Skip to main content

Seeking Alpha Testers for Takumi ASM

· 3 min read
Takashi Yoneuchi
CTO @ GMO Flatt Security Inc.

We are seeking alpha testers for the upcoming Attack Surface Management (ASM) capability in Takumi. The alpha test is free and focuses on discovering internet-facing assets associated with your domains from publicly available information.

Takumi ASM alpha tester recruitment

Takumi Runner Now Supports Threat Detection

· 2 min read
Rio Nishimori
Software Engineer @ GMO Flatt Security Inc.

Takumi Runner now provides threat detection, which proactively detects threats in CI/CD pipelines. When a supply-chain incident occurs — like the ones Takumi Guard has reported on in the past — we promptly investigate the trace data collected through Takumi Runner or cicd-sensor, and immediately notify you when a threat is detected.

Responding to a supply-chain incident: before vs. with threat detection

Takumi Graybox Assessment Now Available

· 2 min read
Tsubasa Umeuchi
Software Engineer @ GMO Flatt Security Inc.

Takumi now supports graybox assessment.

Specify both your source code and the URL of the application running that code. Takumi analyzes the code to enumerate candidate vulnerabilities and attacks the running application, then reports only the ones it manages to reproduce as findings.

Graybox assessment feature

Request to Update the AWS RDS Review Workflow in CSPM

· 3 min read
Yoshiaki Matsutomo
Software Engineer @ GMO Flatt Security Inc.

Due to express configuration, a way of creating Aurora clusters without a VPC that AWS introduced in March 2026, we identified that the managed review item "Ensure that RDS instances are deployed in a VPC" (RDS.18) provided by Flatt Security could not judge instances in this configuration correctly.

We have published a workflow that addresses this issue, so please update yours.

Bot Trust Conditions Now Support Custom OIDC Providers

· 3 min read
Takashi Yoneuchi
CTO @ GMO Flatt Security Inc.

Bot trust conditions now accept ID tokens from any identity provider that complies with OIDC Discovery, not just GitHub Actions and GitLab CI.

Self-hosted CI/CD systems such as Jenkins, Buildkite, and CircleCI, another cloud's workload identity federation, GitHub Enterprise Server, and self-managed GitLab can all sign in as a bot without a static API key.

info

Custom OIDC provider support is currently in beta. Specifications and behavior may change without prior notice.

Takumi AI Penetration Testing Availability Expanded

· 2 min read
Tsubasa Umeuchi
Software Engineer @ GMO Flatt Security Inc.

We are expanding access to AI Penetration Testing, which we began rolling out on June 15, 2026, to more customers. The feature verifies whether a given objective is achievable, from the perspective of a real attacker.

Set a target and a concrete objective — such as accessing user data — and Takumi autonomously chains reconnaissance, vulnerability discovery, and exploitation.

The feature is not yet available to all customers, so if you'd like to use it, register from the application page.

AI Penetration Testing Availability Expanded