40° 42′ 46″ N   /   SECURITY ORBIT 01
BUILT FOR AZURE DEVOPS SECURITY OPERATIONS

Your AppSec stack.
Under control.

Kangl is the security control plane between Azure DevOps and the providers you trust—giving AppSec teams one operating model for posture, policy, pipelines, and audit.

01 Provider-neutral02 Backend-authoritative03 Tenant-isolated
LIVE OPERATING MODEL CONTROL PLANE ONLINE
Azure DevOps connected through Kangl to AppSec security providers
AZURE DEVOPSConnected
POLICY STATEAuthoritative
AZURE DEVOPS SECURITY PROVIDERS REPOSITORY POSTURE PIPELINE ENFORCEMENT POLICY & AUDIT

THE MISSING OPERATING LAYER

Your scanners find risk.
Kangl makes security operable.

Stop managing AppSec as a collection of vendor portals and pipeline-by-pipeline settings. Connect the estate once, normalize the signals, and control how security runs.

WHY KANGL

The problem is no longer detection.
It’s operational control.

Enterprise teams already own capable security tools. What they lack is one durable control layer across Azure DevOps, providers, repositories, policies, and pipelines.

01

Security tools multiply

Every provider brings another console, credential model, project map, and operating workflow.

02

Pipeline control drifts

Security configuration separates from the build pipelines it is meant to protect.

03

Posture loses context

Findings live with scanners while AppSec teams operate repositories, projects, and pipelines.

THE DEVSECOPS COMMAND CENTER

One screen.
The entire security operation.

See provider health, managed pipelines, normalized posture, policy decisions, tenant operations, and audit state without crossing six different tools.

Explore the platform →
platform.kangl / overviewSECURE SESSION
Kangl platform overview dashboard
24 Managed pipelines5 Connected providers128 Policy evaluations99.8% Sync health

A SINGLE OPERATING MODEL

Connect once.
Control continuously.

A clean separation between your delivery platform, the control plane, and the scanners doing the security work.

01

Connect

Azure DevOps

Organizations, projects, repositories, and eligible build pipelines.→
02

Orchestrate

Kangl

Provider configuration, normalized posture, policies, operations, and audit.→
03

Enforce

Security providers

Snyk today, with a provider-neutral ecosystem designed to expand.
Normalized postureCentral policyPipeline controlDurable audit

THE PLATFORM

Four systems.
One control plane.

Every capability is designed around the work AppSec and platform teams actually perform—not another disconnected security dashboard.

Security Providers

Connect and manage security platforms through a single provider-neutral control plane.

Repository Posture

Normalize security findings into fast, consistent repository-level posture.

Managed Pipelines

Enable, synchronize, and enforce controls across Azure DevOps build pipelines.

Policies & Audit

Apply backend-authoritative policy and retain durable operational history.

BRING YOUR SECURITY TOOLS

Provider choice
without operational chaos.

Kangl sits above your security providers. Scanners keep scanning. Kangl standardizes how teams connect, map, govern, synchronize, and enforce them across Azure DevOps.

Snyk is production supported today. Every other provider is clearly labeled as ecosystem / coming soon.
Explore the provider ecosystem →
PROVIDER CATALOG01 LIVE · 05 ROADMAP
SN

Snyk

Available Now
CH

Checkmarx One

Coming Soon
WI

Wiz

Coming Soon
GI

GitGuardian

Coming Soon
AI

Aikido Security

Coming Soon
SE

Semgrep

Coming Soon
AVAILABLE NOW

PIPELINE SECURITY RUNTIME

Run Snyk through one enterprise security runtime.

Connect Snyk once, map organizations, provision projects, configure Kangl Pipeline Security Runtime, and control eligible build pipelines without turning Kangl into another scanner.

  • Connection validation and organization mapping
  • Project audit, provisioning, and repair
  • Security Runtime configuration and global kill switch
  • Pipeline enable, disable, bulk control, and Force Sync
  • Vulnerability posture and service-connection synchronization
See Snyk Operations →
PIPELINE SECURITY RUNTIME ACTIVE
GLOBAL CONTROLSecurity Runtime
ConnectionValidated
OrganizationMapped
ProjectsProvisioned
Pipeline stateSynchronized

Provider validation completednow

Project audit synchronized2m

Runtime policy updated8m

KANGL PIPELINE SECURITY RUNTIME

Security policy,
where delivery happens.

Centralize eligibility, vulnerability posture, policy thresholds, Security Runtime state, bulk operations, drift repair, and Force Sync across YAML and classic build pipelines.

Classic release pipelines are not supported.

Kangl Pipeline Security Runtime controls
FAIL BUILD MONITOR ONLY RUNTIME ON NEEDS SYNC

FAST SECURITY POSTURE

Security posture without waiting on the scanner.

Provider APIs synchronize asynchronously. Kangl keeps a normalized repository read model ready for the operation—not one vendor call per row.

REPOSITORY POSTURE FRESH
2Critical5High12Medium8Low

BACKEND-AUTHORITATIVE POLICY

One policy layer above your scanners.

Evaluate thresholds centrally, make the pipeline decision authoritative, and retain the operational history behind every change.

THRESHOLDHIGH
BLOCKING FINDINGS7
DECISIONFAIL BUILD

SELF-OPERATING COVERAGE

Coverage that repairs itself.
Attention only when it must be you.

Provider estates drift: targets disappear, scans lag, re-runs collide. Kangl absorbs these as reconciliation work for the platform — your team sees attention items only when automation provably cannot proceed.

Guided setup, one run

A resumable server-side wizard takes the estate from discovery to protection — scope, ownership, provider mapping, classification, policy — with a deterministic preflight, one-click execution, and a completion state that stays put across reloads. Recovery reopens at the exact fix step, never a blank form.

Reconciliation before tickets

When a mapped provider target disappears, Kangl re-enrolls it automatically through the same canonical enrollment lifecycle it used the first time. No duplicate workflows, no phantom runs — and the customer is asked to act only with the exact missing prerequisite named.

Bounded convergence

Provider evidence arrives asynchronously. Initial assessments converge inside a bounded retry window and pause as retryable when it closes — slow scanners never turn into false failures, and nothing sits “running” forever.

Exact identity, zero drift

Discovery may use heuristics; operation never does. Once enrolled, every repository is operated by its exact provider organization and target identity — a similarly named resource is never silently substituted.

BUILT FOR ENTERPRISE SCALE

One platform.
Every security estate.

Centralized owner control without collapsing customer boundaries. Preserve tenant-specific configuration, provider isolation, Azure DevOps organization scope, and normalized posture.

MULTI-TENANT CONTROL PLANEISOLATED BY DESIGN
Kangl multi-tenant enterprise architecture
Tenant isolationProvider isolationCentral owner controlNormalized operations

ONE PLATFORM · THREE PERSPECTIVES

Everyone sees the same security operation.

01 / APPSEC

Govern posture and policy across the estate.

See what is protected, what blocks, what drifted, and what needs attention.

02 / PLATFORM

Control pipelines without repetitive configuration.

Coordinate provisioning, Security Runtime state, synchronization, and bulk operations.

03 / SECURITY OPS

Trace every provider and policy operation.

Work from durable operational history instead of disconnected vendor events.

FREQUENTLY ASKED

Straight answers.

Is Kangl a code security scanner?

No — and deliberately so. Kangl performs no scanning of any kind. It is the control plane that operates scanners like Snyk across your Azure DevOps estate: coverage, policy, drift repair, and audit.

Does Kangl replace Snyk, Aikido, or Checkmarx?

Never. Those are the engines Kangl amplifies. Your scanner keeps detecting; Kangl makes sure it runs on every eligible pipeline, under one policy, with evidence to show for it.

Which platforms does Kangl support?

Kangl goes deep on Azure DevOps: YAML and classic build pipelines, Pipeline Security Runtime, PR branch policies, service connections, and variable groups. Depth over breadth is a deliberate choice.

How does enforcement actually work?

Kangl Pipeline Security Runtime applies security controls during pipeline execution while PR checks protect the merge path. Findings are normalized into posture; a backend policy engine issues the verdict — fail the build or monitor — and every decision is audited.

Is Kangl multi-tenant?

Yes, by architecture: tenant-partitioned data under row-level security in the database, per-tenant provider credentials, and a separate owner console for platform operations.

What happens when a provider repository target disappears?

Kangl treats canonical identity loss as a reconciliation event first. If the source repository is alive, the connection healthy, and the provider organization authority intact, the repository re-enters the normal enrollment lifecycle automatically. You are asked to act only when automation provably cannot proceed — and then the reason is exact: repair the connection, restore the organization, or choose a mapping.

Can two workspaces fight over one Azure DevOps organization?

No. Azure configuration writes require an explicit control claim, and exactly one Kangl workspace can hold it per organization. Every other workspace runs observe-only — it can validate, sync, and read posture, but never change Azure configuration — and migration readiness makes cutover between workspaces explicit.

How do we get started?

Choose a plan to start a seven-day trial with a payment method, or book a demo to discuss your Azure DevOps estate. Provider operations remain subject to their supported capabilities and qualification.

SECURITY OPERATIONS, UNIFIED

Bring your security tools.
Kangl makes them one platform.

Start with seven days of full plan access — or see it live with our team first.