Clevi has created Software as a Service (SaaS) business models using large language models.
We will now introduce, one by one, the models created using Clevi’s large language models.
Software as a Service (SaaS) refers to a cloud-based business model in which software is provided as a service over the internet, without requiring installation.
Clevi’s representative SaaS models include Coding Agent, the natural-language-based workflow ARI, and the security agent (Red Team Testing).
Clevi Coding Agent
Next-generation AI Coding Agent
- Clevi Coding Agent is based on the latest LLM (cip-5-agent) and provides code understanding, generation, and analysis performance on par with Claude 4.5 Sonnet and OpenAI Codex
- Ensures high accuracy and consistency even with complex business logic, large-scale projects, and multimodule environments
Agentic AI Architecture
- Rather than a single AI, it uses a structure in which specialized agents for each role—including orchestration, architecture, coding, QA, review, and debugging—collaborate
- Each agent performs tasks through division of labour, automating and optimizing the overall development process
- AI takes the lead in processing the entire workflow, from requirements analysis, design, implementation, testing, code review, and debugging
Broad Programming Support and Practical Applicability
- Supports all currently developed languages and frameworks, including Python, Java, C/C++, Javascript, TypeScript, Go, and Rust
- Automates the entire development process, including code generation, automated refactoring, test code creation, bug detection and fixing, documentation, and code review
- Optimized for enterprise environments, including large-scale codebase analysis, legacy code migration, and automatic API documentation generation
On-Premises & SaaS Support
- SaaS (cloud API): Rapid adoption, no maintenance burden, and easy real-time collaboration and scalability
- On-premises (in-house deployment): Optimized for specific purposes such as security, data sovereignty, and regulatory compliance. Flexible selection is available according to the enterprise’s security policies, data location, and network environment
Compatibility with various IDEs and development environments
- Support for major IDE plugins and extensions, including Visual Studio Code, JetBrains series (IDEA, PuCharm, etc.), Eclipse, and Jupyter Notebook
- Easy integration with CI/CD pipelines, internal development portals, and custom tools through API/SDK formats
ARI (natural language-based workflow automation agent creation and management platform)
ARI is an intelligent agent creation platform that automatically designs, executes, and manages workflows using only natural language commands. By integrating CLEVI’s reasoning model family (cip-5-agent, cip-5-vision, ivy-4-mm, etc.), MCP (Model Context Protocol), external API integrations, and a plugin system, it automatically configures executable agent workflows as soon as a command is entered.
ARI workflow automation platform implementation built on the cip-5-agent model
Key features
- Natural language-based design: automatically generate and connect nodes with a single line, such as “Create a workflow that automatically writes reports”
- MCP, external API, and plugin integration: securely expose and call tools, data, and resources through standardized MCP, while easily extending functionality with internal/external APIs and third-party plugins
- Recursive Optimization: evaluate execution results to automatically modify or refactor node structures or generated code/parameters, continuously improving accuracy and efficiency
- Multimodal support: support text, image, and document input/output, with results provided as a visual node map for easy tracking and auditing
- Governance/security: support permissions, logging, and version history to ensure auditability and reproducibility in enterprise environments
Technical differentiation and value
- Compared with existing tools centred on manual node wiring, the agent independently performs the closed loop of “understanding the objective → planning → execution → result validation → automatic correction” (combining CTA, ToolCalling, and Semantic DB)
- Standardize tool/resource integration with MCP for high portability and scalability, providing the same development experience in both on-premises and SaaS environments
- Expand the scope of enterprise-wide automation through integrated control with Coding Agent, Physical AI, and On-prem solutions
Expected benefits
- Non-developers can naturally design and operate complex automations using natural language, while achieving both reduced operating costs and improved quality metrics (accuracy/processing time) through outcome-based recursive optimization
- Rapid expansion to new tasks/systems is possible by leveraging standard (MCP) and plugin ecosystems
Clevi Security Agent (Red Team Testing)
Clevi Purple Agent is an intelligent security agent that automatically updates the US CVE database daily to obtain the latest vulnerability information, then detects, verifies, and reports security vulnerabilities in internal networks, servers, networks, and applications through white-hat hacker methods (penetration testing and simulation) using only natural-language target specification (e.g., windows, web server, specific folder/file name). It supports the full lifecycle of automated detection → scenario validation → report generation and is designed to operate in on-premises and isolated network environments, making it suitable for regulation-sensitive industries such as public sector, finance, and manufacturing.
<clevi security agent GUI screen>
Key features
Automatic daily CVE feed synchronization
- Synchronizes US NVD/CVE sources and internal threat intelligence (collection pipeline) daily to maintain an up-to-date vulnerability list.
Natural-language target specification (simplified operator interface)
- Users can specify detection targets using natural language/simple keywords such as “windows”, “specific server:10.10.0.5”, and “/var/www/html” (e.g., providing the left-panel input method as a UI).
Simulated white-hat hacker validation engine (non-destructive)
- Safely simulates and validates the possibility of vulnerabilities in a sandbox/emulation environment (reproducing the vulnerability through an exploit attempt → without observing the impact) to determine whether vulnerabilities exist and assess their severity without disrupting actual services.
Automated reporting and prioritization
- Immediately sends summary notifications to administrators upon detection (email/Slack/ticket) and automatically generates PDF/HTML reports including vulnerability impact and priority (summary of vulnerable locations, reproduction conditions, and recommended actions).
Scenario and playbook integration (automatic response integration option)
- In approved environments, it can trigger the automatic execution of patch scenarios and temporary mitigations (applying defensive rules before patching). (Approval procedures according to operational policies are required.)
Integrated logging and SIEM integration
- Integrates system logs, detection logs, and report results with the SIEM/security portal to enable continuous monitoring and auditing.
Permissions, auditing, and governance
- All detection and validation activities are recorded with the account, authorization, and timestamp to support legal and regulatory audits.
Technical Differentiation and Value
Real-Time and Daily Currency
- A daily automated CVE/NVD update pipeline enables impact tracking immediately after a zero-day disclosure.
AI-Based Vulnerability Mapping
- AI matches targets specified in natural language with CVE descriptions (in English and Korean) to prioritize the likelihood of exposure (vulnerability fit) for the relevant systems.
Non-Destructive Simulation Architecture
- Safety is ensured by conducting validation in an “emulation sandbox” that does not interrupt customer services.
Enterprise Deployment Options
- Supports SaaS, on-premises, and isolated networks (SVCE), enabling compliance with public-sector and financial regulations.
Automated Reporting and Traceability
- Reduces operational risk through a complete audit trail (versions, history, and responsible personnel) from detection to validation to reporting.
Integrated Orchestration
- Integrates with ARI (workflow platform) and internal patch management and ticketing systems to automate the repeated PoC-to-patch-to-validation loop.
Expected Benefits (Business Impact)
Proactive Risk Reduction
- Prevents the risk of actual compromise by rapidly checking exposure to newly disclosed CVEs.
Improved Operational Efficiency
- Saves the security team time and labour by automating repetitive vulnerability checks and reporting tasks.
Strengthened Regulatory and Compliance Response
- Provides auditable assessment logs and reports aligned with regulatory requirements such as PIPA/CSAP.
Support for Rapid Decision-Making
- Enables rapid decisions on patching and mitigation priorities through impact-based priority reports.
Enquiries and Demo Requests: [email protected]
Copyright© 2025 Clevi Inc. All rights reserved.
