
How Toma runs security at the speed it onboards dealerships

The depth of CodeAnt's automated offensive security is unlike anything we've seen. They don't just flag issues, they show you exactly what's at risk.

Monik Pamecha
Co-Founder and CEO, Toma(Series A, $17M+ raised, led by a16z)
Toma's agents answer the phone for car dealerships. Booking service appointments, handling parts orders, fielding sales inquiries.
CHALLENGE
Live PII, payment context, and a direct line into dealer management systems.
Dealerships are not staffed with security teams. There is no counterparty doing a second review. The trust sits entirely with Toma.
WHY CODEANT
New dealerships onboard every month, and each one is new surface.
Toma wanted a security program that runs at the speed they ship. That means the offensive side has to be permanent rather than annual, and the defensive side has to inherit everything it learns.
Attack surface management across every environment their agents touch. Shadow IT discovery. Monitoring for leaked credentials and session tokens. Above all, findings they could act on rather than a severity spreadsheet.
WHAT WE RAN
Each finding tied to the specific data and system it puts at risk, with a reproducible proof of concept attached. Then the fix enforced in code, so it stays fixed.
WHAT CHANGED

