Bajaj Finserv Health: 300+ Developers Secure Code in
Seconds with CodeAnt AI

Amartya Jha

Aug 24, 2026

CodeAnt AI helped us consolidate quality and security checks directly into our development workflow, without adding friction for engineering teams.

Yogessh Karape 

CISO, Bajaj Finserve (Large Enterprise)

In this Case Study

No headings found on page

Bajaj Finserv Health is a leading digital healthcare platform serving millions of users. Its growing product suite, complex integrations, and 300-developer engineering organization needed to ship faster without compromising security, quality, or compliance.

CHALLENGE

Multiple tools, slow reviews, and incomplete visibility

As the platform expanded, every pull request required hours of manual review alongside legacy scanning tools. False positives created noise, and developers spent time chasing non-issues instead of shipping product.

Security and quality controls were fragmented:

  • Code-quality checks and security checks ran in separate workflows.

  • Vulnerabilities in code and third-party dependencies required separate investigation.

  • There was no centralized enforcement of quality and security gates before merge.

  • Compliance reporting required manually compiling evidence across tools.

  • Pricing based on lines of code made annual spend harder to forecast as the codebase grew.

Bajaj Finserv Health needed one platform that could operate inside Azure DevOps, cover both application quality and security, and give leadership a clearer view of engineering risk.

WHY CODEANT

One platform for secure, compliant software delivery

CodeAnt AI brought AI code review, code quality, and application security into the existing Azure DevOps workflow.

For every pull request, CodeAnt AI provides:

  • SAST to identify code-level security issues.

  • SCA and SBOM visibility to identify vulnerable third-party dependencies and understand package usage.

  • Secret detection and IaC misconfiguration checks alongside code-quality rules.

  • AI-powered PR reviews, summaries, and suggested fixes directly in Azure DevOps.

  • Quality and security gates that prevent merges when defined policies are not met.

  • Exportable audit reports for release and compliance reviews.

  • Leadership dashboards for engineering quality, security risk, test coverage, and bottlenecks.

WHAT WE RAN

AI code review, quality, and security on every PR

PR-native workflow: Engineers receive review notes, summaries, and suggested fixes directly in Azure DevOps, without switching tools or changing their existing workflow.

Smarter signals, less noise: Code-quality scanning across anti-patterns, cyclomatic complexity, dead code, and duplicate code reduced noise while surfacing actionable issues earlier.

Built-in application security: SAST, SCA, secret detection, and IaC checks run automatically alongside quality rules on every pull request.

Centralized governance and compliance: Quality gates, Azure Board ticket linking, and exportable PDF and Excel reports make every release more reviewable and auditable.

Predictable pricing: Flat per-developer pricing gave the organization clearer cost visibility as engineering teams and codebases scaled.

THE MIGRATION

One platform, same workflow.

Bajaj Finserv Health replaced SonarCloud and manual review checks with CodeAnt AI.

Historical modules were brought under the same quality and security policies. Organization-wide controls now run automatically on every pull request, while Azure DevOps pipelines, permissions, and boards remained unchanged.

WHAT CHANGED

CodeAnt AI enabled Bajaj Finserv Health to:

  • Reduce pull-request review time from hours to seconds for 300+ developers.

  • Consolidate code quality and application-security checks in one Azure DevOps-native platform.

  • Enforce consistent quality and security policies before code is merged.

  • Improve visibility into code, dependencies, security findings, and release risk.

  • Produce audit and compliance evidence without manually aggregating data across tools.

  • Move away from unpredictable lines-of-code pricing toward predictable per-developer pricing.

[GET STARTED]