# From security findings to verified fixes across two repositories. Using a synthetic assessment of our own code, Deployment.io checked eight findings and rejected two deliberately incorrect claims. One selected remediation became two pull requests, opened seven minutes after the Task started. - Type: Case study of Deployment.io's work on its own product - Area: Security and compliance remediation (https://deployment.io/solutions/security-compliance/) - When: September 2026 ## Results - **8** — findings triaged against the code - **2** — deliberately incorrect findings rejected with code references - **7 min** — from Task start to pull requests in 2 repositories ## The situation We created a synthetic, nine-page assessment to evaluate how Deployment.io handles security findings in our own dashboard and API. It contained five valid findings, two deliberately incorrect claims, and one finding that required repositories outside the session. The evaluation tested whether the workflow could distinguish valid findings from incorrect claims and carry a selected remediation through to reviewed code. ## What Deployment.io did We attached the report to a Deployment.io Assistant session connected to the dashboard and API repositories. Each finding was checked against the code. - Both deliberately incorrect findings were rejected with file and line references. - The finding involving other repositories was flagged for validation, with the required repositories identified. - Inaccurate descriptions of valid findings were corrected using the code. - One selected remediation became a specification, preserving its finding ID and verification criteria across the API and dashboard changes. The Task opened two pull requests seven minutes after it started. The changes tightened message validation in the API and message handling in the dashboard, with regression tests covering both. Before the pull requests opened, both repositories passed their builds and automated checks, including tests across 15 Go packages and 198 dashboard tests. ## Verified outcome The fixes for the selected remediation were reviewed and merged the same morning, then deployed to production. The seven-minute figure measures Task start to the two pull requests. It excludes assessment, specification, engineer review, and production rollout. ## The work - **Input:** 9-page synthetic assessment, 8 findings - **Repositories changed:** API, dashboard - **Verification:** Builds, type checks, tests across 15 Go packages, 198 dashboard tests - **Outcome:** Selected remediation reviewed, merged, and deployed to production ## About - **Company:** Deployment.io - **Cloud:** AWS - **Stack:** Go services and a React dashboard in separate repositories --- Source: https://deployment.io/case-studies/security-findings-triage-and-remediation/