Checkmarx has introduced its enhanced Checkmarx One platform designed to integrate AI-driven security into modern application development processes. As artificial intelligence continues to advance the pace and scale of software production, conventional application security strategies are becoming insufficient.
The revamped platform aims to embed intelligent, agentic security across various components including code, open-source dependencies, AI assets, and runtime environments. This approach allows organisations to innovate rapidly while maintaining robust security measures from the outset.
Reducing manual remediation efforts
The foundation of the new Checkmarx One platform lies in its architecture, featuring agentic security agents combined with AI-native intelligence that spans the software and AI supply chain. Noteworthy innovations include Triage Assist, an AI agent that autonomously prioritises vulnerabilities in source control by assessing real-world exploitability and contextual risks. This ensures development teams focus on significant issues rather than static severity scores. Additionally, Remediation Assist provides review-ready fixes for verified vulnerabilities, accelerating secure code delivery and minimising manual intervention.
The platform also offers AI Supply Chain Security, a system that provides governance and visibility for AI components within applications. It identifies hidden AI assets such as models, agents, datasets, and AI-BOM elements, managing risks related to model loading and execution, and enforces policies within existing workflows. AI SAST, a hybrid analysis engine powered by large language models, extends detection capabilities to new and AI-generated programming languages, moving beyond traditional static scanning methods. Furthermore, DAST for AI enhances runtime protection through dynamic analysis, supporting flexible testing strategies for AI-driven applications across continuous integration and production environments.
AI-driven software development
These advancements mark a shift from reactive security processes to proactive agentic governance
These advancements mark a shift from reactive security processes to proactive agentic governance, aligning security measures with the pace and intricacy of AI-accelerated software development.
Sandeep Johri, CEO of Checkmarx, remarked, "The AI era has fundamentally disrupted the balance between software creation and assurance. Code is now produced at machine speed, but successful security in this environment requires more than speed alone. It requires independent oversight, full visibility across the AI software supply chain, and unified governance that spans code, dependencies, AI assets, and runtime. Agentic application security brings those capabilities together, helping enterprises close the risk gap without slowing innovation."
Securing AI-generated applications
Chief Product Officer Jonathan Rende emphasised, "AI has compressed the software development lifecycle from months to minutes. When applications move that fast, risk compounds just as quickly. Our redesigned agentic platform allows development organisations to innovate at machine speed while securing AI generated applications to protect the business."
The newly announced features are accessible as part of the Checkmarx One Enterprise Edition or as enhancements to the Essentials or Professional Edition. Checkmarx is set to showcase these enhancements at the RSA Conference 2026.
