Back

Case Study: Jit Enables Secure-by-Design DevSecOps with Continuous Pentesting

January 20, 2026

3 minutes read

Industry: DevSecOps and Application Security

Organization: Jit

Security Leadership: David Melamed, CTO

Product: Terra Security Continuous Pentesting

Background

Jit is an Agnetic AI platform for Product Security - AI Agents that automatically execute Code Scanning, Cloud Security, Data Security, and Compliance workflows, with Humans-in-the-Loop for every critical decision.

As a company serving modern security teams, Jit must ensure that its own platform exemplifies secure-by-design principles while evolving rapidly to meet customer needs.

Security Leadership in a Developer-First Company

Jit’s security and engineering leadership operate in a deeply integrated model, where security controls are expected to be developer-friendly, automated, and highly contextual.

Security tooling must deliver value without slowing delivery, aligning perfectly with the DevSecOps philosophy Jit promotes.

The Challenge: Practicing What You Preach

Jit’s platform changes frequently, with new capabilities, integrations, and workflows introduced on a regular basis.

Periodic penetration tests could not keep up with this pace, creating blind spots between releases and limiting the team’s ability to confidently validate real-world exploitability.

Continuous Pentesting as Part of the DevSecOps Loop

By adopting Terra Security, Jit embedded continuous penetration testing directly into its operational security stack.

Rather than treating pentesting as a separate event, Jit runs ongoing attack simulations that reflect the current state of its application and infrastructure.

This provides timely, actionable findings that align naturally with Jit’s CI/CD-driven development process.

Real Risk, Real Context

Continuous pentesting enables Jit to focus on vulnerabilities that are exploitable in practice, not just theoretically present.

This mirrors Jit’s own philosophy of prioritization based on context and impact, reinforcing alignment between product vision and internal security operations.

Supporting Customer Trust and Platform Credibility

As a DevSecOps vendor, Jit’s security posture is part of its brand. Continuous pentesting helps demonstrate that the platform is continuously validated against real attack scenarios.

This strengthens customer confidence and supports enterprise security reviews.

Takeaway

Jit shows how DevSecOps platforms can operationalize continuous security validation without disrupting developer velocity. By making pentesting continuous, Jit reinforces its secure-by-design ethos in practice, not just in principle.

Continue reading