Shasheen Bandodkar
Derek C.
Modern AppSec tooling is fragmented: one scanner for secrets, another for dependencies, another for SAST, another for containers, another for SBOMs, and then a separate workflow for triage. Broly is an open source Go scanner built to collapse that workflow into one fast App and finding model.
This Arsenal session walks through Broly's current design: Titus-backed secrets scanning, osv-scalibr + OSV.dev dependency analysis, Together AI powered SAST, container image scanning, license policy checks, SBOM output with baselines, incremental scans, SARIF/JSON/table output, and built in AI triage with optionality. The demo will show Broly scanning a vulnerable repo, producing actionable findings, filtering noise and fitting into a PR workflow.
The session is also a candid engineering case study on what broke, what was rebuilt, where & how AI helped, where deterministic engines still lead, and why security tools need to be attacked with the same rigor as the code they judge.
Shasheen Bandodkar
Security Engineer @Together AI
Shasheen Bandodkar is a security engineer passionate about safeguarding technology and innovation. With deep cybersecurity expertise, he frequently shares insights on his blog and is known for turning rants into revelations.
Derek C.
Head of Security @ Together AI
Derek is the Head of Security at Together.ai and the former Head of Infrastructure Security at Cloudflare. He has over 20 years of experience in designing security frameworks at scale. His main focus is on research and development within the fields of encryption and infrastructure security.
He earned a masters in cybersecurity from Purdue University and now owns more than 60 global patents related to cryptography, key management, and distributed ledger technology.