Visiminds Technologies, home

Two security products

The code you build and the systems you run

Ivy Lens checks the code you build. Ivy Insight checks the systems you run. They complement each other.

For development teams, security teams and compliance teams.

Two named cards: Ivy Lens checks code, packages and app builds on every build, Ivy Insight checks hosts, cloud accounts and web applications as often as you like, and both write findings the same way on one severity scale

Two things to keep safe, one product for each

A team has two things to keep safe: the code it builds, and the systems it runs. Visiminds makes one product for each.

The code you build. Ivy Lens can check it on every build, from the command line with a pass or fail gate.

  • Your own code, and the packages it uses
  • Passwords and keys left in files
  • Server and cloud setup files
  • Android and iOS apps, even without source code

The systems you run. Ivy Insight checks them as often as you like, before and after a release.

  • What is open to the internet
  • Websites, APIs (Application programming interface. The interface one program uses to talk to another.) and databases
  • Servers and networks
  • Cloud accounts and AI applications
Two columns, what you build and what you run: source code, packages and the app build are checked on every build, and hosts, web applications and cloud accounts are checked as often as you like, across a timeline of releases, on one severity scale

Using both

Where the two meet

The same kind of weakness can show up in both places. Each product finds it in a different way.

A weakness in your own code

Ivy Lens
Found in the code, before it ships
Ivy Insight
Found on the running system, if it can be reached

A package with a known vulnerability

Ivy Lens
Found in the package list in your code
Ivy Insight
Found in a running service, by checks for published vulnerabilities

A misconfigured server or cloud account

Ivy Lens
Found in the setup files, before deployment
Ivy Insight
Found on the running system, with Visiminds' own checks for part of the CIS Linux benchmark (Free lists of secure settings for each kind of system, from the Center for Internet Security.)

A password or key

Ivy Lens
Found in the files in the repository
Ivy Insight
Found when it is served to the public

Built on the same four choices

Four choices made once, for both products.

Runs where you choose

On your own hardware, even with no internet connection. Ivy Insight can also run as a service.

Nothing leaves unless you say so

Your code, and the data about your systems, go only where you tell them. Attack surface discovery looks up your domain name in public sources.

Clear about coverage

Both show what they covered and what they left out, and why.

Licensed by use, not by seat

Credits (The units a scan is paid with. You pay for the scans you run, not for each user.) for what you scan, from a balance you can see.

Two reports, the same terms

Findings written the same way

Findings from code and from running systems written the same way: one severity scale of five levels, the weakness class, the evidence, and the change to make

How a finding is written

Each product writes its own report. Both use the same severities, weakness classes and layout, so one team can read both, and compare them.

Rules, reports and mappings to standards can be adapted to your needs, and to the regulations of your country or region.

  • Severity: critical, high, medium, low or info
  • Weakness class: its weakness type (CWE (Common Weakness Enumeration. The common list of software weakness types.))
  • Evidence: what shows it is real
  • What to change: the fix, in plain words
Two separate reports laid beside each other, one for code and app builds and one for the running estate, read on one severity scale

Two reports, read on one scale

The report on your code and app builds, and the report on your running systems, sit side by side. A critical finding means the same in both.

What the 2026 reports say

Many breaches start with an exploited weakness, and these weaknesses take a long time to fix.

31%of the breaches studied began with an exploited weakness, more than any other way inVerizon 2026 Data Breach Investigations Report
43 daysthe median (The middle value. Half of the values are above it, and half are below it.) time to fully fix a weakness that attackers were already using (on CISA's (Cybersecurity and Infrastructure Security Agency. The cybersecurity agency of the United States. It publishes the list of known exploited vulnerabilities.) Known Exploited Vulnerabilities (Known Exploited Vulnerabilities. CISA's list of vulnerabilities that attackers are known to have used.) list), up from 32 days the year beforeVerizon 2026 Data Breach Investigations Report
247 daysthe average time to find and contain a breachIBM Cost of a Data Breach Report 2026

Weaknesses like these can be found in two places: in the code, on every build, and in the systems it runs on, at any time. Ivy Lens checks the first. Ivy Insight checks the second.

Where to start

Start with what is due first

Add the other product when you are ready.

A release is coming

Start with Ivy Lens. It runs on your own computer, and checks the code before it ships.

An auditor or a customer asks for a report on your systems

Start with Ivy Insight. It can run fully inside your network, and it puts a deadline on every finding.

Ask for a demo of either product, or both

Write to info@visiminds.com. We will show you Ivy Lens, Ivy Insight, or the two side by side.