories onlyIngestion requires an authenticated token and reads private repos exclusively. There is no public fallback.
-
Deploys in your environmentOne container serves the app and API. You own the host, the network and the data.
-
Tamper-evident audit trailEvery action is written to a SHA-256 hash chain. Change one entry and every entry after it stops verifying.
-
Bring your own AI keyAgent runs use your own Anthropic key, encrypted at rest. We never see or bill those tokens.
-
Role-based access and tenant isolationViewer, lead and admin roles, account lockout, revocable sessions and per-tenant data separation.
Plans
Licensed monthly. Start with visibility, add the agent when you're ready.
Base
Control Tower
Full visibility and a ranked plan of action for your whole estate.
- Live activity feed across every connected source
- Security posture: static analysis, CVEs, licenses
- Fix-first remediation queue
- FinOps, migration cockpit and trend reporting
- Audit log export and role-based access
Monthly license, sized to your repository count.
Base + Agent
Control Tower with Agent
Everything in Base, plus an agent that turns findings into reviewed pull requests.
- Agent triage across the full queue
- Fix-by-PR on new branches, human-merged
- Auto re-scan on every push
- Background job queue with retries
- Runs on your own AI key
Monthly license. AI usage is billed to your own key, typically cents per run.
Put your estate
under one tower.
We'll connect Northgate to a sample of your private repositories and walk your security and platform leads through the live queue in 45 minutes.