Case study

GenAI Chatbot for Faster Vulnerability Remediation

How SquareShift built a Gen AI chatbot on Vertex AI to speed up vulnerability remediation for a global semiconductor and infrastructure-technology leader.

Book a session
A vulnerability chatbot is only as good as its retrieval layer. Get RAG wrong and you get confident, wrong answers — worse than analysts checking five tools by hand.

AI & Generative AI Practice Lead, SquareShift

A global infrastructure-technology leader that designs, manufactures, and supplies semiconductor and software products across data centers, networking, and industrial markets.

Its vulnerability analysts were manually researching threats across multiple tools and websites — a slow, repetitive process that needed an automated assistant.

Highlights
  • Centralized vulnerability data — Armorcode and external advisories unified into one system.
  • GenAI chatbot on Vertex AI — contextual remediation guidance for analysts, on demand.
  • Automated remediation pipeline — bulk-generates suggestions and status updates instead of manual tracking.
Key services
AiAI & Generative AI
PePlatform & Software Engineering
Industry

Technology

Key technologies / platforms

Vertex AI · Gemini Pro · PaLM 2 · BigQuery · RAG (Retrieval-Augmented Generation) · Armorcode

The engagement

How SquareShift delivered it.

The challenge

Vulnerability analysts had to manually cross-check findings across a stack of scanning tools — BlackDuck, Lacework, JFrog, Coverity, Qualys — plus external web sources, then track down and log remediation status by hand. It was repetitive, slow, and pulled analysts away from real security work.

What we delivered

SquareShift built a Gen AI chatbot powered by Vertex AI’s Gemini Pro and PaLM 2, using a Retrieval-Augmented Generation (RAG) architecture over BigQuery. Data engineers scraped vulnerability data from external sources and ingested it alongside Armorcode data into a single, unified BigQuery dataset.

On top of that dataset, SquareShift’s AI developer built the chatbot interface analysts actually use — answering contextual questions and interfacing with a backend ML pipeline that bulk-generates remediation suggestions and pushes status updates automatically.

The payoff

Vulnerability analysts now get contextual answers from a chatbot instead of manually cross-checking multiple tools, and remediation suggestions and status updates generate in bulk instead of one at a time. Centralizing external advisories and Armorcode data into one BigQuery dataset gave the remediation workflow a single source of truth.