Parse supported manifests. Review what matters first.
Perpensa inventories five shipped parser families, matches advisories, and ranks the resulting findings and update candidates—so AppSec and platform share one review queue.
No credit card. Deterministic scoring always on—AI is explainable and optional.
Prioritized updates
Base risk + AI delta
- expressCritical+4npm
AI: direct dependency · KEV · review first
CVE-2024-43796
4.18.24.21.2risk 96100Review - djangoCritical+2pypi
AI: direct dependency · public exploit signal
CVE-2024-45230
4.2.114.2.16risk 9193Review - lodashHigh-12npm
AI: transitive dependency · lower priority than direct criticals
CVE-2021-23337
4.17.204.17.21risk 7866Wait - reactLownpm
Hygiene patch — no CVE · schedule with next release
18.2.018.3.1risk 2222Batch - junit:junitInfo-8maven
AI: no matched advisory · schedule after security work
4.12.04.13.2risk 1810Defer
Parser families shipped in this version
- npm
- PyPI
- Dockerfile FROM
- Go modules
- Maven / Gradle
Interactive demo
Real product paths, labeled demo data
Run a fixture scan, apply policies and optional AI, request an evidence-note PR on a writable remote, then preview or deliver a digest when a provider is configured. Switch between Acme (Team) and Northstar (Starter) in the app sidebar — isolation is real; the repositories and findings are sample data.
- 01
Scan
Fixture parser + advisory evidence
- 02
Policy
Suppression rules · KEV guardrail
- 03
AI rank
F21 on top of F05 risk score
- 04
Apply
Suggestion · suppress · PR note
- 05
Digest
Stored preview · optional delivery
- 06
Orgs
Switch demo tenants in-app
See the queue your team will live in
Current sample-data captures of the overview, risk-ranked queue, and matched findings. Click any shot to open that screen in the demo.

Posture overview
Criticals, highs, and a 7-day trend at a glance.
- app.perpensa.dev

Update queue
Risk-ranked updates from supported parsers and repositories.
- app.perpensa.dev

Findings
Triage open advisories with KEV and exploit signals.

Mobile-ready triage
Queue and detail stay readable at ~390px. Primary actions stay thumb-friendly so on-call can act without a laptop.
Try the queueRisk over volume
Not another upgrade bot
Renovate and Dependabot keep dependencies fresh. Perpensa tells you which findings and update candidates deserve review, why, and what to do first—with a shared queue and evidence for AppSec.
Risk over volume
A KEV-listed or high-exploit-probability finding before forty hygiene patches. Deterministic score first—always auditable.
Brain, not another arm
Renovate is excellent at automation. Perpensa is the triage layer AppSec and platform share.
Evidence, not just bumps
Findings, digests, CycloneDX/SPDX exports, and an audit trail — prove you are watching, not only merging.
Opens / groups PRs to keep packages fresh
Ranks the queue by risk (CVE/severity, EPSS, KEV/public exploit, direct/transitive)
Noise is volume of bumps (tunable, still PR-centric)
Prioritised queue + digests; optional evidence-note PR
Lives in each repo’s config
One org cockpit: findings, inventory, SBOM, policies
Needs write to open branches
Read-first scan; public watch without push rights
Works alongside Renovate. Keep the bot for cadence and automerge; use Perpensa as the risk brain — triage, digests, SBOM, and optional evidence-note PRs on writable repos. Perpensa does not edit manifests today, and does not claim to replace Renovate's ecosystem depth.
Features
Built for teams who can't afford surprise outages
Stop sorting by severity alone. Perpensa turns supported dependency evidence into a prioritized review queue—scored by risk, shaped by policy, optionally re-ranked by AI.
Supported manifest inventory
Parse npm, PyPI, Go, Maven/Gradle lock data, and Dockerfile base-image references. Other package formats are not scanned yet.
Auditable risk scores
Rank matched advisories with deterministic severity, EPSS, KEV/public-exploit, and direct/transitive inputs. Every factor remains visible.
AI prioritization
Team plans can re-rank from allowlisted inventory and advisory metadata. On failure, a deterministic heuristic delta is applied instead.
Policy engine
Configure transitive-medium suppression, KEV guardrails, alert floors, and an open-PR limit. Policy actions are recorded for review.
Five parser families, one queue
npm and compatible JS lockfiles, PyPI lock and requirement files, Go modules, Maven/Gradle lock data, and Dockerfile FROM images.
Evidence-note PR workflow
With VCS write access, open a remote PR containing a .stackpulse evidence note. It does not edit manifests or run a package manager; grouped notes are GitHub-only today.
Digest previews and delivery
Build ranked email and Slack previews. Delivery requires a configured provider or per-org webhook; scheduled multi-tenant Slack remains store-only.
SBOM & audit-ready
Export CycloneDX or SPDX SBOMs, findings and updates CSV, and a compliance bundle. Scan, AI, policy, and digest actions produce audit events.
How it works
From connect to digest in one continuous loop
The demo uses labeled sample data and fixture scans while exercising the real queue, policy, export, and delivery-preview paths.
- 01
Connect your repos
Connect GitHub, GitLab, Bitbucket, Forgejo, or Gitea credentials. Public GitHub watches stay read-only.
- 02
Parse supported files
Supported lockfiles, manifests, and Dockerfile FROM lines feed OSV matching, with fixture fallback for the demo.
- 03
Score + policy
Transparent F05 risk (0–100), then deterministic policies such as suppression floors and a KEV suppression guardrail.
- 04
AI prioritize
Optional F21 re-ranks allowlisted update and finding metadata. Suggested actions remain explicit and auditable.
- 05
Review & notify
Leave advice unapplied or ignore it, create an evidence-note PR when configured, and preview or deliver digests through configured channels.
Risk you can audit. Priority your team can act on.
Perpensa adds an LLM layer above the transparent risk score—not instead of it. Validated output structure, allowlisted inventory context, and human-or-policy final say.
How priority is built
F05 → F21- 1
Deterministic risk (0–100)
Severity, EPSS, KEV/public exploit, and direct/transitive dependency status.
- 2
Context pack
Package, versions, advisory facts, and related findings—metadata only, not your source tree.
- 3
LLM delta + rationale
Validated JSON: priority adjustment, suggested action, citations. Low-confidence output stays advice for human review; on model failure, a deterministic heuristic delta is used.
- 4
You decide — one click
Applying a suggestion can request an evidence-note PR or suppress with a reason. Both paths are audited.
Model output is validated JSON with structured citations. Vulnerability matching remains independent and uses OSV/semver; requested actions are re-checked against their own authorization and policy gates.
Auditable score first
Severity, EPSS, KEV/public-exploit, and direct/transitive inputs stay deterministic. The model never replaces the risk formula.
Context-aware priority
Re-rank from allowlisted inventory, update, and advisory metadata. No repository source tree is sent to the model.
Structured suggestions
Return a validated priority delta, rationale, suggested action, and citations. Digests can use the resulting effective priority.
Human-controlled actions
Apply a suggestion explicitly or leave it as advice. Suppression requires a reason, and PR creation remains a separate audited action.
Pricing
Product plan gates, without a billing claim
The plan and entitlement shell is implemented; billing checkout is not connected yet.
Starter
For side projects and open source maintainers.
Freeplan shell- 3 repositories (VCS + public watches)
- Five shipped parser families
- Deterministic risk scores
- Email digest preview or configured delivery
- CycloneDX, SPDX, and CSV exports
- Team feature gate
Team
For product and platform teams shipping weekly.
Pilotno checkout yet- Unlimited repositories
- Manual and webhook scan jobs
- Optional AI prioritization
- Policy controls and audit events
- Evidence-note PRs with VCS write access
- Configured email, Slack, and webhook delivery
- CycloneDX, SPDX, and CSV exports
Enterprise
For teams evaluating the self-managed deployment path.
Self-hostDocker path- Everything in Team
- Node-server Docker build
- Organization roles and audit events
- Encrypted per-org integration secrets
- Policy YAML import and export
- Self-managed runtime controls
Shipped workflow
What the current product helps teams review
Review matched advisories in one risk-ranked queue instead of treating every version bump as equally urgent.
Generate email or Slack previews, then deliver only when the corresponding provider or per-org webhook is configured.
Open a remote evidence-note PR when write credentials exist, while leaving the actual dependency edit and verification to the team.
Explore the evidence before choosing an action
Explore the sample-data demo—risk-ranked queue, findings, exports, policies, and optional AI prioritization.
Explore the live demoAuditable scores. Optional AI uses allowlisted inventory and advisory metadata—not the open web.