Solutions
Security work starts with a team and a decision.
Choose the workflow that matches what you are responsible for: a code change, an application portfolio, a device release or a firmware update. Each solution explains the inputs, review process and deliverables.
Code Security · and combined product review
Software and application security
Keep source analysis in the delivery workflow and give security teams a usable view across participating repositories.
Application and platform engineering
Give developers feedback while the repository is still in front of them, then use the same analysis in CI. Code Security helps application and platform teams review source, dependency and configuration changes without making a source upload the prerequisite for a scan.
Scenario: A pull request changes an API and its deployment configuration
Read the workflowEnterprise security programmes
Security leaders need to know which services need attention, who can act and whether the evidence is current. Code Security brings uploaded findings and inventories into an application-centred review, with SLA policy and governance records that help coordinate remediation.
Scenario: A newly relevant advisory affects a shared dependency
Read the workflowProduct security and AppSec
Product security and AppSec teams connect technical findings to release decisions. Magdox supports that work in two product workflows: source and application review in Code Security, and firmware and release evidence in FDIE. Each keeps the available evidence and assessment scope close to the review.
Scenario: A release owner asks whether an unresolved finding blocks shipment
Read the workflowFDIE
Firmware, devices and technical assessment
Investigate what is inside an image, compare releases and produce evidence for the people who own the product.
Firmware and connected devices
Connected-device manufacturers inherit components from operating systems, vendors and internal teams. FDIE helps identify what can be recovered from a release image, investigate relevant vulnerabilities and compare the evidence when the next firmware version is ready.
Scenario: A supplier delivers an updated image with a claimed security fix
Read the workflowIndustrial, EV and energy systems
Industrial gateways, controllers and charging infrastructure can remain in service across several maintained firmware branches. FDIE helps engineering teams investigate recognised components, candidate vulnerabilities and release changes while keeping operational and safety decisions with the responsible product owners.
Scenario: A common library needs attention across maintained device releases
Read the workflowConnected buildings and consumer devices
Cameras, locks, sensors, gateways and building controllers often reuse vendor platforms and libraries. FDIE helps teams review those components and the firmware changes that affect them, then retain evidence for the people responsible for the next device release.
Scenario: A shared vendor SDK appears in several connected products
Read the workflowPlan the first evaluation
Choose a representative input and a useful result.
| Team | Bring | Check the result with |
|---|---|---|
| Application engineering | A known repository and a recent security-relevant change | The engineers and CI owners who will act on the finding |
| Enterprise security | Several repositories belonging to one service | The application owner and the team setting remediation policy |
| Device engineering | An authorised firmware image and a related release | The product engineers who understand the components and update |
Product capabilities, deployment and commercial terms are separate parts of the decision. Review the product pages for analysis scope, the plans for resources and features, and the security centre for data handling.