Smithy is a platform that automates security workflows and integrates various application security tools, enabling teams to identify and address vulnerabilities without writing code. By streamlining data management and enhancing toolset deployment, Smithy increases operational efficiency and allows security teams to focus on critical tasks.
Funding
Funding not disclosed

Founders
Product
Problem
Security teams often struggle with fragmented application security toolsets and manual workflows, leading to inefficiencies in vulnerability identification and remediation. Integrating diverse security tools and managing the resulting data requires significant engineering effort and custom code. This complexity hinders operational efficiency and diverts security teams from focusing on critical security tasks.
Solution
Smithy is a no-code security workflow automation platform that integrates with existing application security tools to streamline vulnerability management. The platform allows security teams to build custom workflows by connecting various security tools through a drag-and-drop interface. Smithy automates data enrichment, deduplication, and routing, enabling teams to identify, prioritize, and address vulnerabilities more efficiently. By automating repetitive tasks and providing a unified view of security data, Smithy increases team capacity and reduces the need for custom scripting.
Target Audience
Smithy is designed for application security teams, DevOps engineers, and security architects who need to automate security workflows and integrate diverse security tools without writing code.
Features
- No-code workflow builder for creating custom security automation pipelines
- Seamless integration with a wide range of application security tools, including SAST, DAST, and SCA scanners
- Automated data enrichment and deduplication to improve the accuracy and completeness of vulnerability data
- Centralized dashboard for visualizing security data and tracking workflow progress
- Flexible deployment options, including on-premises and cloud-based deployments on Kubernetes
- Open-core architecture providing transparency and community contributions
- Pre-built integrations with popular tools such as GitHub, Snyk, Semgrep, and DefectDojo
- Role-based access control for managing user permissions and data access