Back to blog

Why we built Pragma Core

· · 5 min read
Why we built Pragma Core

AppSec teams have a math problem that nobody likes to talk about. Code volume has been climbing for years. Pentest budgets have not. Most companies still rely on a once-a-year engagement to validate the security posture of an application that ships, in some cases, a hundred times a day between those two engagements. Everyone in the industry knows this, and most of us have made peace with it because the alternatives are either too noisy or too expensive.

That gap is no longer something you can shrug off.

The velocity problem just changed shape

Two things happened in parallel over the last couple of years. Development cycles compressed again, with deployment frequency in mid-sized companies hitting numbers that used to belong only to the FAANG tier. And AI-assisted coding moved from a curiosity to default behavior. A senior engineer working with Cursor or Copilot can land features at a pace that would have been considered reckless five years ago, because, in a sense, it was.

The output is real, the productivity gains are real, but the security posture of that code is a different conversation. AI assistants will happily produce code that is functional, idiomatic, and quietly wrong from a security standpoint. They reproduce patterns from their training data, including the bad ones. They have no opinion about your authorization model. They do not know which endpoint is internet-facing.

We do not think this is a reason to slow down development. Most of our customers cannot, even if they wanted to. We think it is a reason to stop pretending that an annual pentest plus a noisy SAST scanner is a security program.

Why pure automation has a ceiling

Plenty of vendors will tell you their AI scanner solves the velocity problem. We have used most of them. Some are genuinely good at the surface-level findings. The honest assessment is that none of them, on their own, replaces an engineer who understands what the application actually does.

Automated tools are very good at pattern recognition. They are weak at intent. A scanner can flag that a function takes user input and reaches a database call. It cannot reliably tell you whether that path is exploitable in your specific authorization model, whether the surrounding business logic neutralizes the risk, or whether the finding is a duplicate of something you triaged six weeks ago and consciously accepted. Without that judgment, every scan produces a stack of tickets that nobody on the engineering side wants to triage, and trust in the tooling erodes.

This is the part where most platforms stop and hand the problem back to you.

Why pure human services have a different ceiling

The other side of the market is consultancies. Good ones do excellent work, and the offensive security industry in Romania has produced some of the best operators in Europe. We are part of that lineage. But a pentest is, by definition, a snapshot. It is comprehensive on the day it ends and progressively less accurate every week after. If you ship continuously, the value of the report decays faster than most procurement cycles allow you to refresh it.

Hiring a full-time AppSec team solves the freshness problem and creates two new ones: cost, and the difficulty of finding people who can actually do the work in a market where the talent pool is small and the demand is not.

The shape of the answer

Pragma Core is what happens when you stop treating those two ceilings as separate problems.

The platform connects to your repository, runs continuous agentic scans on every push, and does the unglamorous work of triaging findings against the rest of the codebase so that what reaches your tracker is filtered, contextualized, and worth a human looking at. That part is automated, because it has to be, and because the agents are good at it.

The other part is not automated. When a finding sits in a fragile area of the application, or touches business logic that automated tools struggle to reason about, you can hand that investigation to one of our AppSec engineers, who works inside the platform with the same telemetry your team sees. You get a real operator on the hard problems, without the overhead of a separate engagement. You get the speed of automation everywhere else.

That model is the reason we built the company. It is not a marketing line. We tried to do this work without it and concluded the math does not close any other way.

Who is behind this

Pragma Core is a partnership between two companies that, on their own, would have built half a product. One side brings offensive security, the kind of team that finds zero-days for a living and has spent years inside the harder corners of European red teaming. The other is Expertware, an IT and security consultancy that has been operating SOCs, vulnerability management programs, and multi-cloud environments since 2006. Neither of those skill sets, alone, builds a continuous AppSec platform that you would actually want to use. Together, they do.

What you will find on this blog

We are going to write about the things we work on, and the things we see. Expect technical breakdowns of vulnerabilities our agents and our engineers find, opinions about where AppSec tooling is going, and the occasional retrospective on what worked and what did not. We will not write filler, and we will not pretend to have answers we do not have.

If any of this resonates and you want to see what continuous AppSec looks like on your own codebase, the platform is live and you can connect a repository in a few minutes. If you would rather start with a conversation, we are happy to have one.

Related posts
CVE-2026-74820: how an unsanitized ORDER BY clause turned ServiceNow's AI Platform into an unauthenticated database backdoor
Sep 18, 2026
CVE-2026-85978: how one path normalization mismatch turned Akana's admin console into unauthenticated remote code execution
Sep 9, 2026
CVE-2026-78174: how an unredacted session token in a diagnostic log turned a low-privileged WatchGuard Dimension admin into super admin
Sep 1, 2026

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →