Eureka DevSecOps
Our Story

AppSec expertise,
built into the workflow.

Eureka was built by application security practitioners who spent decades helping software teams find risk, make sense of scanner output, satisfy security reviews, and show what happened.

The idea is simple: most teams don't need another disconnected security tool. They need the judgment, structure, and workflow discipline of experienced AppSec leaders built into the way they scan, prioritize, remediate, and collect evidence.

30-day free trial. No credit card required.
Built by leaders behind OWASP ASVS and OWASP SPVS
Portrait of Farshad Abasi, Co-Founder and Co-CEO of Eureka DevSecOps
Founder Story

Farshad Abasi brings decades of AppSec, enterprise security, and standards leadership into Eureka

Farshad is the founder and CEO of Forward Security and Co-Founder, Co-CEO of Eureka DevSecOps. His career spans software engineering, enterprise security architecture, application security leadership, and security education, including senior security roles at HSBC, technical roles at Intel and Motorola, OWASP Vancouver leadership, and long-standing involvement in the AppSec community. Eureka reflects that practical experience: the repeated gap between scanner output, developer workflow, and the evidence teams need when customers, auditors, or reviewers ask what happened.

"Scanner output was never the whole problem. The harder part was helping teams understand what mattered, move the work forward, and keep a clear record of what happened."
, Farshad Abasi, Co-Founder & Co-CEO, Eureka DevSecOps
Why Eureka Exists

The same AppSec failure kept showing up everywhere

Before Eureka, Farshad ran application security at HSBC, building and leading the team responsible for helping hundreds of development teams ship secure software. He was a developer first, then a security leader, so he understood the problem from both sides.

Two things broke everything. The security tools took a year to get into developer pipelines, unreasonable for teams trying to ship. And the findings lived in spreadsheets, scattered everywhere, with no way to see what mattered or show what had been done. So he built an in-house system to bring those findings into one place and manage them. That system was the seed of Eureka.

With close to a thousand developers and an AppSec team that could never cover them by headcount, the lesson was clear: you can't hire your way out of application security. You solve it through automation, enablement, and workflow, the real origin of DevSecOps, and of Eureka.

Eureka grew from years of practical AppSec work and a repeated market pattern: teams could scan, but they could not reliably decide what mattered, route the work, or show what happened.

Origin · How Eureka Came to Be
  1. 01HSBC
    Enterprise AppSec at scale

    Farshad helped support hundreds of development teams with an AppSec organization that could never scale through headcount alone.

  2. 02Forward Security
    The same pattern kept repeating

    Scanners found vulnerabilities, but teams still needed help organizing findings, deciding what mattered, and moving the work forward.

  3. 03The Missing Layer
    The work stayed manual

    Prioritization, review decisions, remediation history, and evidence lived across spreadsheets, tickets, and disconnected reports.

  4. 04The Insight
    AppSec expertise had to become operational

    Teams needed the judgment and structure of experienced AppSec leaders built directly into the workflow.

  5. 05Eureka
    From scanner output to an AppSec workflow

    Eureka brings scanning, prioritization, remediation tracking, and the workflow record into one connected system.

"Scanner output was never the whole problem. The harder part was helping teams understand what mattered, move the work forward, and keep a clear record of what happened."
, Farshad Abasi, Co-Founder & Co-CEO, Eureka DevSecOps
The Pattern

What Farshad and the team kept seeing

PATTERN · APPSEC_FAILURE_MODES04 OBSERVATIONS
01

Scanner output still needed judgment

The tools found vulnerabilities, but not what mattered, what blocked a review, or how to move work forward.

02

Security work became manual

Prioritization, review notes, exceptions, and evidence lived in tickets, spreadsheets, and scattered reports.

03

Proof was reconstructed too late

By the time a customer, auditor, or regulator asked, teams were rebuilding the story after the fact.

04

Eureka was built for the missing layer

From scanner output to prioritized work, remediation tracking, and evidence collection in one workflow.

Mission

Help every software team run AppSec with clarity, speed, and proof

Eureka helps software teams move from scattered scanner output to prioritized AppSec work, so they can see what matters, fix the right issues, and collect evidence as work happens. Our mission is to make application security easier to start, easier to operate, and easier to prove, without requiring every team to build deep AppSec expertise from scratch.

Standards Foundation

Eureka is built on the standards we helped write

Eureka isn't built on standards the team merely follows, it's built on standards the team helped author. That's the difference between buying a tool and getting the judgment of the people who define what good looks like.

STANDARDS · FOUNDATIONOWASP ASVS · OWASP SPVS

OWASP ASVS

The application security verification standard auditors respect and architects build to. Eureka's team didn't just adopt ASVS, its people authored parts of it.

OWASP SPVS

The Secure Pipeline Verification Standard, a standard for pipeline security. Co-authored by Eureka's founder, now covering AI controls in its latest release.

Standards-based by design

Findings, prioritization, and evidence are organized around the controls reviewers actually recognize.

Expertise operationalized

That standards knowledge isn't a whitepaper. It's wired into how Eureka runs scans, prioritizes findings, and structures evidence.

You don't need to become AppSec experts to operate like a mature AppSec team
Leadership Team

The experts behind Eureka

Eureka was built by cofounders who bring together the three disciplines this problem requires: deep application security and DevSecOps expertise, product and technology leadership, and the finance and operations discipline to turn it into a scalable company.

Portrait of Farshad Abasi

Farshad Abasi

Co-Founder and Co-CEO, Eureka DevSecOps
LinkedIn ↗

Application security leader with 30 years in software across security, software design, network architecture, and enterprise security programs. Co-Founder and CEO of Forward Security, co-author of the OWASP Secure Pipeline Verification Standard, contributor to OWASP ASVS, OWASP Vancouver Chapter Lead, and lead organizer of BSides Vancouver. His practical AppSec experience shaped Eureka's core belief: scanner output is not enough, teams need a workflow that helps them understand what matters, route the work, and keep a defensible record of what was found, reviewed, fixed, accepted, and documented.

Designations: CISSP, AWS Security Professional, Azure Security Engineer.
Portrait of Sasa Djolic

Sasa Djolic

Co-Founder and Co-CEO, Eureka DevSecOps
LinkedIn ↗

Technology and product leader with 20 years building high-performing engineering teams. Served as VP and Program Owner, Data Science Services at Mastercard. Sasa leads Eureka's product and technology direction, turning the team's AppSec and DevSecOps expertise into a product software teams can actually use, without enterprise-tool complexity.

Designations: Master's degree in Cybersecurity.
Portrait of Mathieu Chretien

Mathieu Chretien

Co-Founder, COO
LinkedIn ↗

Operations and finance leader with 17+ years across IT program and project management, cash flow optimization, and supply-chain optimization at Deloitte, EY, BC Hydro, GE, and emerging technology companies. Mathieu leads finance and operations, bringing the operating structure, and financial discipline to turn Eureka's technical vision into a durable, scalable company.

Designations: PMP, CSCP, AWS Cloud Practitioner.
Portrait of Iman Sharafaldin

Iman Sharafaldin

ASVS Contributor | Application and Cloud Security Lead
LinkedIn ↗

Iman brings deep cybersecurity research expertise to Eureka's standards foundation. He contributes to OWASP ASVS, helping anchor Eureka's approach in practical application security requirements, not generic scanner output. His expertise supports Eureka's standards-based model for organizing findings, connecting vulnerabilities to meaningful AppSec controls, and helping teams understand what strong application security looks like in practice.

Credentials: PhD in Cybersecurity, AWS Solutions Architect, OSWE, AWS Certified Security – Specialty
Made in Canada

Made in Canada. Built for teams that need trust, speed, and proof

Eureka is made in Canada by application security and DevSecOps experts who understand the needs of software teams facing customer security reviews, audits, compliance workflows, and regulated-market pressure. For Canadian public-sector, healthtech, fintech, and regulated buyers, local trust and data-residency expectations matter. But the core reason to choose Eureka is the product: workflow traceability, practical AppSec expertise, and a clearer way to move from findings to prioritized work and evidence.

How We Build

Practical security, not security theatre

Eureka is built around real AppSec expertise, proven standards, and practical development workflows. The goal is not to create more security noise. The goal is to help teams understand what matters, act on the right issues, and keep evidence connected to the work as it happens.

01

Built on AppSec standards teams already trust

Eureka is grounded in practical frameworks like OWASP ASVS and OWASP SPVS, so teams aren't inventing their security process from scratch.

02

Designed for real software teams

Built for teams with deadlines, customer reviews, audits, and submissions already in motion. AppSec becomes part of the workflow, not another process teams avoid.

03

Clear about what Eureka does and doesn't do

Eureka is not a GRC platform, auditor, or standalone scanner. It supports the AppSec evidence layer beneath compliance workflows by connecting findings, workflow activity, remediation history, and evidence.

FAQ

Frequently asked questions.

See how Eureka turns AppSec expertise into a workflow your team can use.

Eureka helps teams move from scattered findings to prioritized work, remediation tracking, and AppSec evidence they can stand behind.

30-day free trial. No credit card required.