
The implementation process for Xygeni is designed to be frictionless, often cited as a '30-second onboarding' experience. Organizations can start by connecting their SCM (GitHub, GitLab, Bitbucket, or Azure DevOps) via an OAuth app or personal access token. Once connected, Xygeni automatically performs an 'Asset Discovery' to inventory repositories, teams, and CI/CD pipelines. Scanning can be triggered immediately using pre-configured 'Standard' policies. Because Xygeni uses a 'no code upload' architecture, the scanners run within the customer’s existing CI/CD runner or local environment, ensuring that the initial setup doesn't require complex network reconfigurations or long-drawn-out security reviews regarding source code exposure.
Xygeni offers extensive customization capabilities to align with an organization's specific security policies. Users can define 'Policy Guardrails' that determine what constitutes a 'break' in a build or a pull request. These policies can be tiered (e.g., Strict, Default, or Loose) and applied globally or to specific projects. The platform also allows for the customization of risk scoring metrics, enabling teams to weigh certain vulnerabilities more heavily based on their business context. Furthermore, Xygeni supports custom detector creation and integrates with third-party security tools, allowing organizations to ingest external findings into the Xygeni ASPM dashboard for a unified view.
Beyond the base subscription price per contributor, Xygeni is generally transparent about costs. There are no hidden fees for basic integrations with major Git providers. However, organizations opting for 'On-Premise' deployment or requiring specialized enterprise support (dedicated account managers, 24/7 priority response) may incur additional professional services or licensing fees. Training and certification programs are typically included in enterprise contracts, but may be offered as add-ons for smaller teams. Customers should also account for the compute costs of running the local scanners within their own CI/CD infrastructure, though these are typically negligible.
Xygeni provides a multi-layered training ecosystem to ensure successful adoption. New customers are provided with a comprehensive 'Product Tour' and onboarding sessions led by security engineers. The company maintains an extensive online 'Resource Library' featuring video tutorials, detailed documentation, and step-by-step guides for integrating with various DevOps tools. For enterprise clients, Xygeni offers structured training workshops and webinars focused on the latest supply chain threats. Additionally, their 'Malicious Code Digest' and blog serve as ongoing educational resources to keep teams informed about emerging risks and best practices in AppSec.
Security is the core of Xygeni’s platform. The most significant security measure is their 'No Code Upload' policy; source code never leaves the customer’s controlled environment during a scan. Only the metadata and security findings are encrypted (TLS 1.2+ in transit and AES-256 at rest) and sent to the Xygeni dashboard. The platform itself is hosted in secure, ISO-certified data centers and undergoes regular third-party penetration testing. Xygeni also implements robust Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and detailed audit logging to ensure that only authorized personnel can access the security results and configurations.
Xygeni follows a rapid release cadence, typical of modern SaaS platforms, with updates and new features being deployed almost weekly. Because the control plane is SaaS-based, users automatically benefit from UI improvements, new vulnerability signatures, and enhanced detection logic without needing to perform manual updates. For the local scanning components (CLI and CI/CD actions), Xygeni provides automated version management to ensure that customers are always using the latest scanners. The company also publishes a 'Malicious Code Digest' in real-time as new supply chain threats are identified by their global sensor network.
Xygeni’s data ownership policy is clear: customers retain 100% ownership of their source code and the security findings generated by the platform. Xygeni acts only as a data processor for the findings. The platform provides comprehensive export options, allowing users to download security reports and findings in multiple formats (JSON, PDF, CSV). Furthermore, SBOMs can be exported in standardized CycloneDX and SPDX formats, ensuring data portability and compliance with vendor-neutral standards. In the event of contract termination, customers can export their historical data before it is securely purged from Xygeni’s systems.
Xygeni is built to scale from small teams with a handful of repositories to large enterprises with thousands of projects and millions of lines of code. The platform’s distributed scanning architecture means that as an organization grows, the scanning load is handled by the customer’s own CI/CD infrastructure, preventing Xygeni’s central control plane from becoming a bottleneck. The ASPM layer is designed to handle massive amounts of security data, using AI-driven deduplication and correlation to keep the user interface responsive and the alerts manageable even at enterprise scale. Pricing scales linearly based on active contributors, providing a predictable cost model as the team grows.
Xygeni typically offers annual and multi-year subscription contracts, with renewals occurring on the anniversary of the sign-up date. The terms include standard Service Level Agreements (SLAs) regarding platform availability and support response times. Cancellation usually requires a 30-day notice prior to the end of the current term. The platform’s 'Standard' terms emphasize a commitment to data privacy and security, aligning with GDPR requirements. Enterprise contracts may include more tailored clauses regarding liability, custom integration support, and dedicated environment hosting for on-premise clients.
Xygeni helps organizations meet several critical compliance standards. The platform is designed with GDPR principles at its heart, specifically regarding data minimization and privacy. It directly supports compliance with ISO 27001 by providing controls for secure software development (Annex A.14). Furthermore, Xygeni is a leader in implementing the SLSA (Supply-chain Levels for Software Artifacts) framework, helping organizations reach Level 3 compliance through automated build attestations. It also aligns with the NIST Secure Software Development Framework (SSDF), DORA (Digital Operational Resilience Act) requirements for financial institutions, and the OpenSSF Scorecard for open-source health.

Xygeni Security
By Xygeni