Case Study: How Quorum Delivers Secure Code Faster with Jit
Key results
The challenge
Quorum, a public affairs software company headquartered in Washington, D.C. and running on AWS, needed to meet PCI and SOC2 requirements and broaden security testing beyond runtime pentesting to catch issues earlier in the SDLC. Development and security teams were bombarded with noisy alerts after scans, making it hard to focus on the most critical risks. Quorum wanted full code-to-cloud coverage without the cost and complexity of managing multiple disparate tools.
The solution
Quorum adopted Jit's Open ASPM platform, which developers use entirely within GitHub and which consolidated eleven code and cloud security scanners (SAST, DAST, SBOM, secrets detection, SCA, IaC scanning, CSPM, CI/CD and container scanning) into a single platform. Infrastructure-as-Code files were scanned on every pull request to catch AWS misconfigurations before production. Rollout began with a proof of value on a few repositories, then expanded via one-click activation of controls across repos.
“We wanted to try to reduce the noise and get to the important things, and I think Jit helps out tremendously with that. Developers liked the way it's intuitive, and just integrate easily with what they were already doing.”
KJKelly JohnsonSecurity Engineer, Quorum
The results, in context
According to Jit's user story, Quorum's noise reduction and in-workflow remediation produced an estimated 50% faster issue resolution compared to its previous state. Kelly Johnson also estimated an 80% reduction in security issues that would previously have slipped through manual code reviews. Both figures are explicitly Quorum's own estimates as quoted on Jit's source page.