Engineering control tower

See every repo.
Fix what matters first.

Northgate watches the code your teams ship, scans each push for real vulnerabilities, and ranks every finding by security, reliability, cost and ownership. One queue tells you what to fix today. The agent add-on can open the fix as a pull request for a human to merge.

Private repos only Runs in your cloud Hash-chained audit log
Live Activity · all repositories
    Sample data SSE stream · connected
    Connects to GitHub GitHub Enterprise Server GitLab Bitbucket Azure DevOps

    See it run

    The same tower, in the browser or the terminal.

    Recorded on a sample 131-repository estate. Leads use the dashboard, engineers use the CLI, and both read from the same API.

    localhost:8787 · Northgate Control Tower Narrated
    Executive overviewLive control towerSecurity & qualityRemediation queueFinOps

    The fix-first queue

    Four scanners give you four lists. Northgate gives you one.

    Security tools rank by severity. Cost tools rank by spend. Nobody tells you which single change clears the most risk for the least effort. Northgate fuses every engine into one score per finding, so the top of the queue is the work that moves the most.

    Security exposure× 0.45
    Reliability risk× 0.25
    Cost impact× 0.20
    Ownership gap× 0.10

    Findings come from semantic static analysis, dependency CVEs from the OSV database, license checks, CI/CD run data and cloud spend. Each one lands in the same ranked list.

    #FindingSeverityReposScore
    1
    Middleware authorization bypass in web framework
    one version bump · clears 3 criticals
    Critical 3 0.91
    2
    Shell injection in CI workflow input
    .github/workflows/release.yml
    Critical 1 0.84
    3
    Remote code execution in test runner dependency
    devDependency · CI exposed
    High 2 0.72
    4
    Idle build minutes on unowned service
    $7,625 / mo · no active owner
    Medium 1 0.58

    Example queue, drawn from a real scan of an eight-repository estate.

    The platform

    One tower over the whole estate.

    Live control tower

    Every push, as it happens

    Webhooks stream commits, new repositories and merges into one feed, attributed to the person behind them. Each push can trigger a re-scan that shows its security effect on the spot.

    Security posture

    Real findings with evidence

    Semantic static analysis, known CVEs in dependencies, and license compliance, with the offending line pulled from your own source and test code filtered out.

    Remediation queue

    A single ranked list

    Security, reliability, cost and ownership fused into one score. Your leads stop arguing about priorities and start closing the top item.

    FinOps

    What each repo costs

    Pipeline spend from real CI run minutes, duplicate services grouped into clusters, and a reclaim estimate for the waste you can retire.

    Migration cockpit

    Waves, blockers, progress

    Track every repository through migration with a state machine, assign waves, and see exactly what blocks each one from moving.

    Trends and drill-in

    Posture over time

    Scheduled snapshots chart debt and security scores week over week. Open any repository to see its findings, owners, pipelines and history.

    Agent add-on · fix by pull request

    From finding to fix, with a person holding the merge button.

    The agent reads the source, writes the patch, and opens a pull request on a new branch. It never pushes to your default branch and never merges on its own.

    Triage

    The agent works the top of the queue and spots shared root causes, such as one dependency bump that closes several criticals.

    Patch

    It fetches the affected files, targets the right manifest even in a monorepo, and prepares the smallest change that resolves the finding.

    Open PR

    A branch and pull request appear in your repository with the finding, the reasoning and the diff. The action is written to the audit log.

    Human step

    Review and merge

    Your engineer reviews it like any other PR. Nothing reaches production until they approve it.

    Built for the security review

    Your code stays yours.

    Northgate is designed to pass a CISO's questions before the first demo. It deploys as one container inside your environment and refuses to start in production with unsafe settings.

    seq actor action hash 1041 lead@corp scan.live 9f3c…a1e2 1042 agent(svc) fix.propose 4b7d…0c9f ← 9f3c 1043 agent(svc) pr.open e210…77b4 ← 4b7d 1044 admin@corp audit.export c85a…3d10 ← e210
    • Private repositories onlyIngestion requires an authenticated token and reads private repos exclusively. There is no public fallback.
    • Deploys in your environmentOne container serves the app and API. You own the host, the network and the data.
    • Tamper-evident audit trailEvery action is written to a SHA-256 hash chain. Change one entry and every entry after it stops verifying.
    • Bring your own AI keyAgent runs use your own Anthropic key, encrypted at rest. We never see or bill those tokens.
    • Role-based access and tenant isolationViewer, lead and admin roles, account lockout, revocable sessions and per-tenant data separation.

    Plans

    Licensed monthly. Start with visibility, add the agent when you're ready.

    Base

    Control Tower

    Full visibility and a ranked plan of action for your whole estate.

    • Live activity feed across every connected source
    • Security posture: static analysis, CVEs, licenses
    • Fix-first remediation queue
    • FinOps, migration cockpit and trend reporting
    • Audit log export and role-based access

    Monthly license, sized to your repository count.

    Base + Agent

    Control Tower with Agent

    Everything in Base, plus an agent that turns findings into reviewed pull requests.

    • Agent triage across the full queue
    • Fix-by-PR on new branches, human-merged
    • Auto re-scan on every push
    • Background job queue with retries
    • Runs on your own AI key

    Monthly license. AI usage is billed to your own key, typically cents per run.

    Put your estate
    under one tower.

    We'll connect Northgate to a sample of your private repositories and walk your security and platform leads through the live queue in 45 minutes.

    Request a briefing