# How Cohere Health cleared 92% of its critical and high findings and got their time back

**URL:** https://mazehq.com/customer-story/how-cohere-health-cleared-92-of-its-critical-and-high-findings
**Date:** 2026-09-22

## Introduction

Cohere Health builds AI into the heart of healthcare, from prior authorization to the systems its own teams depend on. That puts its security team in an unusual spot. They spend their days building high-quality AI and hold their tools to that same bar.

As a Senior Cloud AI and Security Engineer, Jonathan King’s team looks after the cloud infrastructure Cohere Health runs on and the security of the AI built on top of it. The hard part of that job was never finding vulnerabilities. It was deciding which ones were real, and clearing them before they wore his team down. Today, because of Maze, more than half of what the scanner flags never reaches his team.

## Life before Maze

Cohere Health’s scanners never had trouble surfacing vulnerabilities. With more than a hundred container repositories throwing off thousands of findings, it didn’t matter that half of everything flagged was never exploitable. Each one still had to be investigated, assigned, and researched before being written off as a false positive.

That cost more than the wasted hours. It cost the security team their credibility. After enough false alarms, engineering started deprioritizing tickets security sent over. Alerts that mattered got lost with the ones that didn’t.

> If I were to send a thousand high alerts to somebody, they’re probably not going to look at the security team again, or even want to talk about something they need again to us.
> 
> Jonathan King, Senior Cloud AI and Security Engineer, Cohere Health

## The usual solutions only added overhead

With the scanner labeling nearly a third of all findings critical or high, the team couldn’t chase all of them. So the Cohere Health security team tried to get control of their vulnerabilities using the standard playbook. They tried shift-left, shift-right, runbooks, in-house workarounds. Each turned out to be a bandaid that added work instead of removing it. Tuning rules cost engineering hours, and every change meant tuning them again. Better scanners just produced more to sift through.

Cohere Health knew there had to be a better way. One where every finding was reviewed before it reached the team, so they only ever saw true positives.

> The more tools you throw at something doesn’t solve the issue. I’ve worked for companies where they throw more heads to try to solve the problem and the company falls apart.
> 
> Jonathan King, Senior Cloud AI and Security Engineer, Cohere Health

## Now only true positives reach the team

51% of all findings turned out to be not exploitable. Maze provides evidence with every verdict, even the ones it closes, so a decision not to prioritize a finding is already documented and defensible.

Once Maze weighed the real environment, 87% of the critical and high findings turned out to be not exploitable or safe to deprioritize. The team has remediated more on top of that.

Maze investigates every finding the way an experienced engineer would. It weighs each one against Cohere Health’s AWS environment, their code, and their compensating controls. Then it works out whether the vulnerability is exploitable, and whether those conditions actually exist in their environment. Only then does it route the finding to the owner who needs to fix it.

Maze sits between Cohere Health’s scanners and their engineers, and it’s the only solution they trust to create tickets.

> The only thing that we’re really confident in sending to Jira is tickets from Maze.
> 
> Jonathan King, Senior Cloud AI and Security Engineer, Cohere Health

## One change fixes many findings

Around 57% of the fixes Maze recommends are low-effort, and engineers can knock them out fast. Because it traces each vulnerability to its root cause, it groups the ones that share a root cause, so a single change can clear a whole batch at once.

> It’s the whole mentality of not working harder, but working smarter, and being able to find strategies that actually will work without involving many people whatsoever. I think that’s the end all strategy, automation first.
> 
> Jonathan King, Senior Cloud AI and Security Engineer, Cohere Health

## Giving the teams their time back

Now more than half of all findings are closed before anyone sees them. Automating investigations didn’t hand over the decisions blindly. Cohere Health’s engineers still make the final call when they decide to. Maze provides evidence with every verdict, even closed ones. What used to be an afternoon of digging is now a quick check.

Engineering started prioritizing those tickets again because everything that reaches them is now a true positive. The security team was never the problem. It was the alert quality. They had the rigor and the relationships all along.

> Showing enough proof to put anybody into a corner and say there’s no other way to disprove this information is the best way to communicate to people that this is true. This is what’s happening within our own environment.
> 
> Jonathan King, Senior Cloud AI and Security Engineer, Cohere Health

## The results

Maze cleared out the noise, re-scored what was left against Cohere Health’s real environment, and gave the team back the hours and trust they lost to false positives.

- 92% of critical and high findings not exploitable, downgraded, or remediated
- 51% of findings closed automatically, each documented and audit-ready
- 57% of fixes are low-effort, and Maze includes guidance to speed up remediation
- The team’s hours go to real threats, not chasing dead ends

> I haven’t seen anything that disproves what Maze is doing whatsoever.
> 
> Jonathan King, Senior Cloud AI and Security Engineer, Cohere Health