
How Tint keeps security current with a codebase that changes faster than ever

With our code base evolving faster than ever, CodeAnt's approach to security and vulnerability scanning is truly innovative and solving real pain points in the this new AI era

Jérôme Selles
Co-Founder, Tint AI (Series A, $25M+ Raised)
Tint is both an MGA running embedded insurance programs and the AI-native operating system that powers them, headquartered in San Francisco. Underwriting and rating, policy management, claims from first notice to payment, billing, and reporting, all in one environment. Partners include Turo, Guesty, Escapia, OwnerRez, uShip, CitizenShipper, Super Dispatch, Montway, and Deel.
CHALLENGE
Tint's code runs on other companies' front ends.
Embedded insurance means the quote, the bind, and the policy view happen inside the partner's product. Every integration is a piece of Tint's surface living on a domain Tint does not control, in front of an audience that never chose Tint directly. Behind those integrations sits the concentration: policyholder PII, payment and billing flows, claims files, and the rate and risk logic that is the commercial IP of every program on the platform.
And the codebase carrying all of it is moving faster than it ever has.
WHY CODEANT
The volume of code went up. Review capacity did not.
This is the actual shape of the AI era problem, and it is not that AI writes bad code. It is that a team can now produce far more of it than the same team can meaningfully review, while the consequences of a miss stay exactly where they were.
The standard answer is a scanner, and the standard result is a backlog nobody trusts. Ten thousand findings, no way to tell which of them an attacker could ever reach, and a security review that becomes a queue instead of a decision.
The reason ours escalates differently is the offensive side. The engine has already proven which of these patterns is genuinely exploitable in the wild, so it knows what to raise and what to leave alone. A finding arrives with a reason attached, not a severity label.
WHAT WE RAN
The defensive engine in the pull request across Tint's codebase. Vulnerability scanning that reviews what changed, in the place the engineer already is, with escalation informed by what the offensive engine has proven reachable in live environments
WHAT CHANGED

