# Oplane > AI coding agents now ship more code than security teams can review, and code scanners catch line-level > bugs, not the architectural risk in how a system is designed. Oplane closes that gap: an AI agent that > continuously threat-models a codebase, finds real risks in minutes, and drives the fix itself. It is > not a code scanner and not "a better AI SAST," it works one layer above, at the architecture. Free to test. ## Product - [Oplane](https://www.oplane.com/): Homepage. Security built in: continuous architectural threat modeling for AI-first engineering teams. - [Continuous Threat Modeling](https://www.oplane.com/product/continuous-threat-modeling): Always-on architectural threat modeling that stays current with every repo and every change. - [AI Coding Security](https://www.oplane.com/product/ai-coding-security): Oplane in the IDE via MCP, surfacing security requirements in Claude Code, Cursor, and Copilot CLI before a PR is opened. - [PR Analysis](https://www.oplane.com/product/pr-analysis): Scans every pull and merge request against the architectural threat model and posts findings inline before merge. ## Solutions - [Enterprise](https://www.oplane.com/solutions/enterprise): For organisations shipping AI products at scale, where every architectural change carries compliance and customer implications. - [Scale-ups](https://www.oplane.com/solutions/scale-ups): For Series A-C engineering teams shipping AI products faster than security can keep up. ## Docs - [Documentation](https://www.oplane.com/docs/introduction): Setup, MCP/IDE integration, GitHub and GitLab connections, workspaces, roles, and the Oplane vs. AI security scanners comparison. The docs are served separately via Mintlify and publish their own [llms.txt](https://www.oplane.com/docs/llms.txt) and [llms-full.txt](https://www.oplane.com/docs/llms-full.txt); see those for full documentation content. ## Research and disclosures - [Blog](https://www.oplane.com/blog): Security research, findings disclosures, and notes from building Oplane. - [An AI agent in CI turns a public issue into an unauthenticated input](https://www.oplane.com/blog/agent-in-ci-untrusted-input): Disclosure of an untrusted-input path from a public issue into an AI agent running in CI. - [claude-mem runs an unpinned dependency with your full credentials](https://www.oplane.com/blog/claude-mem-unpinned-dependency): Disclosure of an unpinned dependency risk in the claude-mem project. - [Reachability makes AI threat modeling worth the trust](https://www.oplane.com/blog/help-net-security-reachability): Why reachability analysis, not just pattern matching, is what makes AI-driven threat modeling trustworthy. - [When a coding skill tells the AI to leave vulnerabilities alone](https://www.oplane.com/blog/karpathy-skills-security-blind-spot): A security blind spot in how coding agent skills can instruct a model to ignore vulnerabilities. - [Stored XSS to account takeover in Multica (self-hosted)](https://www.oplane.com/blog/multica-xss-account-takeover): Disclosure of a stored XSS to account takeover chain in the self-hosted Multica project. - [Give every step a definition of done. Then it stops mattering who does it.](https://www.oplane.com/blog/ai-patches-definition-of-done): On applying a clear definition of done to AI-authored changes, security included. ## Company - [About](https://www.oplane.com/company): Who Oplane is built by and why: security expertise built for AI-first engineering teams, by people who lived the problem. - [We raised $5.2M to build security into AI-first development](https://www.oplane.com/blog/seed-round): The seed round announcement. - [Careers](https://www.oplane.com/careers): Open roles, remote-friendly, based out of Malmö. ## Get started - [Request a demo](https://www.oplane.com/demo): A security engineer walks through Oplane on your own architecture. Free to test.