Skip to main content
The loop is the core model behind Cantina. It describes how a security issue moves from first signal to verified closure, and it is the same whether the work starts in code, in the cloud, or in your identity provider.

1. Find

Signals come in from Apex (code and pull requests), Clarion integrations (SIEM, EDR, cloud, identity, and more), and the human network (audits, competitions, bounty). Cantina turns raw signal into a validated, contextualized finding.

2. Prioritize

Not every finding deserves the same attention. Cantina weighs each against your environment: is the affected service exposed, who owns it, does it carry regulatory weight, is it reachable in practice. The output is a short list your team can trust.

3. Remediate

Cantina works the fix to completion. It can generate the change, open a context-rich pull request or ticket, and route it to the right owner. Consequential actions can be gated behind human approval; the team controls the level of autonomy.

4. Prove

Closure is verified, not assumed. Cantina confirms the issue is actually resolved (the check passes, the exploit path closes), records the evidence, and keeps proof on the record.

Why the loop matters

Time to exploit is going down. Time to remediate has been going up. Breaches happen in that gap. The loop is how Cantina closes it, and how a lean team gets the security capacity of a team many times its size.