Research

Clevi SaaS (Coding Agent, ARI, Red Team testing)

CLEVI has created Software as a Service (SaaS) business models using large language models.

CLEVI has created Software as a Service (SaaS) business models using large language models.

From now on, we will introduce, one by one, the models created using CLEVI's large language models.

First, Software as a Service (SaaS) refers to a cloud-based business model in which software is provided as a service over the internet, without the need to install it.

CLEVI's representative SaaS models include Coding Agent, the natural-language-based workflow ARI, and the security agent (Red Team testing).

Clevi Coding Agent (CLEVI Coding Agent)

Image in the body

Next-generation AI Coding Agent

  • Clevi Coding Agent is based on the latest LLM (cip-5-agent) and provides code understanding, generation and analysis performance equivalent to Claude 4.5 Sonnet and OpenAI Codex
  • Ensures high accuracy and consistency even with complex business logic, large-scale projects and multimodule environments

Agentic AI architecture

  • Rather than a single AI, it uses a structure in which specialised agents for each role—including orchestration, architecture, coding, QA, review and debugging—work together
  • Each agent performs its assigned tasks and automates and optimises the overall development process
  • AI takes the lead in handling the entire process, from requirements analysis, design, implementation, testing, code review and debugging

Broad programming support and practical applicability

  • Supports all currently developed languages and frameworks, including Python, Java, C/C++, Javascript, TypeScript, Go and Rust
  • Automates the entire development process, including code generation, automated refactoring, test code creation, bug detection and fixing, documentation and code review
  • Optimised for enterprise environments, including large-scale codebase analysis, legacy code migration and automatic API documentation generation

On-premises & SaaS support

  • SaaS (cloud API): quick adoption, no maintenance burden, and easy real-time collaboration and scalability
  • On-premises (in-house deployment): optimised for specialised purposes such as security, data sovereignty and regulatory compliance. Can be selected flexibly according to the organisation's security policies, data location and network environment

Compatibility with various IDEs and development environments

  • Support for major IDE plugins and extensions, including Visual Studio Code, JetBrains IDEs (IDEA, PuCharm, etc.), Eclipse and Jupyter Notebook
  • Can be easily integrated into CI/CD pipelines, internal developer portals and custom tools in API/SDK form

ARI (natural language-based workflow automation agent creation and management platform)

ARI is an intelligent agent creation platform that automatically designs, executes and manages workflows using only natural language commands. By integrating CLEVI’s reasoning model family (cip-5-agent, cip-5-vision, ivy-4-mm, etc.) with MCP (Model Context Protocol), external API integration and a plugin system, it automatically configures executable agent workflows as soon as a command is entered.

Main image

ARI workflow automation platform implementation scene built on the cip-5-agent model

Key features

  • Natural language-based design: nodes are automatically generated and connected with a single line, such as “Create a workflow to write reports automatically”
  • MCP, external API and plugin integration: standardised MCP securely exposes and calls tools, data and resources, while internal/external APIs and third-party plugins can be easily extended
  • Recursive Optimisation: evaluates execution results to automatically modify or refactor node structures or generated code/parameters, continuously improving accuracy and efficiency
  • Multimodal support: supports text, image and document input/output, while results are provided as a visual node map for easy tracking and auditing
  • Governance/security: supports permissions, logging and version history to ensure auditability and reproducibility in enterprise environments

Technical differentiation and value

  • Compared with existing tools centred on manual node wiring, the agent independently performs the closed loop of “understanding the objective → planning → execution → validating results → automatic correction” (combining CTA, ToolCalling and Semantic DB)
  • Standardises tool/resource integration with MCP, providing high portability and scalability, as well as the same development experience across on-premises and SaaS environments
  • Expands the scope of enterprise-wide automation through integrated control of Coding Agent, Physical AI and On-prem solutions

Expected benefits

  • Non-developers can naturally design and operate complex automations using natural language, while achieving both reduced operating costs and improved quality metrics (accuracy/processing time) through outcome-based recursive optimisation
  • Rapid expansion to new tasks/systems is possible by leveraging the standard (MCP) and plugin ecosystem

Clevi security agent (red team testing)

Clevi Purple Agent is an intelligent security agent that automatically updates the US CVE database daily to obtain the latest vulnerability information and, based on this, detects, validates and reports security vulnerabilities in internal networks, servers, networks and applications using white-hat hacking methods (penetration testing, simulation) through natural-language target specification alone (e.g. Windows, web server, specific folder/file name). It supports the entire lifecycle of automated detection → scenario validation → report generation and is designed to operate in on-premises and isolated-network environments, making it suitable for regulation-sensitive industries such as public-sector organisations, finance and manufacturing.

Body image

<CLEVI security agent GUI screen>

Key features

Daily automatic CVE feed synchronisation

  • Synchronises US NVD/CVE sources and internal threat intelligence (collection pipeline) daily to maintain an up-to-date vulnerability list.

Natural-language target specification (simplified operator interface)

  • Users can specify detection targets using natural language/simple keywords such as “Windows”, “specific server:10.10.0.5” and “/var/www/html” (e.g. the left-panel input method is provided as a UI)

Simulated white-hat validation engine (non-destructive)

  • Safely validates the possibility of vulnerabilities in a sandbox/emulation environment (reproducing the vulnerability through an exploit attempt → without observing the impact) to determine whether vulnerabilities exist and their risk level without interrupting actual services.

Automatic reporting and prioritisation

  • Immediately sends summary notifications to administrators upon detection (email/Slack/ticket) and automatically generates PDF/HTML reports including vulnerability impact and priority (summary of vulnerable location, reproduction conditions and recommended actions)

Scenario and playbook integration (automatic action integration option)

  • In approved environments, can trigger the automatic execution of patch scenarios and temporary mitigations (applying defence rules before patching). (Approval procedures in accordance with operational policies are mandatory)

Integrated logging and SIEM integration

  • Integrates system logs, detection logs and report results with the SIEM/security portal to enable continuous monitoring and auditing

Permissions, auditing and governance

  • All detection and verification activities are recorded with the account, approval and timestamp to prepare for legal and regulatory audits.

Technical differentiation and value

Real-time and daily currency

  • A daily automated CVE/NVD update pipeline enables impact tracking immediately after a ‘zero-day disclosure’.

AI-based vulnerability mapping

  • AI matches the targets specified in natural language with CVE technical descriptions (in English and Korean) to prioritise the likelihood of exposure (vulnerability relevance) for the relevant systems.

Non-destructive simulation architecture

  • Safety is ensured through validation in an ‘emulation sandbox’ that does not cause customer service interruptions.

Enterprise deployment options

  • Supports SaaS, on-premises and isolated networks (SVCE), enabling compliance with public-sector and financial regulations.

Automated reporting and traceability

  • Reduces operational risk through a complete audit trail (versions, history and responsible personnel) from detection → verification → reporting.

Integrated orchestration

  • Integrates with ARI (workflow platform) and internal patch management and ticketing systems to automate the repeated PoC → patch → verification loop.

Expected benefits (business impact)

Proactive risk reduction

  • Rapid exposure checks for newly disclosed CVEs help prevent the risk of actual compromise in advance.

Improved operational efficiency

  • Automating repetitive vulnerability checks and reporting reduces the time and manpower required from security teams.

Enhanced regulatory and compliance response

  • Provides auditable inspection logs and reports aligned with regulatory requirements such as PIPA/CSAP.

Faster decision-making support

  • Impact-based priority reports enable the rapid determination of patching and mitigation priorities.

Enquiries and demo requests: [email protected]

Copyright© 2025 Clevi Inc. All rights reserved.

Back to newsroom
CLEVI

Language and region

Machine-translated languages are marked. Availability follows the published site bundle.

136 languages

Recommended

1

East Asia

7

Southeast Asia

11

South Asia

18

Central Asia

5

Middle East and the Caucasus

10

Western and Southern Europe

16

Britain and Ireland

4

Northern Europe and the Baltics

10

Central Europe and the Balkans

14

Eastern Europe

5

East Africa and the Horn

8

West and Central Africa

9

Southern Africa

8

The Americas

5

The Pacific

5