Sigrid® Core

The control center for your entire software portfolio.

Security, productivity, compliance, ROI and AI impact. Measured, benchmarked and under control.

40,000+

Systems benchmarked

ISO/IEC 17025

Accredited software quality lab

Gartner® Leader

Magic Quadrant™ 2026

Sigrid Core · Portfolio overview
Sigrid Core Portfolio Overview: Acme Portfolio maintainability ratings, objective progress, and hotspots treemap

Trusted by architects and engineering leaders worldwide

  • Philips
  • ING
  • Siemens
  • NXP
  • KLM
  • Konecranes
Gartner® Leader

Named a Leader in the 2026 Gartner® Magic Quadrant™ for Technical Debt Management Tools.

Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.

Access the full report →

Features

Sigrid Core

One standard across every system in your portfolio: maintainability, architecture, security, and open source health, with reporting that's ready for the board.

  • Maintainability overview across every system
  • Architecture as-is view and drift detection
  • Security exposure across the portfolio
  • Open source health, licences and dependency risk
  • Automatic management reports, board-ready
  • Custom objective setting per system or portfolio

Foundation ISO/IEC 25010 quality model · ISO/IEC 17025 accredited lab · benchmarked against 40,000+ real-world systems.

app.sigrid-says.com / Acme Portfolio / Security

Acme Portfolio

Showing 61 / 65 systems

Findings

589

Also showing 22 informational findings.

Security

★☆☆☆☆ (1.4)

Model version: 2025

Security benchmark is a new feature that enables you to compare your security hygiene against 50% benchmark. Click here to learn more

CVSS severity

39Critical
117High
433Medium
0Low

Activity

18New
542Recurring
29Resolved

CVSS severity benchmark

Based on deployment type: Public-facing  ⓘ

Grouping: Model › OWASP Top 10 (2021)

Low High Impact
Sorting: Description
Add finding Export as CSV
DescriptionFindings
A1 Broken Access Control H 5M 76L 6
A2 Cryptographic Failures H 13M 5
A3 Injection C 25H 22M 22
A4 Insecure Design M 5

The proof

Outcomes customers take to the board.

4.5×

Faster time to market after reducing technical debt with Sigrid Core

Sigrid Core customer outcomes

"Sigrid helps us keep control of technical debt and identify where we need to put our focus. The benchmarks are key — they give us an objective view that we can bring straight to the board."
Rabobank
Harald ThoonenSolutions Architect · Rabobank
Read the story
  • −97%

    Fewer high-risk security findings with Guardrails on

    SIG testing, 2026

  • +24%

    Higher maintainability score with Guardrails on

    SIG testing, 2026

  • −50%

    Lower software maintenance cost

    Sigrid Core customer outcomes

  • +30%

    More development capacity freed up

    Sigrid Core customer outcomes

  • 2×

    Fewer security vulnerabilities in production

    Sigrid Core customer outcomes

  • 3.9 → 0.9

    Review comments per pull request, before and after Sigrid Guardrails

    SIG partner testing, 2026

One platform, every level

Built for every level of your organization.

Management Dashboard Showing changes between 1 Oct 2025 and 29 Sep 2026 Security Quality Effectiveness and Control How your portfolio compares to the market (SIG benchmark) Security View details 4.0 ★ Better than industry average 46% less prone to data breaches Open Source Health View details 4.3 ★ Better than industry average 62% less prone to license violations Open and resolved findings Acute (Critical + High) There are 94 open security findings 6133553 NewExistingResolved Are you keeping pace with security findings? New findings Resolved findings AprMayJunJulAugSep

C-suite & Boards

Executive reports, portfolio KPIs, business impact, all from the same data as the rest of the team.

customer-portal Architecture quality · ★★★ 3.1 Structure Communication Data access Evolution Knowledge web-ui api-gw orders payments auth shared postgres Undesired dependency auth → shared, 37 calls System properties Component coupling★★ Component cohesion★★★★ Communication centr.★★★ Data coupling★★★★ Knowledge distribution★★ Dependency risk 3 libraries with known CVEs 11 components not touched in 12m

Architects

Architecture visualization, system-level analysis, dependency risk, and a high-level quality overview.

Findings customer-portal · Maintainability · 47 refactoring candidates Refactoring candidates Security Objectives Delta quality Unit complexity · McCabe 42 OrderService.java : calculateTotals() Unit size · 188 LOC CheckoutController.java : submit() Duplication · 3 clones, 61 lines PriceMapper.java, TaxMapper.java Unit interfacing · 7 parameters InvoiceBuilder.java : build() Module coupling · fan-in 34 Money.java OrderService.java CheckoutController.java 41public Totals calculateTotals(Order o) { 42 if (o.isB2B() && o.region() == EU) { 43 for (Line l : o.lines()) { 44 if (l.vatExempt()) { ... } Sigrid MCP connected · reads live findings Which finding blocks the Q4 objective? calculateTotals() has complexity 42 and sits on the checkout path. Splitting the EU/VAT branch into its own method lifts unit complexity from ★★ to ★★★★. Open finding in Sigrid →

Developers

Detailed findings, objectives, code-level metrics, and Sigrid MCP directly in the IDE.

The Sigrid difference: our approach

Many tools will tell you what "good" looks like. Only Sigrid can prove it.

Sigrid assesses your code against deterministic rules, calibrated on 40,000+ real systems in the context of your own architecture.

It's the engine behind each Sigrid product: Core across your portfolio, Axis inside your coding agents.

Explore our methodologyHow the Sigrid standard works — PDF, instant download

  • 01

    Deterministic, globally-recognized standards

    Quality standards refined for 25+ years in the world's only ISO/IEC 17025-accredited software quality lab — not a prompt, not another model's opinion.

  • 02

    Benchmarked against 40,000+ real systems

    "Good" isn't abstract. It's what the largest software benchmark in the world says good looks like for a system like yours.

  • 03

    Architecture-aware: catches problems before merge

    Every check understands what your system is meant to look like. It catches the drift and erosion that may be harmless in isolation but wrong in your codebase.

Sigrid — Integrations
// Integrations

Sigrid meets you where your team already works

Powered by Sigrid CI

Pipeline integration for any environment — block merges that don't meet quality standards, surface findings directly in pull requests.

View Sigrid CI docs

Demo

See Core at Work

Deep dive into how Core works in practice from portfolio-wide maintainability and architecture drift to security exposure, open source health, and board-ready management reporting.

Agentic SDLC Governance

Go deeper into your agentic SDLC with Sigrid Axis

Embed Sigrid Core's insights and context into your agentic SDLC. Prevent architecture drift, erosion, quality, and security issues the moment your AI agent writes them — not after they ship.

Explore Sigrid Axis

Quick Scans · Powered by Sigrid® Core

Not ready for a subscription? Start with a scan.

Fixed-price, one-time diagnostics on the same engine and benchmark as Sigrid Core. No onboarding, no commitment.

  • Technical Debt Scan

    Up to 5 systems · Fixed price

    Request scan
  • Security Scan

    Full portfolio · Fixed price

    Request scan
  • Product Risk & Value Scan

    One product · Fixed price

    Request scan

Get started with Core

Request a free trialWatch the demo

Frequently asked questions

How does Sigrid Core measure code quality?

Sigrid Core compares your source code against a benchmark of 40,000+ industry systems and more than 600 billion lines of code, recalibrated every year to reflect the current state of software development, covering old and new technologies, legacy and modern frameworks alike. Because the benchmark is technology-independent, you can compare a COBOL system and a React app on the same scale, normalized to how much developer effort each represents. The result is a 1–5 star rating from our quality models that shows how your code compares to the rest of the market.

What does the star rating actually mean?

3 stars marks the market average, the point where most systems land. The scale follows a fixed 5%–30%–30%–30%–5% split, so 3 stars covers a defined middle band (2.5–3.5), with the bottom 5% at 1 star and the top 5% at 5. Scores always round down, never up. A 4.49 stays at 4 stars instead of rounding up, and a fractional score like 3.4 means "solid, upper end of average" rather than "almost a 4."

What is software architecture, and why does Sigrid Core measure it?

Software architecture is how a codebase is divided into components based on responsibility, and how those components depend on each other. It's the layer where individual functions and files stop mattering and the relationships between them start to matter, because that's where the expensive problems live. A single messy function costs a few hours to fix. A codebase where everything depends on everything else costs months, and by the time it's visible, a routine change breaks something three systems away.

How does Sigrid Core measure architecture quality specifically?

Five categories, nine measurable properties in our architecture quality model: structure, communication, data access, evolution, and knowledge. These cover code breakdown, component coupling, component adjacency, component cohesion, communication centralization, data coupling, bounded evolution, knowledge distribution, and component freshness. All nine come from static code analysis and repository history, measuring how the architecture actually behaves rather than how a diagram says it should.

How is Sigrid Core's security assessment different from a penetration test?

Sigrid Core looks from the inside out, examining the source code and infrastructure itself rather than probing the system from the outside. That gives it high predictive value for finding why a vulnerability exists, which complements rather than replaces external pen testing. Findings are scored with CVSS and mapped to the OWASP Top 10, so you get both the severity and the specific risk category.

What does the security star rating mean?

It's a 1–5 scale from our security model reflecting how well security best practices are built into the design and implementation, from severely low controls at 1 star to a high degree of control at 5. Even a 5-star rating isn't a guarantee of zero vulnerabilities. It means security was systematically factored into design and implementation.

What security standards does Sigrid Core align with?

OWASP ASVS, OWASP Top 10, NIST SP800-53, PCI-DSS, CIS/SANS Top 20, and CWE, all underpinned by ISO/IEC 25010's security model, grouped into confidentiality and integrity, non-repudiation and accountability, and authenticity. Sigrid Core acts as a gateway into these frameworks, surfacing where your code falls short and which standard that shortfall maps to.

What can I actually see on the Management Dashboard?

A portfolio-level view that turns technical signals into business questions: where you have acute risk that needs attention now, where to prioritize next, and whether you're on track against the targets you've set. Security posture, technical debt, IT spend, development activity, and productivity all roll up into KPIs a CIO or board can act on without translating them first.

What are objectives in Sigrid Core?

Targets you set for where your systems should be: desired maintainability, new-code quality, minimum test coverage, or maximum tolerated vulnerabilities in a library. Apply them to whichever group of systems shares a trait you care about (technology, business criticality, lifecycle stage). Once set, every system in that group is measured against the target automatically, so drift shows up before it becomes a conversation you have to start yourself.

How does Sigrid Core help manage open-source library risk across a portfolio?

One view answers the questions that usually take a spreadsheet and a Slack thread to piece together: which libraries are in use across the whole portfolio, which systems are running versions with known CVEs, which teams have fallen behind your version policy, and exactly which systems are exposed if a library like Log4j turns out to be compromised. Portfolio-wide, not system by system.

Who is Sigrid Core actually built for?

Whoever's asking has a different question. Executives and portfolio managers want a landscape-level view of risk and health to steer investment, and enterprise architects get that same view plus the ability to drill into any system for root cause. Product owners track delivery predictability over time. Developers want the specifics: which components are hardest to change, and why. One dataset, four sets of answers.

Can you easily export reports?

Yes, generated reports export as PowerPoint or Word, so the numbers can slot straight into a board deck, a steering committee update, or an audit trail without anyone re-typing anything. You can pull a snapshot of current state, a change report showing how metrics moved over a period, or a process/metadata report, and share or archive it offline.

Read our methodology

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

Watch Core in action

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

Watch Axis in action

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

This field is for validation purposes and should be left unchanged.
Name*
What type of partnership are you interested in?*
Privacy*

Register for access to Summer Sessions

This field is for validation purposes and should be left unchanged.
Name*
Privacy*