Every capability in Kangl traces back to one observation: enterprises do not fail at detecting vulnerabilities; they fail at operating detection. The scanners work. What breaks is everything around them — coverage, configuration, policy, credentials, and evidence — multiplied across hundreds of pipelines and every tool in the stack.
This post lays out the reasoning in one place: why a control plane, why Azure DevOps first, and why we deliberately do not scan.
The gap nobody owns
Scanner vendors own detection quality. Platform teams own pipeline throughput. Between them sits unowned work: which pipelines run which security steps, under what policy, with what credentials, recorded where. In most organizations that gap is filled by scripts, spreadsheets, and one overloaded engineer — infrastructure by accident.
Why a control plane, specifically
- Operating problems need state: inventory, enrollment, policy, and history — not another dashboard over someone else's API.
- Enforcement needs authority: decisions computed in a backend and projected to pipelines and PRs, not toggles scattered across surfaces.
- Estates need reconciliation: drift detected and repaired continuously, like modern infrastructure.
- Enterprises need boundaries: tenant isolation and owner control that hold in the data layer.
Why Azure DevOps first
Depth beats breadth in operational tooling. Azure DevOps has powerful branch policies, service connections, and pipeline execution primitives — and enormous enterprise estates, but the thinnest ecosystem of operating tools. Kangl goes deep there: real Pipeline Security Runtime control, real drift repair, and real PR enforcement mechanics rather than a shallow integration with everything.
Why we do not scan
The moment a control plane ships its own scanner, its neutrality dies and its incentives shift to competing with the tools it should operate. Kangl stays the layer above: Snyk production-supported today, a provider contract designed for the ecosystem, and every scanner treated as an engine to be operated — not replaced.

