Trust Issues: AI can write the fix. We make it prove it.
AI coding agents can identify vulnerabilities and generate patches in seconds. But who verifies that those patches actually work?
Trust Issues is an autonomous security remediation system that detects vulnerabilities, generates patches, independently verifies their effectiveness, and escalates unresolved issues to human engineers through AI-powered phone calls.
How it works:
Detect: Semgrep scans repository changes and identifies vulnerabilities.Reproduce: An AI agent generates an exploit test to establish that the vulnerability is real.Repair: OpenAI generates a candidate security patch in an isolated environment.Verify: Six independent checks validate exploit prevention, security rescanning, regression tests, test integrity, and patch scope.Escalate: After two failed verification attempts, an ElevenLabs voice agent calls an engineer, explains the evidence, and requests a decision to ship, hold, or retry.Audit: ClickHouse records remediation attempts, verification outcomes, and human decisions.Trust Issues also supports repository monitoring and GitHub pull requests containing proposed fixes and regression tests.
Our principle: Never trust an AI-generated security fix without evidence.