A global property data and analytics company that turns large-scale property, ownership, and market data into insight and decision tools for customers across real estate, lending, and insurance.
remediated; fixes applied, tested, and validated automatically
by replacing manual baseline with automated loop
Head of Engineering
The company's CISO and CIO issued a joint mandate: remediate every software composition analysis (SCA) vulnerability across thousands of repositories within six months. Done manually, patching averaged hours per application – so at portfolio scale, effort, not technique, was the binding constraint.
Before committing the full estate, the team needed proof that an automated approach could hold up reliably at speed under real production conditions.
To de-risk the mandate, the team piloted the approach on a defined slice of the portfolio – roughly 153,000 lines of code. CAST Highlight triaged at portfolio level, identifying which applications carried SCA vulnerabilities; CAST Imaging then worked at application level, deterministically mapping each vulnerability and its blast radius.
Through MCP, Claude Sonnet drew on that intelligence to generate grounded remediations, which were automatically applied, tested, and validated.
On this bounded slice, AI grounded in CAST software intelligence cleared 94.7% of the SCA vulnerabilities identified – each fix applied, tested, and validated, not merely attempted. Where manual patching had cost hours per application, the automated loop cut per-application remediation effort by 12-20X.
Having proven both coverage and efficiency under real conditions, the organization is now extending the same deterministic process across its broader portfolio of thousands of repositories.