FAQs
Who is Heeler built for?
Heeler is built for security leaders — CISOs, AppSec, ProdSec, and DevSecOps — at companies where developers and AI coding agents work side by side. The platform brings security guidance into the moment of code generation, so AI-assisted development doesn't outpace what review can catch.
What does "Agentic Development Security" mean?
Agentic Development Security (ADS) is the emerging security paradigm Forrester introduced for AI-powered software development. It spans prevention, detection, prioritization, remediation, policy, and continuous intelligence across the AI SDLC. Heeler operationalizes that model through three continuous layers: Prevent, Fix, and Operate, all powered by one Context Engine.
What is the Context Engine?
The Context Engine is Heeler's foundation: six interconnected dimensions — Code, Cloud, Business, Ownership, Threat, and Agent — automatically built and maintained from your existing tools. Every security decision Heeler makes draws from this context, so what's risky for your organization differs intelligently from what's risky in the abstract.
How does Heeler integrate with AI coding agents?
Heeler ships an MCP server and Agent Skills that AI coding agents (Claude Code, Cursor, GitHub Copilot, and others) read at the moment they generate code — so policy and security context arrive in the agent's reasoning instead of failing review later. A CLI lets developers and agents run the same checks locally before commit.
What does Heeler do at PR time?
Heeler runs Block / Warn / Observe guardrails on every PR. Block prevents merge on critical violations. Warn flags issues for reviewer attention without blocking. Observe captures data without changing behavior, so teams can roll out new guardrails risk-free before enforcing them.
What is deterministic agentic remediation?
Heeler separates the security decision from the agent doing the work. For dependency findings, Heeler computes the exact upgrade target from the dependency graph and live vulnerability data. For supported SAST findings, it selects a deterministic remediation strategy anchored to the proven source-to-sink path. An agent applies the change, your build and CI validate it, and Heeler opens a merge-ready pull request rather than handing you a suggested fix.
What is Agent Skills security?
Agent Skills Security inventories the instruction files, skills, subagents, hooks, MCP configuration, and related agent configuration already present in your repositories. Heeler analyzes them for deterministic indicators such as hidden Unicode, dangerous commands, excessive permissions, and suspicious external references, then uses semantic analysis to identify risky intent such as prompt injection, exfiltration, privilege escalation, and deception. Each file receives a safety score and verdict so security teams can review the agent supply chain like any other dependency class.
What environments and tech stacks does Heeler support?
Heeler is built for cloud-first engineering, and connects read-only — no agents, no sensors, no changes to your build. Source control: GitHub, GitLab, Bitbucket and Azure DevOps. Clouds: AWS, Azure and GCP, including serverless code on AWS Lambda and Azure Functions. Static analysis covers 30 languages and formats, among them Java, Kotlin, Scala, Groovy, C#, Go, Python, JavaScript, TypeScript, Ruby, PHP, Rust, Swift, C and C++, Objective-C, Dart, Elixir and Lua — plus Razor and Blazor components, Dockerfiles and GitHub Actions workflows. Automated fixes are available across 12 of those languages. Dependency analysis resolves npm, Maven, PyPI, Go modules, NuGet, RubyGems, Composer, Cargo, Hex, JSR, Swift Package Manager and GitHub Actions, with WordPress plugins and themes covered through Composer. Symbol-level reachability — proving the vulnerable function is actually called — runs for Go, Java and Python; everywhere else a finding is never downgraded on a reachability verdict Heeler cannot stand behind. Infrastructure as code covers Terraform, OpenTofu, CloudFormation, Pulumi and Kubernetes manifests, including Helm charts. CI systems detected per repository: GitHub Actions, Jenkins, GitLab CI, CircleCI, Azure Pipelines, Bitbucket Pipelines and Travis, with Jenkins and Actions pipelines analyzed for risky configuration. Workflows route to Slack, Microsoft Teams, Google Chat, email, Jira, Linear, GitHub Issues, Shortcut or any webhook.
Is Heeler a fit for my team?
Heeler is built for teams where AI coding agents are already writing production code. If agents are opening pull requests in your repositories, Heeler applies the same policy at code generation, at commit, at the pull request, and after merge.
What does Heeler cost?
Heeler publishes its full pricing: $35 down to $17 per contributing developer per month by volume, billed as an annual subscription with quarterly true-ups. Every tier includes the full platform.
How does Heeler count "contributing developers"?
A contributing developer is anyone whose commits land in repos Heeler is scanning. AI agents that commit on behalf of developers count under the human user account, not separately. The pricing unit scales with team size, not with how much code your agents generate.
Is Heeler SOC 2 certified?
Yes — Heeler holds a SOC 2 Type II attestation. Our complete compliance posture — controls, attestations, and security practices — is documented at our public Trust Center: trust.heeler.com.

