Case study
GenAI Chatbot for Faster Vulnerability Remediation
How SquareShift built a Gen AI chatbot on Vertex AI to speed up vulnerability remediation for a global semiconductor and infrastructure-technology leader.
A vulnerability chatbot is only as good as its retrieval layer. Get RAG wrong and you get confident, wrong answers — worse than analysts checking five tools by hand.
AI & Generative AI Practice Lead, SquareShift
A global infrastructure-technology leader that designs, manufactures, and supplies semiconductor and software products across data centers, networking, and industrial markets.
Its vulnerability analysts were manually researching threats across multiple tools and websites — a slow, repetitive process that needed an automated assistant.
- Centralized vulnerability data — Armorcode and external advisories unified into one system.
- GenAI chatbot on Vertex AI — contextual remediation guidance for analysts, on demand.
- Automated remediation pipeline — bulk-generates suggestions and status updates instead of manual tracking.
How SquareShift delivered it.
The challenge
Vulnerability analysts had to manually cross-check findings across a stack of scanning tools — BlackDuck, Lacework, JFrog, Coverity, Qualys — plus external web sources, then track down and log remediation status by hand. It was repetitive, slow, and pulled analysts away from real security work.
What we delivered
SquareShift built a Gen AI chatbot powered by Vertex AI’s Gemini Pro and PaLM 2, using a Retrieval-Augmented Generation (RAG) architecture over BigQuery. Data engineers scraped vulnerability data from external sources and ingested it alongside Armorcode data into a single, unified BigQuery dataset.
On top of that dataset, SquareShift’s AI developer built the chatbot interface analysts actually use — answering contextual questions and interfacing with a backend ML pipeline that bulk-generates remediation suggestions and pushes status updates automatically.
The payoff
Vulnerability analysts now get contextual answers from a chatbot instead of manually cross-checking multiple tools, and remediation suggestions and status updates generate in bulk instead of one at a time. Centralizing external advisories and Armorcode data into one BigQuery dataset gave the remediation workflow a single source of truth.
Where this work sits
