VulnOps Trailblazers/ 01
·Financial Services·Customer story

How MoneyGram achieves machine-speed security for the AI era

MoneyGram processes seamless money movement across 200 countries and territories through nearly 500,000 locations, serving 60 million active customers. When the company made a deliberate bet on AI-accelerated software development, it faced a question most organizations were just beginning to take seriously: if developers can ship code at machine speed, how does security keep up?

60Mactive customers
200countries and territories
~500Klocations worldwide
“We believed AI would fundamentally change how software gets built. Our opportunity was to ensure security evolved with it, not as a gate, but as part of the architecture. At machine speed, innovation and security shouldn’t compete; they should accelerate together.
Luke Tuttle Chief Product and Technology Officer, MoneyGram
96%
Processed automatically
on triage
72%
Fewer findings need humans
via exploitability analysis
6,500+
Hours of effort saved
across triage & fixes
01

The opportunity

MoneyGram has long been an industry leader in security, with investments in repository tiering, automated GitLab workflows, and defined remediation objectives.

As MoneyGram began implementing AI across its business, the security team saw an opportunity to evolve its approach and stay ahead of the pace of innovation.

AI coding tools were increasing developer speed, so MoneyGram needed security to scale with engineering velocity - reducing noise, improving prioritization, and enabling faster, more intelligent remediation without slowing delivery.

By adopting a VulnOps operating model, MoneyGram could bring automated triage and remediation directly into the development lifecycle.

02

The solution

After evaluating several approaches, MoneyGram chose Pixee to operationalize VulnOps at scale. Pixee addressed both sides of the challenge directly.

Triage came first: Pixee's exploitability analysis filtered out findings that weren't real risks, cutting the noise before it reached development teams. Then remediation: for findings that were real, Pixee generated merge-ready pull requests matched to MoneyGram's code conventions and integrated directly into their existing GitLab pipelines.

With triage and remediation running in the same continuous workflow, teams stopped having to choose between speed and thoroughness. Security analysis ran automatically, developers received actionable fixes rather than alert lists, and time from finding to fix dropped significantly.

1
Findings
SAST & SCA results enter the pipeline
2
Triage
Exploitability analysis cuts false positives
3
Remediate
Merge-ready PRs, matched to conventions
4
Merge
Developers review and ship

Continuous — running inside MoneyGram’s existing GitLab pipelines

The operating principle

Fighting machine speed with machine speed.

03

The outcome

Pixee analyzed more than 200 repositories across 8,000+ automated scans. On the triage side, 96% of findings were processed automatically, with a 72% reduction in the findings requiring human attention, eliminating more than 3,500 hours of manual security work.

On the remediation side, Pixee generated automated fixes directly in the developer workflow, saving an additional 3,000+ hours of developer effort. Developers reviewed and merged pull requests that already matched their conventions, rather than writing fixes from scratch.

200+
Repositories analyzed
8,000+ automated scans
3,500+
Hours of manual security work eliminated
3,000+
Hours of developer effort saved

The VulnOps program delivered:

  • Security that scales with engineering velocity, not behind it
  • Developers getting merge-ready fixes to review, not long lists of findings to wade through
  • False positive noise cut before it reached engineering teams
  • Vulnerability triage capacity that scaled automatically, so added headcount could go toward expanding the program's footprint rather than sustaining manual work
  • Security and engineering working from the same signal, not debating remediation windows

What changed most was how the team operated. With higher confidence in signal quality, teams stopped spending time on SLA-driven prioritization machinery: 30-day remediation windows, 60-day windows, exception processes and reviews. They could focus on one question:

Is this a real risk?If so, fix it.
04

Looking ahead

Machine-speed security, VulnOps, continuous remediation at scale: for much of the industry, these are still goals. For MoneyGram, they're already how the team operates.

“The future of cybersecurity isn’t about choosing between speed and security—it’s about eliminating the tradeoff entirely. Machine speed is our advantage. The organizations that lead will be those that build defenses capable of moving, adapting, and responding as fast as the technology they protect.”
Jana Moore Chief Information Security Officer, MoneyGram
VulnOps for your codebase

See what machine-speed security looks like on your own repositories.

Pixee triages what your scanners already find, then opens merge-ready fixes inside your pipeline.

MoneyGram × Pixee · VulnOps Trailblazers · © 2026 Pixee