EveryDev.ai
Subscribe
Home
Developers

3,241+ AI companies

  • Radar
  • Trending
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Developers
    3. Railo

    Railo

    Railo is a GitHub-native security-remediation platform that scans pull requests for supported vulnerabilities and opens deterministic, reviewable fix pull requests with verification evidence. Its stated goal is to clear security backlogs without asking developers to merge AI-generated patches on faith.

    Visit Website

    At a Glance

    1Tool Listed
    2Products
    12Capabilities
    Discussions
    Dhaka, BangladeshHeadquarters
    2026Est.
    2Employees
    Focus Areas
    Code Security
    Bug Detection
    Code Review
    Connect
    Latest News
    Railo launched on GitHub Marketplace as Railo Dev, offering deterministic pull-request security fixes and verification evidence.Jan 1, 2026
    Zarif Latif published “Introducing Railo: The Security Bot That Fixes Your Code, Not Just Finds Problems,” describing the product's rule-based remediation, supported vulnerability types and languages, and GitHub Action workflow.Jan 1, 2026
    Markets
    • Small and medium-sized software teams
    • B2B SaaS companies using Python
    • Organizations with application-security backlogs
    • Enterprise engineering and security teams needing audit evidence and policy controls
    • +1 more

    AI Tools by Railo

    (1)
    View Railo
    Railo tool icon

    Railo

    AI Security Scanner for GitHub

    Code SecurityBug DetectionCode Review

    Discussions

    No discussions yet

    Be the first to start a discussion about Railo

    Latest News

    01/01/2026

    Railo launched on GitHub Marketplace as Railo Dev, offering deterministic pull-request security fixes and verification evidence.

    github.com
    01/01/2026

    Zarif Latif published “Introducing Railo: The Security Bot That Fixes Your Code, Not Just Finds Problems,” describing the product's rule-based remediation, supported vulnerability types and languages, and GitHub Action workflow.

    medium.com
    01/01/2026

    Railo published its measured remediation result: 68% SSRF clearance, representing 248 of 363 CWE-918 findings across 22 repositories and 21,768 findings.

    railo.dev
    08/01/2026

    Railo published updated privacy, security/data-handling, and service-level materials, including paid-plan availability, 90-day metadata retention, and a 99.5% uptime target.

    railo.dev

    Products & Services

    2
    Railo GitHub App / Railo Dev
    2026

    GitHub App and Marketplace product that scans changed code in pull requests, comments findings and status checks, and opens a separate fix PR when it can produce a deterministic remediation. The Marketplace listing describes the implementation as running through GitHub Actions, with no external API calls and no code leaving the user's environment.

    Finding Closure Sprint
    2026

    A fixed-scope service for one authorized Python repository: a point-in-time scan, in-scope hardcoded-secret and SQL-injection findings, reviewable fix PRs, verification evidence, and one follow-up scan.

    Market Position

    Railo positions itself between vulnerability scanners and remediation automation: unlike Snyk, Semgrep, and similar scanners that primarily report findings, it produces reviewable fix PRs; unlike generic AI coding assistants, it uses deterministic rules and verification evidence rather than LLM-generated patches. Its GitHub-native, organization-priced model also contrasts with seat-priced alternatives, while its explicit limitations mean it targets known, mechanically remediable patterns rather than novel vulnerabilities or business-logic flaws.

    Leadership

    Founders

    ZL

    Zarif Latif

    Founder of Railo and IWEBai; describes himself publicly as a software engineer and AI researcher. He is building autonomous DevSecOps that automatically fixes and formally verifies vulnerabilities.

    Executive Team

    ZL

    Zarif Latif

    Founder

    Software engineer and AI researcher; founder of IWEBai and builder of Railo's autonomous DevSecOps product.

    Founding Story

    Zarif Latif says he started Railo after repeatedly seeing scanners identify the same mechanical issues—such as SQL injection—while teams spent weeks triaging and hand-writing small fixes. The initial vision was a Dependabot-like workflow for vulnerabilities in first-party code: use deterministic rewrite rules for remediation rather than probabilistic LLM-generated patches, and deliver every change as a reviewable pull request.

    Business Model

    Revenue Model

    Organization-based SaaS subscriptions priced by repository and pull-request-scan quotas rather than per developer, plus a fixed-scope $1,500 Finding Closure Sprint and custom Enterprise agreements.

    Pricing Tiers

    Free
    $0 forever

    3 repositories, 200 pull-request scans per month, detection on every pull request, warn-mode comments, and findings dashboard.

    Pro
    $99 per organization per month

    Free features plus automated fix pull requests, 10 repositories, 2,000 scans per month, email notifications, and CSV export.

    Team
    $299 per organization per month

    Pro features plus organization-wide policy controls, 50 repositories, 10,000 scans per month, Slack notifications, and priority support.

    Enterprise
    Custom

    Unlimited repositories and scans, SARIF export, audit log, dedicated support, and the one-repository $1,500 Finding Closure Sprint.

    Target Markets

    Industries & Segments
    • Small and medium-sized software teams
    • B2B SaaS companies using Python
    • Organizations with application-security backlogs
    • Enterprise engineering and security teams needing audit evidence and policy controls
    • Teams using GitHub pull-request workflows
    Use Cases
    • Clearing backlogs of known application-security findings
    • Automatically remediating SQL injection, SSRF, path traversal, XSS, command injection, hardcoded secrets, and other supported patterns
    • Security review and pull-request protection for development teams
    • Preparing small B2B SaaS teams for customer security reviews, SOC 2 work, or a security-backlog deadline
    • Enterprise audit evidence, organization-wide remediation policy, and controlled security operations across repositories

    Quick Facts

    Headquarters
    Dhaka, Bangladesh
    Founded
    2026
    Employees
    2
    Office Locations
    Dhaka

    History & Milestones

    2026

    Railo was founded; LinkedIn lists the company as founded in 2026 and privately held, with a 2–10 employee size band.

    2026

    Railo launched its GitHub Marketplace app, listed as Railo Dev by IWEBai, for scanning pull requests and proposing deterministic security fixes.

    2026

    The product expanded from the original GitHub Action positioning to a GitHub App workflow with companion fix PRs, verification outcomes, evidence exports, organization policy controls, and paid Pro, Team, and Enterprise plans.

    August 2026

    Railo published current Security & Data Handling, Privacy Policy, and Service Level pages; the service-level page says paid plans are live and gives a 99.5% monthly uptime target for the core service.

    Key Capabilities

    12
    Pull-request vulnerability detection with source-to-sink tracing
    Deterministic, rule-based patches that produce a byte-identical result for the same input
    Companion fix pull requests; Railo does not directly modify the developer's branch
    Verification outcomes: cleared, not cleared, inconclusive, or not attempted
    Proof-strength labels and per-finding evidence records
    Warn mode for comments and checks, and enforce mode for fix PRs

    Integrations & Partnerships

    Platform Integrations

    • GitHub pull requests, comments, status checks, repositories, and GitHub App installation tokens
    • GitHub Actions
    • Semgrep-powered vulnerability-pattern scanning
    • Z3 SMT solver for formal verification
    • GitHub Code Scanning/SARIF export on eligible Enterprise plans
    • JSON and CSV evidence export
    • Slack notifications on Team plans; email notifications on Pro plans

    Key Partnerships

    GitHub Marketplace distribution and GitHub App integration
    GitHub Actions execution through the IWEBai/railo-action@v2 workflow

    Connect

    Website
    railo.dev
    GitHub
    railo-dev

    AI Topics

    3

    Railo focuses on these topics:

    Code Security(1)
    Bug Detection(1)
    Code Review(1)
    Back to all developersSuggest an edit