20.11.2025
Reading time: 2-3 min

Software Improvement Group showcases secure, high-quality AI-assisted development in joint proof of concept with Progress Software

Software Improvement Group

Software Improvement Group and Progress Software demonstrate that with quality and security guardrails, AI-assisted coding can deliver speed without compromise.

Amsterdam, 20 November 2025 – Software Improvement Group (SIG) has successfully demonstrated that developers can use AI-coding assistants without sacrificing code quality or security.

In a proof of concept (POC) conducted in collaboration with Progress Software, SIG integrated its Sigrid® MCP server into the Progress® OpenEdge® development environment, enabling real-time, automated checks on AI-generated code directly in the Integrated Development Environment (IDE).

The need for security and quality guardrails

Today, AI-assisted coding is everywhere.

According to Stack Overflow’s 2025 survey, 84% of developers are already using or planning to use AI tools. While large language models (LLMs) can increase developer output by 26%, separate experiments show experienced engineers may slow down by 19% when reworking flawed AI-generated code.

This happens because LLMs make suggestions based on patterns in their training data. LLMs are trained on market-average code and rely on associative, pattern-based reasoning, which makes them fast but not always accurate.

The takeaway: productivity gains are real only if quality and security controls keep pace.

That’s where the Model Context Protocol (MCP) server from SIG comes in.

Sigrid® MCP


MCP stands for Model Context Protocol. It’s an open standard that allows AI models (LLMs) to interact with and use external data sources and tools.

SIG’s MCP server allows real-time quality and security checks on AI-generated code as soon as it’s created and right in the IDE. If a code suggestion falls short, feedback is provided instantly, helping the AI code assistant improve AI-generated results according to leading global standards within seconds.

The image depicts a dark-themed Integrated Development Environment (IDE) mockup showing a code editor on the left and an overlay with maintainability findings on the right. The left section displays a project directory tree with folders and Java files listed, such as "AdapterScript.java," "FunctionUtils," and "TrivariateFunction." The code editor shows Java code for a "BankAccount" class with methods including "depositCash" and "depositCheck." Syntax highlighting is used, with keywords in orange, class names in purple, and comments in green. On the right, an overlay titled "MCP Tool: SigridCode / Code_quality_guardrails" reports a "Maintainability Issue Detected," highlighting code duplication and a critical security vulnerability. Alt-text: IDE mockup showing a Java project with maintainability findings overlay. Transcribed Text: MCP Tool: SigridCode / Code_quality_guardrails Maintainability Issue Detected The Sigrid Code Quality Guardrails analysis has identified some maintainability issues that I need to address: Code Duplication (VERY_HIGH severity): There’s duplicated code in the BankAccount class between the depositCash and depositCheck methods. I also notice a critical security vulnerability in the existing getTransactionHistory method—it uses string concatenation for SQL queries, making it vulnerable to SQL injection attacks. Let me fix these issues by refactoring the code.

SIG and Progress teamed up for a joint POC

SIG and Progress demonstrated that LLM-assisted coding doesn’t have to introduce hidden risks or technical debt. It can accelerate quality, reduce rework, and support enterprise-scale development

“With quality and security checks built right into the workflow, developers can generate code, review it, and fix issues instantly, without ever leaving the IDE,”Stephan Leferink, Senior Vice President Global Sales, Application and Data Platform at Progress

By integrating SIG’s Sigrid® MCP server with Progress OpenEdge during the POC, developers could automatically verify and improve code quality, detect vulnerabilities in real time, and reduce rework, all without disrupting their workflows.

Progress published a whitepaper and shared key results

Last week, Progress published a whitepaper, ‘8 Steps to Unlocking Quality AI Code at Speed’, and shared significant results of the POC and showcased how Progress leveraged SIG’s MCP server to optimize AI-Powered Coding Assistance in the OpenEdge QSM solution.

Key results from the joint POC include:

  • Reduced average maintainability violations from five to zero.
  • Flagged security misconfigurations directly within the IDE.
  • Spent no more than mere seconds on manual checks, instead of hours reworking faulty code.
  • Estimated savings of up to €2.25 million in maintenance costs per system, per year.

“AI is a powerful tool, but it needs oversight. With the Sigrid MCP server, developers can trust what the AI coding assistant produces, and ship better code, faster,”Michel van Dorp, Vice President Strategic Partnerships at Software Improvement Group.

As AI continues to reshape development workflows, quality and security cannot be an afterthought. Software Improvement Group and Progress are committed to providing developers with tools that accelerate delivery, while ensuring that every line of code is secure, maintainable, and ready for production.

To learn more about the joint POC, download the whitepaper, explore Progress OpenEdge QSM, or discover SIG’s MCP server.

About Software Improvement Group

Software Improvement Group (SIG) empowers organizations to govern the software their business runs on. Through complete portfolio analysis and tailored strategic advice, SIG helps companies improve software quality and security by focusing strategic efforts across people, process, and technology.

Sigrid®—SIG’s software governance platform—analyzes over 400 billion lines of code across more than 30,000 systems and 300+ technologies, offering evidence-based insights to help organizations prioritize and manage their most critical IT initiatives.

Founded in 2000 and headquartered in Amsterdam, SIG has offices in New York, Copenhagen, Brussels, and Frankfurt. The company complies with leading ISO/IEC standards, including 27001 and 17025, and co-developed ISO/IEC 5338—the new global standard for AI lifecycle management.

Combining expert consulting with over 25 years of industry-leading research, SIG is the global authority on software portfolio governance.

For more information, please visit Software Improvement Group‘s website or social media channels.

Experience Sigrid live

Request your demo of the Sigrid® | Software Assurance Platform:
  • This field is for validation purposes and should be left unchanged.

Register for access to Summer Sessions

This field is for validation purposes and should be left unchanged.
Name*
Privacy*