Shifting security left at enterprise scale
Engineering

Shifting security left at enterprise scale
At a global investment bank, code could reach production without being properly scanned. We built an event-driven platform that scans every push across a complex mix of tools and environments and enforces security policy in real time.
The challenge
The problem was a gap between development and production: changes were going live without a proper scan, so a vulnerability introduced during development could reach production without anyone being alerted.
The environment ruled out a simple "scan everything" answer. Developers worked across many combinations of languages, source-control repositories and practices, continuous-integration tools, deployment targets and operating systems. The scanning tools varied too: some support certain languages or source-control systems and not others, and some need a build of the code while others don't.
What we did
We built a cross-platform design that works across multiple scanning tools, CI environments and source-control systems, so vulnerabilities are found and fixed early, before release. The platform has three parts:
Configuration. A tailored set of configurations for each project and tool, stored and managed dynamically in a database. When a configuration changes, events propagate the update to every relevant component immediately.
Scanning. Coordinates each scan using reusable job components built on Jenkins Pipeline-as-Code templates. Results are stored as evidence for delivery-lifecycle policy checks.
Review. Analyses scan results, evaluates them against policy, and confirms whether a release is safe from a security point of view.
The key architectural choice was to make the whole system event driven. Scanning and policy decisions complete in real time, so developers aren't left waiting on API calls or batch jobs. The platform is fully self-service, auditable and extensible, and every policy decision is backed by cryptographically signed evidence, so it can't later be disputed.
Several supporting pieces made it practical at scale: a shared library that removed much of the duplicated code across services; a WebSocket integration that gives developers real-time feedback; a vulnerability-report command-line tool for management; and automated system tests that run every three hours to confirm every service involved in a scan is working.
The outcome
The platform is in production and heavily used. As at mid-2025, it had published around 1.9 million events and scanned roughly 7,000 projects, with the majority of the firm's projects and development teams onboarded. Every code push is scanned, and policy is enforced from development through QA to production.
It has also proven easy to extend under deadline. When the firm needed AI-assisted scanning, where a model reviews and interprets scan results, we added it in 15 days, fully compatible with the existing tools.
Shifting security left at this scale isn't about finding a better scanner. It's about building a self-service layer that sits across all your tools and environments, enforces policy in real time, and produces signed evidence, so that the code you scan is always the code you release.
Facing a similar challenge? Get in touch. We'd be glad to talk it through.



