CodeMender can help you advance from passive scanning to automated code remediation, and reduce zero-day risk. It examines and remediates existing code security issues without sacrificing development velocity by:
-
Deploying the best-fit model. You can choose from multiple models to optimize for costs, speed, deep scanning, and coding performance.
-
Automating machine-scale remediation. You can now eliminate remediation bottlenecks caused by manual verification and patching, while keeping developers in the loop.
-
Prioritizing fixes by exploitability. You can run proof-of-concept exploits and execute simulations to verify that vulnerabilities in the code are exploitable, and prioritize resources on fixing the most critical issues first.
Find and fix vulnerabilities with AI
Born from Google DeepMind’s pioneering AI research, CodeMender transforms vulnerability management from a manual bottleneck into an autonomous, high-speed system. Your developers and security practitioners can automatically scan software for flaws, verify them with executable exploits, and remediate them with tested code fixes.
“At Salesforce, trust is our number one value, and protecting customer data means continually raising the bar for how we find, validate, and mitigate risks. CodeMender brings AI into a critical part of the security lifecycle by accelerating the path from validated vulnerability to tested fix. As AI reshapes the threat landscape, capabilities like this help strengthen resilience and give our customers the confidence to keep innovating,” said Iain Mulholland, CISO, Salesforce.
“CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It doesn’t just find theoretical flaws — it proves the immediate risk and delivers targeted, validated fixes that secure our environment without disrupting core business logic,” said Scott Ponte, head, Security Operations, Robinhood.
“CodeMender is fast, comprehensive, and genuinely ambitious about closing the loop from detection to fix, enabling teams to secure their software supply chain without losing velocity,” said Ashwin Kannan, principal AI engineer, Office of the CTO, Palo Alto Networks.
How the CodeMender agent works
We’ve fine-tuned CodeMender’s harness to be continuously updated with the latest Google DeepMind research, including the up-to-date agent skills, security tools, and system prompts.
Operating in the secure-by-design Agent Platform, CodeMender is protected by enterprise-grade, built-in governance and security guardrails, including secure traffic routing through your VPC, data isolation and encryption, and zero retention of source code data.
As an agent, it can integrate with existing continuous integration and continuous delivery (CI/CD) workflows, or run directly in local developer environments using a lightweight command-line interface (CLI) client.
You can also configure CodeMender to scan and analyze code in a sandbox that you manage. The agent connects to your code repositories and works with developer tools, such as VS Code and Antigravity, to safely analyze first-party, open-source, and third-party software.
Scan: Find hidden vulnerabilities with flexible model scanning
CodeMender scans for top vulnerability classes and understands the unique context, goals, and functionality of your software repositories and applications.






