Logo
Overview
How Mobbin achieves near-immediate security triage with Hacktron
Mobbin logo

How Mobbin achieves near-immediate security triage with Hacktron

September 8, 2026
2 min read
Product DesignSaaS

32 minutes

median time to triage across evaluated findings

21 findings

were addressed in the first eight weeks

10.3 hours

longest time to triage

I don't see how else we can scale this.

It helps a lot to have Hacktron take the first pass for our security issues.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo

About Mobbin

Mobbin has become essential infrastructure for modern product teams. More than two million designers use its library of 600,000+ screens from shipped mobile apps, web apps and websites to learn from the world’s best digital products.

The challenge

AI has dramatically increased the speed at which Mobbin’s engineering team writes and ships code.

Findings appeared after release, without a clear owner

Security findings often appeared only after a feature had shipped. By then, there was no clear owner, and the team had to find the right engineer to investigate each issue.

Before, a security finding would appear after a feature had shipped. No owner was assigned, so we needed to find someone to take it on.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo

Manual review struggled with cross-cutting changes

Before Hacktron, security review was manual. Engineers wrote tests and reviewed pull requests themselves. That worked for small, isolated changes. Cross-cutting changes were harder because any one reviewer could only account for the system interactions already visible to the team.

Generally, small testable units are fine. But for cross-cutting changes, the test suite is limited by the team's understanding of how systems interact across the codebase.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo

As code generation accelerated, Mobbin needed security review that could keep up, bring the wider application context into every change and help engineers reach decisions while the code was still fresh.

Hacktron brings security review into every pull request

Mobbin now uses Hacktron as the first security pass on every pull request. When Hacktron identifies a finding, it appears as part of the PR review process, so security review progresses alongside the code rather than after release. Hacktron reviews each change against the wider codebase, traces how it interacts with the application and posts its findings directly in GitHub.

With Hacktron, a security finding appears in the PR review process, and the PR owner is also the security finding owner.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo

When the code changes, Hacktron reviews it again. Engineers see the finding while the pull request is active, inspect the evidence and make the final triage decision.

The speed at which we are shipping code has increased dramatically.

The demand for an automated PR security review tool as extra eyes was certainly needed.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo
  • Before Hacktron: Findings often appeared after release, without a clear owner.
  • With Hacktron: Findings appear during PR review, making security part of the active change.

Full-codebase context

Hacktron makes findings faster to triage by bringing application context to the decision.

Hacktron can connect a change to code elsewhere in the application and highlight security implications that are difficult to see from an isolated diff. It can also identify structural changes that may create a vulnerable path as the codebase evolves.

What I appreciate is that Hacktron does not just check for existing security vulnerabilities.

It also highlights high-risk surface areas or changes—areas that pose no risk at the point of writing, but have a chance of creating a vulnerability through future changes because of how the code was structured.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo

The results

From finding to decision in minutes

Because Hacktron is part of the PR review process, engineers react to findings nearly immediately.

The PR owner is also the security finding owner.

Jian Jie Liau

Jian Jie Liau

CTO and co-founder, Mobbin

Mobbin logo

During Mobbin’s first eight weeks with Hacktron, 21 findings reached a final verdict. The median time for triage was approximately 32 minutes. Even the longest case was triaged within 10.3 hours. By moving security review into every pull request and assembling application context around each finding, Hacktron turned triage from a post-release handoff into part of the active development workflow.

For an AI-native engineering team, security review can now keep pace with code generation—surfacing issues early to act while changes are still in motion.

Hacktron reviews your code and finds real vulnerabilities before they ship to production.