Orca Security protects applications built with AI and created by developers

Applications of AI


Orca Security announced two new AI-powered features. Orca AI AppGen Security detects and protects AI applications built outside the development pipeline on AI-powered platforms such as Claude, Supabase, and Lovable. The other is AI Code Security Auditor, which provides deep AI-driven static analysis of code developed within traditional pipelines.

This feature extends the Orca platform to protect software across the entire spectrum of application development, from professional engineering teams to a growing number of AI-assisted builders.

Orca’s newly released State of AI Security Report 2026 is based on anonymized telemetry from more than 1,200 production cloud environments analyzed by Orca Research Pod and finds that 52% of organizations are currently using AI to build custom applications. Software development is expanding beyond traditional visibility into security as business teams increasingly deploy AI-generated applications connected to APIs, cloud resources, and sensitive data. At the same time, exploitable risks remain in the development pipeline.

IBM estimates that breaches involving shadow AI cost organizations an average of $670,000 more than other incidents, highlighting the need for organizations to consistently protect software, whether built by developers in the pipeline or by employees using AI externally.

“Everyone is a builder now. Developers are building software in the pipeline, employees are building AI applications outside of it, and next-generation frontier AI models are increasingly producing and modifying software on their own. Organizations need security that can adapt to this change without slowing innovation. Our AI code security auditors are preparing our customers for the next wave of AI-assisted software development while providing security with the deep and accurate context needed to understand what is truly exploitable. Combined with AI AppGen Security, Orca helps organizations protect every builder and every application, no matter where or how they are created.” said Gil Geron, CEO of Orca Security.

Whether the software is written by professional developers or produced by AI-powered builders, security teams need the same outcomes: complete visibility, meaningful context, and the ability to prioritize real risks. Orca AI AppGen Security and Orca Code Security Auditor extend the Orca platform to ensure software development is secure no matter where it happens.

Orca AI AppGen Security: Securing a new generation of AI builders

As AI extends software development beyond engineering, Orca AI AppGen Security provides security teams with visibility and control over applications built outside the development pipeline by:

  • Discover AI-generated applications and the users who created them.
  • Map application risks across APIs, integrations, and data access.
  • Prioritize high-risk exposures based on their actual business impact.

Orca Code Security Auditor: AI-assisted secure development

Orca Code Security Auditor helps developers identify and prioritize the most important vulnerabilities by:

  • AI-powered code analysis uncovers vulnerabilities missed by traditional SAST.
  • Scans the entire repository to discover frontier model vulnerabilities in the Mythos class.
  • Prioritize exploitable risks so your team can focus on what attackers can actually reach.

“Both developers and business teams were shipping software faster than my team could review it, and apps built outside the pipeline were a complete blind spot. By seeing AI apps with exploitable code and employees running on one platform, we can say yes without slowing down developers, and we know exactly what we’re in control of,” said Sangram Dash, CISO at Sisense.



Source link