ShiftLeft (Qwiet AI) was acquired by OpenText in 2024 and may have been consolidated into the Fortify product line.
How Vulnetix compares: better together
Vulnetix does not replace ShiftLeft / Qwiet AI. Keep running it. Vulnetix sits on top of ShiftLeft / Qwiet AI (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
ShiftLeft / Qwiet AI is strongest at its core category and also carries features in SCA, Secret Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | ShiftLeft / Qwiet AI |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✓ Core: CPG-based SAST (preZero), deep data-flow, not pattern matching |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Intelligent SCA with CPG-powered reachability, 85-95% alert reduction |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ~ Detects hardcoded secrets and data leakage as a secondary CPG feature |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✓ Core differentiator: CPG data-flow reachability for both code and OSS CVEs |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What ShiftLeft / Qwiet AI does well
- Code Property Graph (CPG) approach analyses code as a graph rather than pattern-matching, enabling deep data-flow analysis across SAST and dependencies
- Best-in-class reachability: Intelligent SCA answers whether a CVE package is loaded, in use, attacker-reachable and reachable via data flow, cutting SCA alert noise by 85-95%
- AI/ML applied to the CPG (preZero) to surface zero-day and pre-zero-day vulnerability classes, plus hardcoded-secret and data-leakage detection
- Now embedded in Harness Security Testing Orchestration (STO) after the Sept 2025 acquisition, giving it a broader DevSecOps pipeline home
Where Vulnetix adds to it: Note: the seed's 'acquired by OpenText' is outdated: Qwiet AI (formerly ShiftLeft) was acquired by Harness effective Sept 26, 2025 and now ships inside Harness STO. Vulnetix complements rather than replaces Qwiet's CPG engine: it ingests Qwiet SAST/SCA findings (including its reachability verdicts) and consolidates them across every other scanner into one prioritised queue, adding exploit-intel (EPSS, KEV, ESS, CWSS, LEV), immutable versioned VEX + audit, SSVC/EOL policy, Safe Harbour autofix, plus native IaC, container, cloud/CSPM, SBOM and install-time package-firewall/malware coverage Qwiet doesn't run. Both do reachability; Vulnetix layers governance and cross-tool prioritisation on top.
No migration, no rip-and-replace. ShiftLeft / Qwiet AI keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise ShiftLeft / Qwiet AI results in Vulnetix
Upload ShiftLeft / Qwiet AI SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.