Case Study

FinTech giant automates security vulnerability fixes with AI + CAST

FinTech giant

The company provides property data, analytics and software globally to lenders, insurers and real estate businesses worldwide. Its solutions help clients assess property values and risk, make informed financial decisions and manage transactions more efficiently.

94.7%

of identified vulnerabilities fixed automatically

12-20X faster

vulnerability
remediation

FinTech giant automates security vulnerability fixes with AI + CAST

“With CAST, we’ve cut per application remediation from 6-10 hours to 30 minutes.”

Head of Engineering

A global FinTech company used AI + CAST to automate vulnerability remediation, resolving 94.7% of identified vulnerabilities on a target set of applications. With remediation 12–20X faster, the company is now expanding the approach across thousands of repositories to reduce security exposure and free engineering capacity.

Challenge

The company’s CISO and CIO set a six-month deadline to remove vulnerabilities in open-source components across thousands of repositories. Manual remediation took 6-10 hours per application, making engineering capacity a major obstacle to meeting the deadline.

The team needed to demonstrate that AI could automate reliable fixes before expanding the approach across the portfolio.

Solution

The company utilized AI + CAST on selected applications. CAST Highlight identified applications with vulnerable components. CAST Imaging mapped application dependencies and the potential impact of changes, giving AI deterministic software intelligence and detailed context to guide remediation.

AI used that intelligence to generate fixes. An automated workflow then applied, tested and validated those fixes.

Results

AI + CAST remediated 94.7% of identified vulnerabilities, with fixes automatically applied, tested and validated. Remediation time per application fell from 6–10 hours to 30 minutes, reducing the engineering effort required to address security vulnerabilities, helping teams meet the aggressive deadline, and freeing up engineering capacity to focus on higher value development tasks.

The company is now extending the approach across its broader portfolio of thousands of repositories.