Skip to content

Fendix for Software Houses

One repeatable security decision process across client projects.

Reduce manual release review while producing technical evidence clients can understand and carry forward.

Client delivery

Make release security consistent and transferable.

Standardize the gate

Apply reviewed policy across repositories without flattening project context.

Share the evidence

Give clients a clear record of testing, decisions, and remaining risk.

Reduce repeat review

Use the same decision workflow across multiple delivery teams.

Improve handover

Preserve provenance, ownership, and verification for due diligence and handover.

03Security Decision Record

One defensible security decision for every release.

See what changed, what was tested, which policies were triggered, and why the release received its decision.

Illustrative example — fictional data, not a customer record.Decided:

Release

payments-api · 2.14.0 · commit 9f3c1ab

Policy: .fendix.yaml v1 — blocks at CRITICAL

Highest finding status

WARN

Decision reasons

  1. 011 HIGH finding reachable from an authenticated route — warns, does not block, under your policy.
  2. 02Dependency scan did not complete, so part of the release is undecided.
  3. 031 accepted risk expires in 6 days and has no fix in progress.

Tests and scanners

  • Static analysis· completed
  • Secret scanning· completed
  • API probing· completed
  • Dependency scan· failed
  • Infrastructure config· not configured

Coverage gaps

  • Dependency scan failed — lockfile could not be resolved. Re-run before relying on this decision.
  • Infrastructure config scanning is not configured for this repository.

Since previous release

  • 2 new
  • 1 fixed
  • 11 persisting

Accepted risks

Wildcard CORS origin on /public/status

Accepted by Security Lead · expires 2026-08-04

Assigned owners

  • SQL injection in refund handler

    @payments-team · due 2026-07-29

  • Missing rate limit on /api/v2/login

    @platform-security · due 2026-08-07

Fix verification

  • 1 verified resolved
  • 1 still present
  • 1 queued

Human accountability

Awaiting sign-off. The accountable owner can approve this recommendation, override it with a documented reason, accept a risk for a defined period, or request verification after a fix.

Audit trail · 4 recorded events — policy evaluated, decision recorded, risk accepted, owner assigned.

  • BLOCK
  • WARN
  • INFO

Test the workflow on one client project.

Bring a repository or staging API and we’ll walk through the evidence together.

Book a Technical Walkthrough