Checkmarx has introduced an updated version of its Checkmarx One platform, designed to address the challenges posed by rapid advances in artificial intelligence (AI) within software development. As AI continues to transform software creation, traditional security approaches struggle to keep pace.
The revamped platform integrates AI-driven security mechanisms throughout the software development lifecycle, covering code, open-source dependencies, AI components, and runtime environments. This integration aims to facilitate innovation while ensuring robust security from the outset.
Innovation in Security Architecture
The heart of the Checkmarx One update lies in its novel architecture, which harnesses AI and agentic security agents to safeguard the software and AI supply chain. Key features introduced in this update include:
- Triage Assist: An autonomous AI agent tasked with prioritizing vulnerabilities in source control by assessing real-world exploitability and contextual risk. This allows development teams to focus their efforts on the most critical issues rather than being swayed by static severity scores.
- Remediation Assist: This feature automatically generates fixes for confirmed vulnerabilities before code integration, expediting secure releases and decreasing the reliance on manual remediation efforts.
- AI Supply Chain Security: A centralized management layer that provides visibility into AI components within applications. It identifies hidden assets like models and datasets, detects risks in AI model execution, and enforces policies within existing development frameworks.
- AI SAST: A hybrid LLM-powered, query-based analysis engine enhancing detection of vulnerabilities across emerging and AI-generated programming languages, pushing security beyond conventional scanning rules.
- DAST for AI: An advanced dynamic analysis engine reinforcing runtime protection throughout CI/CD processes and production settings, offering adaptable testing solutions for AI-driven applications.
Transforming Application Security
These features support a shift in application security from a reactive stance to proactive governance
These features support a shift in application security from a reactive stance to proactive governance that aligns with the accelerated pace of AI-driven development.
According to Sandeep Johri, CEO of Checkmarx, "The AI era has fundamentally disrupted the balance between software creation and assurance. Code is now produced at machine speed, but successful security in this environment requires more than speed alone. It requires independent oversight, full visibility across the AI software supply chain, and unified governance that spans code, dependencies, AI assets, and runtime. Agentic application security brings those capabilities together, helping enterprises close the risk gap without slowing innovation."
Accelerating Software Development
Jonathan Rende, Chief Product Officer at Checkmarx, added, "AI has compressed the software development lifecycle from months to minutes. When applications move that fast, risk compounds just as quickly. Our redesigned agentic platform allows development organizations to innovate at machine speed while securing AI-generated applications to protect the business."
The enhanced features are available in the Checkmarx One Enterprise Edition and can be included as add-ons to the Essentials or Professional Edition. Checkmarx plans to showcase these capabilities at the RSA Conference 2026.
