THE ARKO PLATFORM

Keep your tools.
Own the standard.

ARKO connects your organisation’s policies, code checks and review evidence across the tools your teams use to build.

INSIDE THE WORKFLOW

Find the risk.
Check the fix.

Understand what drives your Code Health Score: follow the underlying findings, the checked scope and the proposed change. Explore the complete example workspace: five findings, code changes, verification, agent activity and the Control Plane.

The demonstration uses sample code and data. It does not scan a live project.

Try it on a project
arkoINTERACTIVE WORKSPACE
Fictional project · working demo
example / AI customer workspacefeature/ai-assistant
CODING BRIEF

Add an AI assistant that can look up a customer’s orders. Follow our approved services, protect credentials and keep the request bounded.

app-chat.tsOriginal example
TypeScript · synthetic sourceReady to review
READY / Explore → Scan → Review → Apply → VerifyAll actions run locally in this demo

Software inventory

Synthetic dependency inventory for this demonstration.

FROM THE FIRST EDIT TO THE RELEASE DECISION

One standard.
Across the delivery path.

Different stages expose different risks. Follow the workflow to see where checks, gates and evidence fit—and what each integration needs.

01DesignCONTEXT & POLICY
CONTEXT ⇄ CHECK ⇄ EVIDENCE

CONTEXT & POLICY

Give the work a clear starting point.

Bring application context, approved patterns and organisational policies into the review. Make the intended architecture visible before judging the change.

Supply and maintain the context relevant to the application and team.

Explore system context

Workflow overview. Controls and availability depend on the integration, deployment and agreed scope.

HUMANS. AGENTS. THE SAME STANDARD.

Two ways to build.
One control layer.

01 / DEVELOPER

Review in your editor.

Inspect the finding, its context and the proposed change. Stay in control of what is applied.

Set up the IDE ↗
02 / AGENT

Check inside the task.

Give your agent ARKO tools through MCP. Bring the independent result back into its next action.

Connect your agent ↗
03 / CONFIGURED GATE

Carry the decision forward.

Use supported hooks and repository checks to apply your policy. Enforcement depends on the integration and configuration.

Explore gate setup ↗
From finding to reviewed changeSee remediation in the editor, repository and decision record.

FROM FINDING TO REVIEWED CHANGE

Make the fix useful.
Then check it again.

Keep remediation close to the finding, whether the change starts in the editor, an agent session or a repository review.

IN THE EDITOR

Inspect the proposed fix.

Understand the change and its context before applying it. Keep the developer involved in the decision.

IN THE REPOSITORY

Bring the change to review.

Use supported remediation and pull-request workflows. Your review and merge policies still govern what ships.

IN THE RECORD

Follow the outcome.

Recheck the updated source and retain the finding, change, scope and decision in the shared view.

FROM INFERENCE TO EXECUTION EVIDENCE

Follow the suspicion.
Exercise the boundary.

Walk through an example customer-isolation check: from a source finding to a reproduced behaviour, then a recheck of the changed application.

SIMULATION WALKTHROUGH / SYNTHETIC EXAMPLE
ISOLATED APPLICATION
01Test agentCustomer A session
02Orders API/orders/:id
03Data boundaryCustomer B order
Suspected boundary gapSource inference
Review whether the route checks ownership before returning an order.
EXAMPLE ARTEFACT / CUSTOMER WORKSPACE
01 / STATIC PASS

Start with a question.

A source finding suggests that an authenticated customer may be able to request another customer’s order. It has not been reproduced yet.

Evidence type
Inference from source
What remains unknown
Whether the behaviour occurs in the running application.

Interactive illustration of the product direction. No application or security test runs here. Confirm current simulation availability, prerequisites and scope with ARKO.

Discuss simulation for your environment ↗

THE ORGANISATION BEHIND THE CODE

Same code.
More context.

A line of code is only part of the picture. Connect it to the application, approved patterns and the standards your organisation needs to uphold.

CONTEXT IN
Codebase & dependencies
AI-generated changes
Configuration & routes
Organisation policies
arkoShared contextPolicies ⇄ Evidence
SECURITY TEAM

Can this path reach restricted data?

Bring the route, authentication boundary and data flow into the finding. Judge it against the application’s actual responsibilities.

REVIEWED CONTEXT ↺

Your team’s decisions and updated policies inform subsequent checks across connected work.

INSIDE THE CHECK

Ground the analysis.
Keep people in control.

Deterministic checks, relevant context and configured model perspectives contribute to the assessment. ARKO Core evaluates the findings and proposed changes.

RULE-BASED CHECKS

A clear basis for known patterns.

Use deterministic checks for recognised risks. Keep the finding and its supporting source visible before adding further analysis.

Organisation context → AssessmentReview decisions → Updated context
The models that write your code and the configured perspectives used by ARKO have different roles.

ONE PLATFORM, CONNECTED PERSPECTIVES

Security is the start.
See the whole picture.

01 / SECURITY

Can this be exploited?

Find vulnerabilities, exposed secrets, dependency risks and infrastructure misconfigurations in the context of your code.

SASTSecretsDependenciesIaC
Architecture, threats and exposurePut findings into the context of the whole application.

ARCHITECTURE · THREATS · EXPOSURE

A finding needs
a system around it.

Look beyond the line of code. Bring the application’s shape and the organisation’s priorities into the decision.

Web interface
API service
Data store
ILLUSTRATIVE SYSTEM

Understand the system around the change.

Review components, routes, data flows and dependencies alongside the finding. Application context helps explain why the same code pattern can matter differently in different systems.

Illustrative system map. No customer application is shown.

Your coding model and the ARKO control layerUnderstand their roles and discuss inference requirements.

CONTROL LAYER ≠ CODING MODEL

Your models will change.
Your standards should endure.

The coding model helps produce the change. ARKO brings the surrounding policy, independent checks, remediation workflow and evidence together.

Connect through supported IDE, MCP and delivery integrations. Keep your governance decisions separate from the coding tool your team chooses.

Your inference requirements matter too.

If you need customer-managed inference or a particular deployment boundary, discuss the supported options with ARKO.

Discuss models and deployment

ACROSS YOUR ORGANISATION

Code comes from everywhere.
Control belongs in one place.

Bring your policies to every connected workflow. Bring findings, changes and review evidence back into one shared view.

EditorsAI agentsRepositories & CI
PoliciesEvidence
arkoYour Control Plane

Your team owns the standards.
ARKO connects them to the work.

Explore enterprise governance

GOVERNANCE ACROSS YOUR ORGANISATION

Set the standard.
Carry it into the work.

Teams use different editors, agents and repositories. ARKO connects their work to centrally managed policies, then brings the findings, fixes and review context back.

Explore your connected organisation
Example policy
arko
ORGANISATION POLICY

Use approved dependencies.

Bring your organisation’s approved package choices into connected coding workflows.

POLICIES OUT

One shared standard.

A common baseline reaches each connected workflow through ARKO.

  • Clear policy context
  • Consistent review criteria
  • Your configured gate behaviour

Select a team to follow its connection. Select it again to return to the whole organisation.

Illustrative organisation and policies. Available controls depend on your integration and organisation configuration.

Repository coverage and estate visibilitySee check sources, scope and review context across repositories.

ACROSS THE CODE YOU ALREADY OWN

See the estate.
Follow the changes.

New agent-generated code joins an existing system. Bring findings across repositories into one view and configure how checks keep up with change.

EDITOR & AGENT

Check in the workflow.

Run checks from your editor or agent. Available automatic checks and hooks follow the integration and organisation configuration.

Connect your workflow
REPOSITORIES

Keep the estate in view.

Follow repository findings and exposure context centrally. Configure change-triggered checks and scheduled re-scans for connected repositories.

Discuss repository coverage
REVIEW & DELIVERY

Apply your gate policy.

Choose advisory or blocking behaviour where supported. Keep the scope, completed checks and remaining findings visible to the people deciding.

Explore MCP gates

THE CONTROL PLANE

Every source of change.
One organisation view.

See which repository was checked, which workflow submitted it and what still needs attention. Keep the source and scope of each result visible.

arkoControl Plane
ILLUSTRATIVE ESTATE · SAMPLE DATA
Synthetic repository coverage example; no repositories were scanned.
RepositoryCheck sourceAnalysed scopeCompletionReview context
example-apiAgentEdited files · revision ACompleteQuery finding needs review
example-webCISubmitted change · revision BCompletePolicy exception needs a decision
example-workerRepositoryFull checkout · revision CIncompleteAwait a completed result
SHARED CONTEXT

Follow shared dependencies and recurring findings across repositories. Review inferred relationships alongside their supporting evidence.

READ THE FINDINGS BEHIND THE SCORE

Severity is one part of the decision.

Use the Code Health Score as a starting point, then inspect the findings, revision and completed scope. Where available, known-exploited indicators and exploit-probability signals add context to dependency prioritisation.

KEEP THE LENSES DISTINCT

A cost concern is not a security verdict.

Review security risk separately from advisory code-health, cost and strategy signals. Apply the policy appropriate to each finding rather than treating every perspective as the same gate.

THE DECISION LEDGER

Keep the decision.
Keep what supports it.

Follow the finding, the change, the reviewer’s decision and the result of the next check. Give the next person a record they can inspect.

Decision recordILLUSTRATIVE EXAMPLE
Finding
Unapproved AI service introduced
Source
Agent-submitted code
Change
Approved organisation gateway proposed
Review
Decision and rationale recorded
Recheck
Completion and scope attached
FINDING CHANGE DECISION EVIDENCE

Know where the result came from.

Keep human, agent and pipeline activity distinguishable. Follow decisions to fix or accept a finding, with the relevant context and responsibility visible.

Read the scope before the status.

A check of edited files, a full repository review and a running-system observation establish different things. Preserve that distinction in the evidence.

Discuss your evidence requirements

What does each result tell you?

CHECKED SCOPE

Files submitted during the task

WHAT IT ESTABLISHES

What the check found in the code submitted from that session.

KEEP IN VIEW

Other files and subsequent changes need their own coverage.

START WITH A WORKFLOW. GROW INTO ORGANISATION CONTROL.

Free for the developer.
A shared view for the organisation.

FOR DEVELOPERS

Free

Get ARKO into the tools you use to build.

  • IDE extension and MCP setup
  • Source, secrets, dependencies and IaC review
  • Findings, threat context and remediation guidance
  • A first project you can check and understand
Install ARKO free

FOR SECURITY & ENGINEERING TEAMS

Enterprise

Bring policies, repository coverage and evidence into one organisation view.

  • Control Plane and organisation policy
  • Repository, agent and CI context
  • Organisation-wide threat and architecture oversight
  • Decision history and evidence requirements
  • Access controls, onboarding and deployment planning
Discuss your organisation

Confirm enterprise capabilities, usage limits, identity requirements and commercial terms with ARKO.

DEPLOYMENT & DATA BOUNDARIES

Your operating requirements
shape the deployment.

Start with where your code, inference and evidence may run. Review the supported configuration with ARKO before committing to a rollout.

ARKO CLOUDYOUR ESTATE
ARKO analysisARKO cloud
Model inferenceARKO cloud
Control Plane + LedgerARKO cloud

Illustrative architecture boundary. Select a mode to compare; the supported configuration is agreed with ARKO.

Start with the managed service.

Connect supported tools and repositories to ARKO’s managed service. Agree organisation access, policies and the evidence your stakeholders need.

Discuss this deployment
ARKO PROCESSINGARKO-managed analysis services
MODEL INFERENCEManaged service configuration
CONTROL & EVIDENCEARKO-managed Control Plane

Discuss the right workspace and integration setup.

Findings and minimal snippets retained. Your full source is not retained after scanning, and your code is not used to train models. Read the processing details ↗

Connect your toolsFind the IDE, agent and organisation route that fits.

YOUR TOOLS, CONNECTED

Start where your team works.

IDE

Free IDE extension

Inspect findings and remediation guidance in the editor. Run an explicit first scan and configure available automation with your organisation.

Install the extension
MCP

Agent workflow

Give your coding agent access to ARKO tools. Source checks and dependency checks become part of the task.

Set up MCP
ENTERPRISE

Organisation oversight

Discuss repository and CI workflows, policy controls, access requirements and the deployment approach your organisation needs.

Plan your rollout

COMMON QUESTIONS

Know what you’re connecting.

Does ARKO replace our coding agent?
Your coding agent remains your builder. ARKO supplies separate checks and review context through the supported integrations.
Can we use the extension and MCP together?
Yes. The extension supports the editor experience, while MCP makes ARKO tools available to your agent. Follow the setup for each integration you choose.
Does every workflow automatically block a change?
Gate behaviour depends on the integration, available features and your configuration. Begin with an explicit scan, then agree the enforcement policy for your organisation.
What happens to our source code?
ARKO retains findings and minimal per-finding excerpts rather than your full source after the scan. See the published privacy policy and Trust Centre for the current processing details.
How do we start an enterprise rollout?
Book a conversation to map your editors, agents, repositories and pipelines. Define the first workflow, required policies, deployment needs and evidence your stakeholders need to see.

CORRECT BY DESIGN

Let your teams build.
Keep control of the outcome.

Start with one workflow. Bring its checks, policies and evidence into the organisation.

Example software inventory

This is sample data for the website demonstration.