Sovereign continuous code monitoring platform · Designed and operated in Luxembourg
Your code under permanent watch. Secured, tested, compliant.
LuxGap DevOps connects to your repository in read-only mode and analyses your software continuously: vibe coding control, code security, application pentesting and automated testing, with NIS2, DORA, GDPR and AI Act compliance evidence. From €0.01 excl. VAT per line of code per month.
AI-generated code arrives faster than your capacity to review it
Code assistants have multiplied software production, not review. Vibe coding ships features in a few hours, but it also introduces plain-text secrets, vulnerable dependencies, injections and deviations from your governance rules, with nobody seeing them go by.
On the code LuxGap takes over from its clients, the observed compliance rate with security and quality rules is 10 to 20%, while we require 90 to 100% from our own developers. Meanwhile, NIS2 and DORA make executives personally accountable for the security of their systems, and the AI Act requires documenting the use of artificial intelligence.
LuxGap DevOps puts your software under permanent analysis, flags every deviation in real time and produces the evidence your auditors, your board and your regulator expect.
10 to 20%
observed compliance on code taken over by LuxGap
90 to 100%
compliance required of LuxGap developers
€0.01
per line of code per month, all inclusive
Features
Four disciplines, one subscription
Every module works on the same connection and feeds the same portal. There is nothing to install in your code.
Control vibe coding
Take back control of AI-generated code
The platform spots code produced by AI assistants and not reviewed by a human, checks it against your development rules and flags every drift: a secret introduced by the assistant, a dubious dependency, an incompatible licence, a gap between what your governance says and what your code does.
Detection of AI-generated code without human reviewTraceability: which file, which author, which assistant, which dateMandatory review rules and alerts on any deviationEvidence ready for your AI Act obligations
To review — AI-generated code without human review — PaymentService.tsRequest a review
Secure the code
Expert code review, in real time, on every commit
SQL injections, plain-text secrets and keys, known vulnerabilities (CVE) in your dependencies, dangerous configurations, OWASP non-conformities: every finding is ranked by severity, comes with the recommended fix and is tracked until closure.
Real-time findings, ranked critical, major, minorOWASP framework and technical quality controlsRecommended fix on every findingClosure tracking and full history
3 critical · 12 major · 41 minorAverage time to closure: 2 d
Pentest the application
Attack your application before others do
Automated application penetration tests run continuously against your deployed application and replay real attack techniques. Results land in the same portal as your code findings, with a report your teams can act on. LuxGap’s penetration-testing experts can complement this with a manual pentest.
Automated, recurring application penetration testsVulnerability report ranked by severity, with proof of exploitationManual pentest by LuxGap experts as an optionResults correlated with code findings
Application pentest: 0 exploitable vulnerabilities · last campaign: yesterday
Test automatically
An AI robot that uses your application like your users
An AI-driven robot replays your business journeys (login, data entry, payment, export) and detects regressions before your customers do. Results from your own pipelines are aggregated in the same place.
User journeys replayed automatically, on every releaseAggregation of JUnit, SARIF, code coverage and k6 resultsAlerts on regression or performance degradationA single dashboard for quality, security and compliance
Payment journey — Passed 14 min ago — 27 steps
Compliance
Compliance by evidence, not by declaration
An auditor is no longer satisfied with a signed policy. They want to see that the code does what governance promises. LuxGap DevOps demonstrates it continuously.
Evidence repository
Every control produces a timestamped piece of evidence, retained and exportable for your auditors, your DPO, your CISO or your regulator.
NIS2 and ISO 27001 roadmap
The platform generates and tracks your compliance roadmap and highlights the gaps between governance and code.
Compliance watermark
A single indicator correlates governance, code and infrastructure. Visible to management, it tells you where you stand in one figure.
Auditor access
A dedicated, read-only account for your auditor, your DPO or your CISO. No more manual extraction before every audit.
NIS2DORAGDPRAI ActISO 27001OWASPCSSF circulars
GovernanceCodeInfrastructure87 %Watermark
How it works
Connected read-only, analysed at LuxGap, never exposed
01
You open read-only access
You give LuxGap read-only access to your forge (GitHub, GitLab or Azure DevOps), to your databases and, if you wish, to your server. No write access, nothing to install in your code.
02
The engine analyses continuously, off the Internet
Analysis runs on LuxGap’s infrastructure in Luxembourg, with no Internet exposure. The devops.luxgap.com portal is only a secure mirror of the results.
03
You receive findings in real time
Every finding arrives ranked by severity with its recommended fix. The test robot replays your journeys and the application pentest runs against your deployed application.
04
Your evidence accumulates by itself
The evidence repository fills automatically, the compliance watermark updates and your auditor accesses it whenever they wish.
The number of lines of code is counted automatically at connection and remains visible in your portal: you always know exactly what you are paying for.
Sovereignty
Your code never leaves the perimeter
Source code is a company’s most exposed trade secret. LuxGap DevOps was designed so that it never leaves: processing on our infrastructure in Luxembourg, no transfer to an external AI model by default, contracts under Luxembourg law, team based in Luxembourg.
Hosted in LuxembourgContracts under Luxembourg lawLawyers, cybersecurity engineers and developers under one roof
Stays within the perimeter
Your code, your databases, your detected secretsYour evidence and your reports
Never leaves by default
Nothing to a third-party AI providerNothing outside the European Union
On explicit request only
The external-AI analysis option. The code then leaves the perimeter and the model’s publisher may retain it. Our experience: it rarely brings additional findings, and we say so.
Interoperability
Fits your existing stack, whatever your language
Forges
GitHub, GitLab (cloud or self-hosted), Azure DevOps. Read-only connection, no agent in your pipelines.
Databases
Read-only connection to verify that code and schema tell the same story: secrets, personal data, access.
Servers
Optional connection of your server to correlate code, configuration and infrastructure in the compliance watermark.
CI/CD pipelines
Import and aggregation of your existing results: JUnit, SARIF, code coverage, k6. You keep your tools, you gain a single view.
LuxGap SOC 24/7
Optionally, critical alerts escalate to LuxGap’s managed SOC, with follow-up by our team.
All languages
From COBOL to TypeScript, from SQL to Python: the analysis does not depend on the language or the framework.
Pricing
One price per line of code. Nothing else.
No per-user licence, no surcharge per repository or per pipeline. You pay for the code surface we monitor, and you see it in your portal.
€0.01 excl. VAT
per line of code per month
Minimum billing €250 excl. VAT per month, i.e. up to 25,000 lines of code included12-month minimum commitment, monthly billingAll languages, all forges, users and repositories at no extra cost
Included in the subscription
Vibe coding controlCode security and real-time reviewAutomated application pentestingAI-robot automated testing and CI/CD aggregationCompliance: evidence repository, NIS2 and ISO 27001 roadmap, watermark, auditor accessSecure devops.luxgap.com portal and alertsReply within 24 h from the LuxGap team
Built for organisations that cannot afford mistakes
Financial institutions
Banks, insurers, PSF and managers subject to the CSSF and DORA: prove control of your critical applications and your ICT providers.
Healthcare and public sector
Hospitals, laboratories, administrations and bodies subject to NIS2: monitor the code that processes sensitive data, with the associated evidence.
Companies outsourcing development
You cannot see what is delivered? LuxGap DevOps gives you back control: real quality level, vulnerabilities, dependencies, and the evidence to renegotiate.
Software vendors, IT firms and teams using AI assistants
Keep the speed of vibe coding without suffering its risks: every generated line is spotted, reviewed and documented.
Monitoring the code is the beginning. The LuxGap group does the rest.
Sovereign hosting, backup, secrets vault, legal compliance of your website and multi-site distribution for ultra-high availability: a single Luxembourg team — LuxGap, LuxApps and LuxOps — takes charge of your application’s full lifecycle.
The source-code lines of the software you place under permanent analysis. The count is performed automatically when your repository is connected, then remains permanently visible in your portal. You always know exactly what you are paying for.
Do you need write access to my repository?
No. LuxGap DevOps works exclusively in read-only mode on your forge, your databases and, if you wish, your server. We never modify your code and we install nothing in your pipelines.
Is my code sent to an external artificial intelligence?
Never by default. Analysis runs on LuxGap’s infrastructure in Luxembourg, with no Internet exposure. External-AI analysis exists only as an option, on explicit request and billed per analysis; we then warn you that the code leaves the perimeter.
Which languages and forges are supported?
All languages. The GitHub, GitLab (cloud or self-hosted) and Azure DevOps forges are connected in read-only mode. Results from your existing pipelines (JUnit, SARIF, code coverage, k6) are aggregated in the portal.
What happens when a critical finding is detected?
It appears immediately in your portal, ranked critical, with the recommended fix, and an alert is sent to your contacts. Optionally, critical alerts escalate to LuxGap’s 24/7 managed SOC with follow-up by our team.
How does subscribing work?
You fill in the subscription request at the bottom of this page. LuxGap replies within 24 h with a firm quote and the subscription contract (12-month commitment). Once the contract is signed, we organise with you the opening of read-only access and the connection.
Can I monitor several applications?
Yes. The price is the sum of the lines of code of all monitored applications, at €0.01 excl. VAT per line per month, with a minimum billing of €250 excl. VAT per month for the whole.
Does this help me with NIS2, DORA, GDPR or the AI Act?
Yes. The platform generates and tracks your NIS2 and ISO 27001 roadmap, files a timestamped piece of evidence for every control, correlates governance, code and infrastructure in a compliance watermark and spots AI-generated code to document under the AI Act. Your auditor has dedicated read-only access.
Does the automated pentest replace my annual penetration test?
It complements it continuously: attack techniques are replayed automatically against your deployed application, between two manual tests. LuxGap’s penetration-testing experts perform the manual pentest as an option.
Where is my data hosted?
On the LuxGap group’s infrastructure in Luxembourg. Nothing leaves the European Union, and the analysis engine is not exposed to the Internet.
What is the commitment?
12 months minimum, with monthly billing. The minimum billing is €250 excl. VAT per month.
Can I give access to my auditor, my DPO or my external CISO?
Yes, a read-only auditor account is included. They consult the evidence, the reports and the compliance watermark without going through you.
Subscription
Request a subscription
No online payment. You describe your software, LuxGap replies within 24 h with a firm quote and the subscription contract.
Only the email address is required. Everything else helps us prepare a firm quote — you can fill it in later.
The submission failed. Try again in a moment or write to us directly at julien.winkin@luxgap.com.
Request sent, thank you.
The LuxGap team will reply within 24 h to the address provided, with a firm quote and the subscription contract. In the meantime, you can prepare the list of repositories to connect and your technical contact.