Clevi has created SaaS (Software as a Service) business models using large language models.
We will now introduce, one by one, the models created by Clevi using large language models.
SaaS (Software as a Service) refers to a cloud-based business model in which services are provided over the internet without installing software.
Clevi’s representative SaaS models include Coding Agent, the natural language-based workflow ARI, and the security agent (red team testing).
Clevi Coding Agent
Next-generation AI coding agent
- Clevi Coding Agent is based on the latest LLM (cip-5-agent) and provides code comprehension, generation and analysis performance on par with Claude 4.5 Sonnet and OpenAI Codex
- Ensures high accuracy and consistency even with complex business logic, large-scale projects and multimodule environments
Agentic AI architecture
- A structure in which specialised agents for each role, including orchestration, architecture, coding, QA, review and debugging, collaborate rather than relying on a single AI
- Each agent performs its assigned tasks and automates and optimises the overall development process
- AI proactively handles the entire process, from requirements analysis, design, implementation, testing, code review and debugging
Broad programming support and practical applicability
- Supports all currently developed languages and frameworks, including Python, Java, C/C++, Javascript, TypeScript, Go and Rust
- Automates the entire development process, including code generation, automatic refactoring, test code creation, bug detection and fixing, documentation and code review
- Optimised for enterprise environments, including large-scale codebase analysis, legacy code migration and automatic API documentation generation
On-premises & SaaS support
- SaaS (cloud API): Fast adoption, no maintenance burden, and easy real-time collaboration and scalability
- On-premises (in-house deployment): Optimised for specialised purposes, including security, data sovereignty and regulatory compliance. Flexible selection based on the organisation’s security policies, data location and network environment
Compatibility with various IDEs and development environments
- Support for plugins and extensions for major IDEs, including Visual Studio Code, JetBrains products (IDEA, PuCharm, etc.), Eclipse and Jupyter Notebook
- Easy integration in API/SDK form with CI/CD pipelines, internal development portals and custom tools
ARI (natural language-based workflow automation agent creation and management platform)
ARI is an intelligent agent creation platform that automatically designs, executes and manages workflows using only natural language commands. By integrating CLEVI’s reasoning model family (cip-5-agent, cip-5-vision, ivy-4-mm, etc.), MCP (Model Context Protocol), external API integrations and a plugin system, it automatically configures executable agent workflows as soon as a command is entered.
ARI workflow automation platform implementation built on the cip-5-agent model
Key features
- Natural language-based design: nodes are automatically generated and connected from a single line, such as “Create a workflow that automatically generates reports”
- MCP, external API and plugin integration: securely expose and call tools, data and resources through standardised MCP, while easily extending with internal/external APIs and third-party plugins
- Recursive Optimisation: evaluates execution results to automatically modify or refactor node structures or generated code/parameters, continuously improving accuracy and efficiency
- Multimodal support: supports text, image and document input/output, with results provided as a visual node map for easy tracking and auditing
- Governance/security: supports permissions, logging and version history to ensure auditability and reproducibility in enterprise environments
Technical differentiation and value
- Compared with existing tools centred on manual node wiring, the agent independently performs the closed loop of “understanding the objective → planning → execution → result verification → automatic correction” (combining CTA, ToolCalling and Semantic DB)
- Standardises tool/resource integration through MCP, providing high portability and extensibility, as well as the same development experience in both on-premises and SaaS environments
- Expands the scope of enterprise-wide automation through integrated control with Coding Agent, Physical AI and on-premises solutions
Expected benefits
- Non-developers can design and operate complex automation using natural language, while achieving both reduced operating costs and improved quality metrics (accuracy/processing time) through outcome-based recursive optimisation
- Rapid expansion to new tasks/systems is possible by leveraging the standard (MCP) and plugin ecosystems
Clevi Security Agent (Red Team Testing)
Clevi Purple Agent is an intelligent security agent that automatically updates the US CVE database daily to obtain the latest vulnerability information, then detects, validates and reports security vulnerabilities in internal networks, servers, networks and applications through white-hat hacker methods (penetration testing and simulation), using only natural-language target specification (e.g. windows, web server, or a specific folder/file name). It supports the entire lifecycle of automated detection → scenario validation → report generation, and is designed to operate in on-premises and isolated-network environments, making it suitable for regulation-sensitive industries such as the public sector, finance and manufacturing.
<Clevi security agent GUI screen>
Key features
Daily automatic CVE feed synchronisation
- The latest vulnerability list is maintained by synchronising US NVD/CVE sources and internal threat intelligence (collection pipeline) daily.
Natural-language target specification (simplified operator interface)
- Users can specify detection targets using natural language/simple keywords such as “windows”, “specific server:10.10.0.5” and “/var/www/html” (e.g. the left-panel input method is provided as a UI)
Simulated white-hat hacker validation engine (non-destructive)
- Potential vulnerabilities are simulated and validated in a secure sandbox/emulation environment (reproducing the vulnerability through an exploit attempt → without observing the impact), enabling the presence and severity of vulnerabilities to be assessed without interrupting actual services.
Automated reporting and prioritisation
- Summary notifications are sent to administrators immediately upon detection (email/Slack/ticket), and PDF/HTML reports containing vulnerability impact and prioritisation are automatically generated (summary of the vulnerable location, reproduction conditions and recommended actions)
Scenario and playbook integration (automated remediation integration option)
- In approved environments, automatic execution of patching scenarios and temporary mitigation (applying defensive rules before patching) can be triggered. (Approval procedures in accordance with operational policies are mandatory)
Integrated logging and SIEM integration
- System logs, detection logs and report results can be integrated with SIEM/security portals for continuous monitoring and auditing
Permissions, auditing and governance
- All detection and verification activities are recorded with the account, authorisation and timestamp to prepare for legal and regulatory audits.
Technical Differentiation and Value
Real-Time and Daily Currency
- A daily automated CVE/NVD update pipeline enables impact tracking immediately after a zero-day disclosure.
AI-Based Vulnerability Mapping
- AI matches targets specified in natural language with CVE technical descriptions (in English and Korean) to prioritise the likelihood of exposure (vulnerability relevance) for the relevant systems.
Non-Destructive Simulation Architecture
- Safety is ensured through verification in an ‘emulation sandbox’ that does not cause customer service disruptions.
Enterprise Deployment Options
- Supports SaaS, on-premises and isolated networks (SVCE), enabling compliance with public-sector and financial regulations.
Automated Reporting and Traceability
- Operational risk is reduced through a complete audit trail (versions, history and responsible personnel) from detection to verification to reporting.
Integrated Orchestration
- Integrates with ARI (workflow platform) and internal patch management and ticketing systems to automate the iterative PoC→patch→verification loop.
Expected Benefits (Business Impact)
Proactive Risk Reduction
- Rapid exposure checks for newly disclosed CVEs help prevent actual breach risks in advance.
Improved Operational Efficiency
- Automating repetitive vulnerability assessment and reporting tasks reduces the time and personnel required by security teams.
Enhanced Regulatory and Compliance Response
- Provides auditable assessment logs and reports aligned with regulatory requirements such as PIPA and CSAP.
Support for Rapid Decision-Making
- Impact-based priority reports enable rapid decisions on patching and mitigation priorities.
Enquiries and demo requests: [email protected]
Copyright© 2025 Clevi Inc. All rights reserved.
