Scan and Fix
Not Scan and Sigh
Their AI Writes Summaries. Ours Writes the Fix.
Most security AI stops at a summary. DefectDojo Sensei scans your repositories, imports the findings, and opens pull requests that remediate them. Detection to auto fix, all in one platform.
Vulnerabilities Don't Negotiate. Neither Does Sensei
Security teams are drowning in findings, not insights. Scanners generate thousands of alerts. Deduplication and triage eat entire sprints. And the vulnerabilities that matter still sit open for months because the fix always lands in someone else's backlog.
The first wave of security AI made this worse, not better. Chatbots that summarize a CVE do not close it. Copilots that explain a finding do not patch it. And most AI tools ship your security data to a third-party model provider, which means a breach on their side becomes a breach on yours.
The gap is remediation. Finding vulnerabilities was never the hard part. Fixing them at scale, without adding headcount and without handing your data to another vendor, is where security programs stall.
DefectDojo built its AI to close that gap.
1 Click and Fixed
Watch Sensei take a real finding from alert to merged fix. One click on a vulnerability, one pull request out the other side.
Your Backlog Called. Sensei Already Closed the Ticket
Sensei is DefectDojo's AI-powered scan-and-fix capability for source code repositories, available in DefectDojo Pro. Connect a repository and Sensei handles the full loop: scan, import, remediate.
Connect Your Repositories
Sensei supports GitHub (github.com and GitHub Enterprise Server), GitLab (gitlab.com and self-managed), Bitbucket (Cloud and Server/Data Center), and Azure DevOps. Onboarding differs by provider; everything after setup follows the same scan-and-fix flow.
Scan and Import as Findings
Sensei scans your connected repositories and imports the results directly as DefectDojo findings. That means every AI-driven fix works from the same normalized, deduplicated finding data as the rest of your vulnerability management program. No parallel tracking, no second source of truth.
Auto Fix With Pull Requests
Sensei uses a large language model to remediate findings by opening pull requests (merge requests on GitLab), all without leaving DefectDojo. Developers review the fix in the workflow they already use.
Preview First, Always
Nothing runs until you approve. Sensei's preview-first workflow means no fix is generated and no LLM cost is incurred without your sign-off. You stay in control of what gets remediated and when.
Fix From the Pull Request Itself
Comment /fix on a pull request and Sensei pushes a remediation directly to that PR. Remediation meets developers where they work.
Human agency is the design principle. Sensei does not replace your engineers. It clears the backlog of well-understood fixes so your team can spend its time on the vulnerabilities that need human judgment.
Why Teams Choose DefectDojo for AI Security
Remediation, Not Just Recommendations
Most AI security tools end at advice. Sensei ends at a pull request. When the measure of your program is mean time to remediate, an AI that opens fixes beats an AI that writes summaries.
Grounded in a Single System of Action
DefectDojo aggregates findings from 500+ security tools, then deduplicates, enriches, and prioritizes them. Sensei and every MCP-connected model operate on that clean, unified data. AI built on noisy data produces noisy output; AI built on Dojo's system of action produces fixes you can trust.
Cost Control by Default
Preview-first execution means LLM costs only accrue on fixes you approve. Sensei usage is metered against your DefectDojo Pro license, so spend stays visible and predictable.
AI Triage and Risk-Based Prioritization
Beyond Sensei, DefectDojo Pro pre-triages findings by Priority and Risk, factoring in exploitability and business context rather than raw severity scores alone. Your team starts each day looking at the findings that actually matter.
Built by Practitioners, Governed by You
DefectDojo was born in the OWASP community and built by people who ran security programs themselves. Every AI capability follows the same rule: the practitioner approves, the AI executes. Role-based access controls govern who can configure Sensei and who can trigger a fix.
Bring Your Own LLM with MCP
Not every team wants a prescribed model. DefectDojo Pro supports the Model Context Protocol (MCP), the open standard for connecting AI models to live data, so you can plug the LLM of your choice into your vulnerability data with one setup.
Any MCP-Compatible Model
Connect DefectDojo Pro to any third-party or custom model that supports MCP. Your team keeps its preferred AI stack while gaining direct, structured access to findings, deduplication logic, triage context, and security posture data.
Your AI Gets DefectDojo's Context
With an MCP connection, your model can work with the same intelligence DefectDojo Pro applies to your findings: deduplication, auto-triage, vulnerability differentiation, and posture insights, all through natural language interaction.
Security Built Into the Protocol Layer
DefectDojo's MCP implementation includes additional precautions around deployment, with each MCP deployment handled per customer. Your data stays governed by your DefectDojo instance, not scattered across integrations.
Frequently asked questions
What is DefectDojo Sensei?
Sensei is DefectDojo's AI-powered scan-and-fix capability for source code repositories, available in DefectDojo Pro. It scans connected repositories, imports the results as DefectDojo findings, and uses a large language model to remediate findings by opening pull requests.
How does Sensei auto fix vulnerabilities?
Sensei generates remediations as pull requests (or merge requests on GitLab) against your connected repository. Every fix follows a preview-first workflow: nothing is generated, and no LLM cost is incurred, until you approve. Developers can also trigger a fix by commenting /fix on a pull request.
Which source control providers does Sensei support?
Sensei supports GitHub (github.com and GitHub Enterprise Server), GitLab (gitlab.com and self-managed), Bitbucket (Cloud and Server/Data Center), and Azure DevOps.
Is Sensei available in Community Edition?
No. Sensei is a DefectDojo Pro feature. Community Edition remains free forever with 500+ parsers, deduplication, and an OSI license, but AI-powered scan-and-fix requires DefectDojo Pro.
What is MCP and how does DefectDojo use it?
The Model Context Protocol (MCP) is an open standard for connecting AI models to external data and tools. DefectDojo Pro's MCP support lets you connect any MCP-compatible LLM, third party or custom, to your vulnerability data, giving your model of choice access to DefectDojo's deduplication, triage, and security posture context.
Do I control when AI runs and what it costs?
Yes. Sensei's preview-first workflow means no remediation runs without approval, and LLM costs are only incurred on approved fixes. Sensei usage is metered against your DefectDojo Pro license. Configuring Sensei requires a global Maintainer or Owner role, and triggering a fix requires at least Writer access to the finding's product.
Does AI replace my security team?
No. DefectDojo's AI is built to multiply your team, not replace it. Sensei clears the high-volume, well-understood fixes; your engineers keep judgment calls, approvals, and architecture decisions. Every AI action in DefectDojo has a human in control.