> For the complete documentation index, see [llms.txt](https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/readme.md).

# Heeler Documentation

Product documentation for Heeler: setup, the software model, findings, PR guardrails, automated remediation, and operations reference.

Welcome to the Heeler docs.

Heeler connects to your source control, cloud and registries, builds a model of your software, and uses that model to **prevent** risky code from merging, **fix** findings automatically, and **operate** the lifecycle through to confirmed closure.

## Start here

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><h3>Get Started</h3></td><td>Connect your first repository and read its findings.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started.md">Get Started</a></td><td><a href="https://414480750-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXP3dp2kecwKA2KvYkntz%2Fuploads%2Fgit-blob-a32fd2d41999fc90867c5f46f51360eeafa9932a%2Fcover-get-started.png?alt=media">cover-get-started.png</a></td></tr><tr><td><h3>What Is Heeler</h3></td><td>What the product does, and the conditions it is built for.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/overview.md">Overview</a></td><td><a href="https://414480750-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXP3dp2kecwKA2KvYkntz%2Fuploads%2Fgit-blob-2f81f95924aaa2ba5a79100c251d3eee744c1170%2Fcover-overview.png?alt=media">cover-overview.png</a></td></tr><tr><td><h3>Supported Technologies</h3></td><td>Languages, ecosystems, SCMs, clouds, registries, and integrations.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/supported-technologies.md">Supported Technologies</a></td><td><a href="https://414480750-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXP3dp2kecwKA2KvYkntz%2Fuploads%2Fgit-blob-46ed3585290137017a8a2344d2080777fc52c0ee%2Fcover-supported-technologies.png?alt=media">cover-supported-technologies.png</a></td></tr></tbody></table>

## The operating model for the AI SDLC

Heeler works in three continuous layers, all powered by one context engine:

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><h3>Prevent</h3></td><td>Stop risk as code is written — inside the agent, at the keyboard, and on every pull request.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/prevent.md">Prevent</a></td><td><a href="https://414480750-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXP3dp2kecwKA2KvYkntz%2Fuploads%2Fgit-blob-8255a4ba52462a07420c724afb5539a79645178e%2Fcover-prevent.png?alt=media">cover-prevent.png</a></td></tr><tr><td><h3>Fix</h3></td><td>Fix everything deterministically — a validated, merge-ready PR across the whole backlog.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/fix.md">Fix</a></td><td><a href="https://414480750-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXP3dp2kecwKA2KvYkntz%2Fuploads%2Fgit-blob-2ca610415246d63c5aa8501b607535edd3369057%2Fcover-fix.png?alt=media">cover-fix.png</a></td></tr><tr><td><h3>Operate</h3></td><td>Native engines verify every commit; workflows drive every finding to verified closure.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/operate.md">Operate</a></td><td><a href="https://414480750-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXP3dp2kecwKA2KvYkntz%2Fuploads%2Fgit-blob-099316ee04617353b04aa87821fc7efc0f47b0b7%2Fcover-operate.png?alt=media">cover-operate.png</a></td></tr></tbody></table>

## In this section

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-type="content-ref"></th></tr></thead><tbody><tr><td><h3><i class="fa-boxes-stacked" style="color:$primary;">:boxes-stacked:</i></h3></td><td><strong>Catalog</strong></td><td>Your inventory — repositories, dependencies, services, endpoints, deployments, and more.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/catalog.md">Catalog</a></td></tr><tr><td><h3><i class="fa-triangle-exclamation" style="color:$primary;">:triangle-exclamation:</i></h3></td><td><strong>Findings</strong></td><td>Open-source (SCA), code (SAST), secrets, and agent-file findings, banded by exposure.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/findings.md">Findings</a></td></tr><tr><td><h3><i class="fa-arrows-rotate" style="color:$primary;">:arrows-rotate:</i></h3></td><td><strong>Operate</strong></td><td>Workflows, SLOs, dashboards, and Slack — drive every finding to verified closure.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/operate.md">Operate</a></td></tr><tr><td><h3><i class="fa-shield-halved" style="color:$primary;">:shield-halved:</i></h3></td><td><strong>Prevent</strong></td><td>PR guardrails, the CLI, and MCP &#x26; Agent Skills that stop risk left of merge.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/prevent.md">Prevent</a></td></tr><tr><td><h3><i class="fa-wrench" style="color:$primary;">:wrench:</i></h3></td><td><strong>Fix</strong></td><td>Prioritization, SCA/SAST auto-fix, and automated, validated remediation.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/fix.md">Fix</a></td></tr><tr><td><h3><i class="fa-clipboard-check" style="color:$primary;">:clipboard-check:</i></h3></td><td><strong>Standards &#x26; Compliance</strong></td><td>Measure applications against OWASP ASVS, enforce a level, and produce the evidence.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/standards-and-compliance.md">Standards and Compliance</a></td></tr><tr><td><h3><i class="fa-sliders" style="color:$primary;">:sliders:</i></h3></td><td><strong>Administer &#x26; Monitor</strong></td><td>The whole Administration area — connections, access, program, and operational health.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/administer-and-monitor.md">Administer and Monitor</a></td></tr><tr><td><h3><i class="fa-book" style="color:$primary;">:book:</i></h3></td><td><strong>Reference</strong></td><td>CLI commands, MCP tools &#x26; prompts, supported secret types, and the glossary.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/reference.md">Reference</a></td></tr><tr><td><h3><i class="fa-compass" style="color:$primary;">:compass:</i></h3></td><td><strong>Playbooks</strong></td><td>Complete walkthroughs, from "is this CVE exploitable?" to assembling evidence for an audit.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/solutions-and-use-cases.md">Playbooks</a></td></tr><tr><td><h3><i class="fa-life-ring" style="color:$primary;">:life-ring:</i></h3></td><td><strong>Troubleshooting &#x26; FAQ</strong></td><td>Setup and connection issues, findings questions, and common answers.</td><td><a href="/mrecEO40m5D6bt7Pq5pE/troubleshooting-and-faq.md">Troubleshooting and FAQ</a></td></tr></tbody></table>

## Popular tasks

<table><thead><tr><th width="340">I want to…</th><th>Go to</th></tr></thead><tbody><tr><td>Connect my source control</td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/source-code-scm.md">Connect Your Code</a></td></tr><tr><td>Add cloud &#x26; runtime context for prioritization</td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/cloud-and-runtime.md">Connect Your Cloud &#x26; Runtime</a></td></tr><tr><td>Gate risky pull requests</td><td><a href="/mrecEO40m5D6bt7Pq5pE/prevent/pr-guardrails.md">PR Guardrails</a></td></tr><tr><td>Auto-fix dependency &#x26; code vulnerabilities</td><td><a href="/mrecEO40m5D6bt7Pq5pE/fix.md">Fix</a></td></tr><tr><td>Route findings to the right team automatically</td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/map-your-organization/team-ticket-settings.md">Team Ticket Settings</a></td></tr><tr><td>Run Heeler in my IDE or CI</td><td><a href="/mrecEO40m5D6bt7Pq5pE/get-started/set-up-developer-tooling.md">Set Up Developer Tooling</a></td></tr><tr><td>Show an auditor we meet a security standard</td><td><a href="/mrecEO40m5D6bt7Pq5pE/standards-and-compliance.md">Standards &#x26; Compliance</a></td></tr><tr><td>Understand how findings are prioritized</td><td><a href="/mrecEO40m5D6bt7Pq5pE/findings/open-source-sca/prioritization.md">Heeler Risk &#x26; Prioritization</a></td></tr></tbody></table>

{% hint style="info" %}
**New to Heeler?** Read the [Overview](/mrecEO40m5D6bt7Pq5pE/overview.md) for the big picture, then work through [Get Started](/mrecEO40m5D6bt7Pq5pE/get-started.md) to connect your environment. Questions the docs don't answer? See [Troubleshooting and FAQ](/mrecEO40m5D6bt7Pq5pE/troubleshooting-and-faq.md).
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
