Research

Clevi SaaS (Coding Agent, ARI, Red Team Testing)

Clevi has created SaaS (Software as a Service) business models using large language models.

Clevi has created SaaS (Software as a Service) business models using large language models.

From now on, we will introduce, one by one, the models created using Clevi's large language models.

First, SaaS (Software as a Service) refers to a cloud-based business model in which services are provided over the internet rather than requiring software installation.

Clevi's representative SaaS models include Coding Agent, the natural language-based workflow ARI, and the security agent (Red Team Testing).

Clevi Coding Agent (Clevi Coding Agent)

Main image

Next-generation AI Coding Agent

  • Clevi Coding Agent is based on the latest LLM (cip-5-agent) and provides code understanding, generation, and analysis performance on par with Claude 4.5 Sonnet and OpenAI Codex
  • Ensures high accuracy and consistency even with complex business logic, large-scale projects, and multi-module environments

Agentic AI Architecture

  • Rather than a single AI, it uses a collaborative structure in which specialised agents handle roles such as orchestration, architecture, coding, QA, review, and debugging
  • Each agent performs its assigned tasks, automating and optimising the overall development process
  • AI proactively handles the entire process, from requirements analysis, design, implementation, testing, code review, and debugging

Broad Programming Support and Practical Applicability

  • Supports all currently developed languages and frameworks, including Python, Java, C/C++, Javascript, TypeScript, Go, and Rust
  • Automates the entire development process, including code generation, automated refactoring, test code creation, bug detection and fixing, documentation, and code review
  • Optimised for enterprise environments, including large-scale codebase analysis, legacy code migration, and automated API documentation generation

On-Premises & SaaS Support

  • SaaS (Cloud API): Quick adoption, no maintenance burden, and easy real-time collaboration and scalability
  • On-premises (in-house deployment): Optimised for specialised purposes such as security, data sovereignty, and regulatory compliance. Can be selected flexibly based on the company's security policies, data location, and network environment

Compatibility with various IDEs and development environments

  • Support for plugins and extensions for major IDEs, including Visual Studio Code, JetBrains series (IDEA, PuCharm, etc.), Eclipse and Jupyter Notebook
  • Easy integration with CI/CD pipelines, internal developer portals and custom tools through APIs/SDKs

ARI (natural language-based workflow automation agent creation and management platform)

ARI is an intelligent agent creation platform that automatically designs, executes and manages workflows using only natural language commands. By integrating CLEVI's reasoning model family (cip-5-agent, cip-5-vision, ivy-4-mm, etc.), MCP (Model Context Protocol), external API integrations and a plugin system, it automatically configures executable agent workflows as soon as a command is entered.

Body image

ARI workflow automation platform built on the cip-5-agent model

Key features

  • Natural language-based design: Automatically generates and connects nodes with a single instruction, such as “Create a workflow to write reports automatically”
  • MCP, external API and plugin integration: Safely exposes and invokes tools, data and resources through standardised MCP, while easily extending integration with internal/external APIs and third-party plugins
  • Recursive Optimisation: Evaluates execution results to automatically modify or refactor node structures, generated code or parameters, continuously improving accuracy and efficiency
  • Multimodal support: Supports text, image and document input/output, and provides results as a visual node map for easy tracking and auditing
  • Governance/security: Supports permissions, logging and version history to ensure auditability and reproducibility in enterprise environments

Technical differentiation and value

  • Unlike existing tools centred on manual node wiring, the agent independently performs the closed loop of “understanding the objective → planning → execution → result verification → automatic correction” (combining CTA, ToolCalling and Semantic DB)
  • Standardises tool/resource integration through MCP, providing high portability and scalability, along with the same development experience across both on-premises and SaaS environments
  • Expands the scope of enterprise-wide automation through integrated control with coding agents, Physical AI and On-prem solutions

Expected benefits

  • Even non-developers can naturally design and operate complex automations using natural language, while achieving both reduced operating costs and improved quality metrics (accuracy/processing time) through result-based recursive optimisation
  • Rapid expansion to new tasks/systems is possible by leveraging standard (MCP) and plugin ecosystems

Clevi Security Agent (Red Team Testing)

Clevi Purple Agent is an intelligent security agent that automatically updates the US CVE database daily to obtain the latest vulnerability information and, based on this, detects, validates and reports security vulnerabilities in internal networks, servers, networks and applications using white-hat hacker methods (penetration testing and simulation) based solely on natural-language target specification (e.g., windows, web server, specific folder/file name). It supports the entire lifecycle of automated detection → scenario validation → report generation and is designed to operate in on-premises and isolated network environments, making it suitable for regulation-sensitive industries such as the public sector, finance and manufacturing.

Main image

<Clevi Security Agent GUI screen>

Key Features

Automatic Daily CVE Feed Synchronisation

  • The latest vulnerability list is maintained by synchronising US NVD/CVE sources and internal threat intelligence (collection pipeline) daily.

Natural-Language Target Specification (Simplified Operator Interface)

  • Users can specify detection targets using natural language/simple keywords such as “windows”, “specific server:10.10.0.5” and “/var/www/html” (e.g., the left-panel input method is provided as a UI)

Simulated White-Hat Hacker Validation Engine (Non-Destructive)

  • Potential vulnerabilities are simulated and validated in a secure sandbox/emulation environment (reproducing the vulnerability through an exploit attempt → without observing the impact), enabling the presence and risk level of vulnerabilities to be assessed without interrupting actual services.

Automated Reporting and Prioritisation

  • Summary alerts are sent to administrators immediately upon detection (email/Slack/ticket), and PDF/HTML reports containing vulnerability impact and priority are generated automatically (summary of vulnerable locations, reproduction conditions and recommended actions)

Scenario and Playbook Integration (Automated Action Integration Option)

  • In approved environments, patch scenarios and temporary mitigation (applying defensive rules before patching) can be triggered for automatic execution. (Approval procedures in accordance with operational policies are mandatory)

Integrated Logging and SIEM Integration

  • System logs, detection logs and report results can be integrated into the SIEM/security portal for continuous monitoring and auditing

Access Control, Auditing and Governance

  • All detection and verification activities are recorded along with the account, approval and timestamp to support legal and regulatory audits.

Technical Differentiation and Value

Real-Time and Daily Freshness

  • An automated daily CVE/NVD update pipeline enables impact tracking immediately after a zero-day disclosure.

AI-Based Vulnerability Mapping

  • AI matches targets specified in natural language with CVE descriptions (in English and Korean) to prioritise the likelihood of exposure (vulnerability relevance) for the relevant system.

Non-Destructive Simulation Architecture

  • Safety is ensured through validation in an 'emulation sandbox' that does not cause customer service disruption.

Enterprise Deployment Options

  • Supports SaaS, on-premises and isolated networks (SVCE), enabling compliance with public-sector and financial regulations.

Automated Reporting and Traceability

  • Reduces operational risk through a complete audit trail (versions, history and owners) from detection to verification to reporting.

Integrated Orchestration

  • Integrates with ARI (workflow platform) and internal patch management and ticketing systems to automate the iterative PoC → patch → verification loop.

Expected Benefits (Business Impact)

Proactive Risk Reduction

  • Rapid exposure checks for newly disclosed CVEs help prevent the risk of actual breaches in advance.

Improved Operational Efficiency

  • Automating repetitive vulnerability checks and reporting tasks saves the security team's time and resources.

Strengthened Regulatory and Compliance Response

  • Provides auditable assessment logs and reports aligned with regulatory requirements such as PIPA/CSAP.

Faster Decision-Making Support

  • Impact-based priority reports enable rapid decisions on patching and mitigation priorities.

Enquiries and demo requests: [email protected]

Copyright© 2025 Clevi Inc. All rights reserved.

Back to newsroom
CLEVI

Language and region

Machine-translated languages are marked. Availability follows the published site bundle.

136 languages

Recommended

1

East Asia

7

Southeast Asia

11

South Asia

18

Central Asia

5

Middle East and the Caucasus

10

Western and Southern Europe

16

Britain and Ireland

4

Northern Europe and the Baltics

10

Central Europe and the Balkans

14

Eastern Europe

5

East Africa and the Horn

8

West and Central Africa

9

Southern Africa

8

The Americas

5

The Pacific

5