National Health Insurer Transforms Software Supply Chain Security with Kusari
How a 6,000-seat health insurer verified the artifacts its scanners assumed were clean, cut vulnerability noise by 90%, and can now answer a zero-day within the hour.
The challenge: what scanners miss
The organization had invested in every scanner imaginable: SAST, SCA, container scanning, and dependency management. Yet every supply chain attack ended the same way — a scramble, high effort, low confidence, and no solid answer to the questions that actually mattered:
- Do we have this dependency at all, and which artifacts is it in?
- Where did it come from, and what pulled it in?
- What is it affecting right now, across applications, images, and environments?
Then Axios, the most downloaded JavaScript package in the world, got compromised. With every tool in place, the team could not say whether they even had any of the affected versions, let alone which artifacts carried it.
The root cause: scanners read only the top layer. They inspect finished artifacts and take the manifest's word for what's inside, so they cannot say where a dependency came from or what it's affecting. As one of the security team's leaders put it, heading into the next zero-day without a verified picture was no longer tenable.
Why Kusari
The team chose Kusari because it immediately answered the question no other solution could: are we affected by Axios, and where? Kusari answered with definitive proof — they were exposed, and it was in these three artifacts. That answer was enabled by Kusari's dependency graph, built from source rather than reverse-engineered from a finished artifact. It fit into the team's existing workflows, and the accuracy enabled swift action.
From there, Kusari plugged into the developer tooling and gave security immediate blast-radius answers on supply chain zero-days. That is how the team built trust into its running artifacts: confidence in the inputs is what makes every output verifiable.
The flood of new issues hasn't stopped. Kusari now tells them which ones deserve attention.
What changed:
- Every dependency verified on its way into the development process, and every build checked against the source that produced it
- Prioritization built on that verified foundation, ranked by what is actually reachable in their environment
- Full transitive visibility into the hidden, indirect dependencies their stack consistently missed
- Answers on demand for which products are affected, which customers are exposed, and the fix path
From visibility to autonomous action
Kusari became the foundation for a staged rollout — from unifying the estate, to guarding every change, to cutting noise, to fixing what's left automatically.
A single source of truth across repos, images, and pipelines — built from source, continuously updated.
A thumbs-up / thumbs-down on every change — catching risky dependencies before they ever merge.
Reachability and exploitability analysis prioritizes risk and removes the 90% of findings that can't be reached.
Autonomous, environment-aware fixes — validated in CI before they ever touch the codebase.
The results: signal over noise, at enterprise scale
With the Platform as the foundation and Inspector guarding every pull request, the team gained continuous, enterprise-wide visibility into a software estate carrying tens of thousands of vulnerabilities. But visibility was only the start.
By layering in reachability and exploitability analysis, Kusari now strips out 90% of vulnerability noise — the findings that exist in a dependency but can never actually be reached in this environment. Instead of chasing a backlog tens of thousands deep, the security team focuses only on what is genuinely exploitable and material. And with AutoFix, the highest-confidence remediations are generated, validated, and routed automatically, so the queue shrinks instead of growing.
The outcome is a measurable shift in posture: from reactive scrambling during a zero-day to proactive awareness before one hits, with answers in seconds, not days.
Where Kusari fits in the stack
Kusari is not another scanner. It is the system of record for supply chain trust. It maps every direct and transitive dependency to real systems, tells the team what's actually exploitable, and closes the loop with autonomous remediation. Kusari makes the whole estate answerable as one.
We invest heavily in application security, but we had a real gap in transitive and indirect dependencies. The last thing we want is another Shai-Hulud without Kusari in place.
— Security Leader
Want to know what's actually reachable in your own environment? Schedule a demo and speak with one of our founders.