Skip to content
LuxGap LuxGap DevOps
Client login Request a subscription

Sovereign continuous code monitoring platform · Designed and operated in Luxembourg

Your code under permanent watch. Secured, tested, compliant.

LuxGap DevOps connects to your repository in read-only mode and analyses your software continuously: vibe coding control, code security, application pentesting and automated testing, with NIS2, DORA, GDPR and AI Act compliance evidence. From €0.01 excl. VAT per line of code per month.

Request a subscription Calculate my price
No write access to your code Processed at LuxGap, never exposed to the Internet All languages, all forges Reply within 24 h
devops.luxgap.com — client portal
FindingsComplianceTestsPentestEvidenceAuditor

42,318

lines of code under analysis

87 %

NIS2 compliance watermark

3 critical · 12 major

open findings

Passed 14 min ago

latest test-robot journey

Findings in real time

API secret in plain text — src/config/settings.py, line 426 min ago
Possible SQL injection — OrdersRepository.cs21 min ago
Vulnerable dependency (published CVE) — package.json1 h ago
AI-generated code without human review — PaymentService.ts2 h ago
Evidence filed: OWASP A03 control 3 h ago
Application pentest: 0 exploitable vulnerabilities · last campaign: yesterday
Works with GitHubGitLab (cloud or self-hosted)Azure DevOpsDatabasesServersAll languages
Frameworks covered NIS2DORAGDPRAI ActISO 27001OWASPCSSF circulars

The problem

AI-generated code arrives faster than your capacity to review it

Code assistants have multiplied software production, not review. Vibe coding ships features in a few hours, but it also introduces plain-text secrets, vulnerable dependencies, injections and deviations from your governance rules, with nobody seeing them go by.

On the code LuxGap takes over from its clients, the observed compliance rate with security and quality rules is 10 to 20%, while we require 90 to 100% from our own developers. Meanwhile, NIS2 and DORA make executives personally accountable for the security of their systems, and the AI Act requires documenting the use of artificial intelligence.

LuxGap DevOps puts your software under permanent analysis, flags every deviation in real time and produces the evidence your auditors, your board and your regulator expect.

10 to 20%

observed compliance on code taken over by LuxGap

90 to 100%

compliance required of LuxGap developers

€0.01

per line of code per month, all inclusive

Features

Four disciplines, one subscription

Every module works on the same connection and feeds the same portal. There is nothing to install in your code.

Control vibe coding

Take back control of AI-generated code

The platform spots code produced by AI assistants and not reviewed by a human, checks it against your development rules and flags every drift: a secret introduced by the assistant, a dubious dependency, an incompatible licence, a gap between what your governance says and what your code does.

Detection of AI-generated code without human reviewTraceability: which file, which author, which assistant, which dateMandatory review rules and alerts on any deviationEvidence ready for your AI Act obligations
To review — AI-generated code without human review — PaymentService.tsRequest a review

Secure the code

Expert code review, in real time, on every commit

SQL injections, plain-text secrets and keys, known vulnerabilities (CVE) in your dependencies, dangerous configurations, OWASP non-conformities: every finding is ranked by severity, comes with the recommended fix and is tracked until closure.

Real-time findings, ranked critical, major, minorOWASP framework and technical quality controlsRecommended fix on every findingClosure tracking and full history
3 critical · 12 major · 41 minorAverage time to closure: 2 d

Pentest the application

Attack your application before others do

Automated application penetration tests run continuously against your deployed application and replay real attack techniques. Results land in the same portal as your code findings, with a report your teams can act on. LuxGap’s penetration-testing experts can complement this with a manual pentest.

Automated, recurring application penetration testsVulnerability report ranked by severity, with proof of exploitationManual pentest by LuxGap experts as an optionResults correlated with code findings
Application pentest: 0 exploitable vulnerabilities · last campaign: yesterday

Test automatically

An AI robot that uses your application like your users

An AI-driven robot replays your business journeys (login, data entry, payment, export) and detects regressions before your customers do. Results from your own pipelines are aggregated in the same place.

User journeys replayed automatically, on every releaseAggregation of JUnit, SARIF, code coverage and k6 resultsAlerts on regression or performance degradationA single dashboard for quality, security and compliance
Payment journey — Passed 14 min ago — 27 steps

Compliance

Compliance by evidence, not by declaration

An auditor is no longer satisfied with a signed policy. They want to see that the code does what governance promises. LuxGap DevOps demonstrates it continuously.

Evidence repository

Every control produces a timestamped piece of evidence, retained and exportable for your auditors, your DPO, your CISO or your regulator.

NIS2 and ISO 27001 roadmap

The platform generates and tracks your compliance roadmap and highlights the gaps between governance and code.

Compliance watermark

A single indicator correlates governance, code and infrastructure. Visible to management, it tells you where you stand in one figure.

Auditor access

A dedicated, read-only account for your auditor, your DPO or your CISO. No more manual extraction before every audit.

NIS2DORAGDPRAI ActISO 27001OWASPCSSF circulars
Governance Code Infrastructure 87 %Watermark

How it works

Connected read-only, analysed at LuxGap, never exposed

01

You open read-only access

You give LuxGap read-only access to your forge (GitHub, GitLab or Azure DevOps), to your databases and, if you wish, to your server. No write access, nothing to install in your code.

02

The engine analyses continuously, off the Internet

Analysis runs on LuxGap’s infrastructure in Luxembourg, with no Internet exposure. The devops.luxgap.com portal is only a secure mirror of the results.

03

You receive findings in real time

Every finding arrives ranked by severity with its recommended fix. The test robot replays your journeys and the application pentest runs against your deployed application.

04

Your evidence accumulates by itself

The evidence repository fills automatically, the compliance watermark updates and your auditor accesses it whenever they wish.

The number of lines of code is counted automatically at connection and remains visible in your portal: you always know exactly what you are paying for.

Sovereignty

Your code never leaves the perimeter

Source code is a company’s most exposed trade secret. LuxGap DevOps was designed so that it never leaves: processing on our infrastructure in Luxembourg, no transfer to an external AI model by default, contracts under Luxembourg law, team based in Luxembourg.

Hosted in LuxembourgContracts under Luxembourg lawLawyers, cybersecurity engineers and developers under one roof

Stays within the perimeter

Your code, your databases, your detected secretsYour evidence and your reports

Never leaves by default

Nothing to a third-party AI providerNothing outside the European Union

On explicit request only

The external-AI analysis option. The code then leaves the perimeter and the model’s publisher may retain it. Our experience: it rarely brings additional findings, and we say so.

Interoperability

Fits your existing stack, whatever your language

Forges

GitHub, GitLab (cloud or self-hosted), Azure DevOps. Read-only connection, no agent in your pipelines.

Databases

Read-only connection to verify that code and schema tell the same story: secrets, personal data, access.

Servers

Optional connection of your server to correlate code, configuration and infrastructure in the compliance watermark.

CI/CD pipelines

Import and aggregation of your existing results: JUnit, SARIF, code coverage, k6. You keep your tools, you gain a single view.

LuxGap SOC 24/7

Optionally, critical alerts escalate to LuxGap’s managed SOC, with follow-up by our team.

All languages

From COBOL to TypeScript, from SQL to Python: the analysis does not depend on the language or the framework.

Pricing

One price per line of code. Nothing else.

No per-user licence, no surcharge per repository or per pipeline. You pay for the code surface we monitor, and you see it in your portal.

€0.01 excl. VAT

per line of code per month

Minimum billing €250 excl. VAT per month, i.e. up to 25,000 lines of code included12-month minimum commitment, monthly billingAll languages, all forges, users and repositories at no extra cost

Included in the subscription

Vibe coding controlCode security and real-time reviewAutomated application pentestingAI-robot automated testing and CI/CD aggregationCompliance: evidence repository, NIS2 and ISO 27001 roadmap, watermark, auditor accessSecure devops.luxgap.com portal and alertsReply within 24 h from the LuxGap team

Estimate your price

25,000 lines = €250 · 50,000 lines = €500 · 120,000 lines = €1,200 · 300,000 lines = €3,000

€250 excl. VAT / month

i.e. €3,000 excl. VAT over the 12-month commitment

Indicative estimate. The exact count is performed at connection and remains visible in your portal.

Code and database backup

On quote

A copy uploaded every day to a LuxGap server in Luxembourg.

Secrets vault

On quote

A Vaultwarden vault hosted behind VPN, with no Internet access, to get secrets out of your code for good.

Multi-site distribution

On quote

Load balancing and failover across three sites: Luxembourg, France, Germany.

Sovereign hosting

On quote

Hosting of your application on the group’s infrastructure in Luxembourg, with recovery in Germany.

Manual pentest

On quote

Manual penetration testing by LuxGap experts, complementing the automated pentest.

External-AI analysis

from €100 excl. VAT / analysis

On explicit request only. The code leaves the perimeter: we advise against it unless specifically required.

Discover the group’s services: hosting, backup, secrets, compliance, multi-site

Who it is for

Built for organisations that cannot afford mistakes

Financial institutions

Banks, insurers, PSF and managers subject to the CSSF and DORA: prove control of your critical applications and your ICT providers.

Healthcare and public sector

Hospitals, laboratories, administrations and bodies subject to NIS2: monitor the code that processes sensitive data, with the associated evidence.

Companies outsourcing development

You cannot see what is delivered? LuxGap DevOps gives you back control: real quality level, vulnerabilities, dependencies, and the evidence to renegotiate.

Software vendors, IT firms and teams using AI assistants

Keep the speed of vibe coding without suffering its risks: every generated line is spotted, reviewed and documented.

Monitoring the code is the beginning. The LuxGap group does the rest.

Sovereign hosting, backup, secrets vault, legal compliance of your website and multi-site distribution for ultra-high availability: a single Luxembourg team — LuxGap, LuxApps and LuxOps — takes charge of your application’s full lifecycle.

Discover the group’s services

Frequently asked questions

Everything you want to know before subscribing

What exactly do you count as a “line of code”?

The source-code lines of the software you place under permanent analysis. The count is performed automatically when your repository is connected, then remains permanently visible in your portal. You always know exactly what you are paying for.

Do you need write access to my repository?

No. LuxGap DevOps works exclusively in read-only mode on your forge, your databases and, if you wish, your server. We never modify your code and we install nothing in your pipelines.

Is my code sent to an external artificial intelligence?

Never by default. Analysis runs on LuxGap’s infrastructure in Luxembourg, with no Internet exposure. External-AI analysis exists only as an option, on explicit request and billed per analysis; we then warn you that the code leaves the perimeter.

Which languages and forges are supported?

All languages. The GitHub, GitLab (cloud or self-hosted) and Azure DevOps forges are connected in read-only mode. Results from your existing pipelines (JUnit, SARIF, code coverage, k6) are aggregated in the portal.

What happens when a critical finding is detected?

It appears immediately in your portal, ranked critical, with the recommended fix, and an alert is sent to your contacts. Optionally, critical alerts escalate to LuxGap’s 24/7 managed SOC with follow-up by our team.

How does subscribing work?

You fill in the subscription request at the bottom of this page. LuxGap replies within 24 h with a firm quote and the subscription contract (12-month commitment). Once the contract is signed, we organise with you the opening of read-only access and the connection.

Can I monitor several applications?

Yes. The price is the sum of the lines of code of all monitored applications, at €0.01 excl. VAT per line per month, with a minimum billing of €250 excl. VAT per month for the whole.

Does this help me with NIS2, DORA, GDPR or the AI Act?

Yes. The platform generates and tracks your NIS2 and ISO 27001 roadmap, files a timestamped piece of evidence for every control, correlates governance, code and infrastructure in a compliance watermark and spots AI-generated code to document under the AI Act. Your auditor has dedicated read-only access.

Does the automated pentest replace my annual penetration test?

It complements it continuously: attack techniques are replayed automatically against your deployed application, between two manual tests. LuxGap’s penetration-testing experts perform the manual pentest as an option.

Where is my data hosted?

On the LuxGap group’s infrastructure in Luxembourg. Nothing leaves the European Union, and the analysis engine is not exposed to the Internet.

What is the commitment?

12 months minimum, with monthly billing. The minimum billing is €250 excl. VAT per month.

Can I give access to my auditor, my DPO or my external CISO?

Yes, a read-only auditor account is included. They consult the evidence, the reports and the compliance watermark without going through you.

Subscription

Request a subscription

No online payment. You describe your software, LuxGap replies within 24 h with a firm quote and the subscription contract.

Only the email address is required. Everything else helps us prepare a firm quote — you can fill it in later.

Forge used

An estimate is enough, the exact count is done at connection. A small business application is often 20,000 to 25,000 lines.

Is the software developed by an external provider?
Desired options — several choices possible

By submitting this form, you agree that Lux Gap S.à r.l. processes this data to answer your request. It is never shared with third parties and is kept only as long as needed. Privacy policy.