-

Orca Security Extends Its Platform to the New Generation of AI Builders

Ahead of Black Hat USA 2026, Orca unveils AI AppGen Security and AI Code Security Auditor, giving security teams one platform to find truly exploitable code in development and discover shadow builders, safely enable them, and govern the AI applications employees build outside engineering

LAS VEGAS--(BUSINESS WIRE)--Software is no longer built solely by professional developers inside traditional development pipelines. As AI turns employees across the business into builders, organizations need security that protects software wherever it gets built. Today, Orca Security, a leader in cloud and AI security, announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the development pipeline on AI-powered platforms like Claude, Supabase, and Lovable, and AI Code Security Auditor, which delivers deep AI-driven static analysis for code developed within traditional pipelines. Together, the capabilities extend the Orca Platform to secure software across the full spectrum of modern application development, from professional engineering teams to the growing population of AI-assisted builders.

The shift is already well underway. Orca's newly released State of AI Security Report 2026, based on anonymized telemetry from more than 1,200 production cloud environments analyzed by the Orca Research Pod, found that 52% of organizations now build custom applications with AI. As business teams increasingly deploy AI-generated applications connected to APIs, cloud resources, and sensitive data, software development is expanding beyond security's traditional visibility. At the same time, exploitable risks continue to persist within development pipelines. IBM estimates breaches involving shadow AI cost organizations an average of $670,000 more than other incidents, underscoring the need for organizations to secure software consistently, whether it's built by developers in the pipeline or employees using AI outside of it.

“Everyone is a builder now. Developers are creating software in the pipeline, employees are building AI applications outside it, and the next generation of frontier AI models will increasingly generate and modify software on their own. Organizations need security that can keep pace with this shift without slowing innovation. Our AI Code Security Auditor prepares customers for the next wave of AI-assisted software development, while giving security teams the deep, accurate context they need to understand what's truly exploitable. Combined with AI AppGen Security, Orca helps organizations secure every builder and every application, wherever and however it's created.”

— Gil Geron, CEO and Co-Founder, Orca Security

Whether software is written by professional developers or generated by AI-powered builders, security teams need the same outcome: complete visibility, meaningful context, and the ability to prioritize real risk. Together, Orca AI AppGen Security and Orca Code Security Auditor extend the Orca platform to secure modern software development wherever it happens.

Orca AI AppGen Security: Secure the New Generation of AI Builders

As AI expands software development beyond engineering, Orca AI AppGen Security gives security teams visibility and control over applications built outside the development pipeline by:

  • Discovering AI-generated applications and who built them.
  • Mapping application risk across APIs, integrations, and data access.
  • Prioritizing high-risk exposures based on real business impact.

Orca Code Security Auditor: Secure AI-Assisted Development

Orca Code Security Auditor helps developers identify and prioritize the vulnerabilities that matter most by:

  • Finding vulnerabilities traditional SAST misses with AI-powered code analysis.
  • Full repository scanning to uncover Mythos class frontier model vulnerabilities.
  • Prioritizing exploitable risk so teams can focus on what attackers can actually reach.

“My developers and my business teams are both shipping software faster than my team can review it, and the apps built outside our pipeline were a complete blind spot. Seeing exploitable code and the AI apps our employees stand up in one platform lets us say yes to builders instead of slowing them down — and still know exactly what we’re governing.”

— Sangram Dash, Chief Information Security Officer, Sisense

One platform for everyone who builds

Software is no longer built solely by developers. Employees across the business are creating applications with AI, while autonomous agents increasingly contribute to how software is developed and deployed. As the population of builders continues to grow, organizations need a single platform to secure and govern every application, regardless of who—or what—built it. Recent additions, including support for Anthropic Claude through its Compliance API, further extend Orca's unified approach to AI governance. Orca delivers on its promise of security for the companies that build by providing unified visibility and risk prioritization across the entire software lifecycle, enabling organizations to innovate with confidence while keeping every builder building.

Availability

Orca AI AppGen Security and Code Security Auditor will be unveiled at Black Hat USA 2026 and will be generally available later in 2026. Orca will demonstrate both capabilities at booth 5115 at Black Hat USA 2026 in Las Vegas. The State of AI Security Report 2026 is available now at orca.security.

About Orca Security

Orca Security delivers security for the companies that build. As cloud, applications, AI and app generation expand the attack surface, Orca transforms security risk into the context teams need to act. The Orca Platform provides complete visibility across cloud, AI, and application environments, correlates risk across every layer, and prioritizes the exposures that matter most so organizations can remediate faster and innovate with confidence. Trusted by hundreds of organizations, including SAP, Autodesk, Gannett, Lemonade, and Digital Turbine, Orca is backed by leading investors including Temasek, CapitalG, ICONIQ Capital, and Redpoint Ventures. Learn more at orca.security. Connect your first account in minutes: https://orca.security or book a personalized demo.

Contacts

Media Contact
Inkhouse on behalf of Orca Security
orcasecurity@inkhouse.com

Orca Security


Release Versions

Contacts

Media Contact
Inkhouse on behalf of Orca Security
orcasecurity@inkhouse.com

More News From Orca Security

Orca Security Extends AI Security Platform with Integration to Claude's Compliance API

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, a leader in cloud and AI security, today announced an integration with Claude's Compliance API, extending Orca's AI security capabilities to Claude Enterprise. The integration enables organizations to gain visibility into AI activity, identify security and compliance risks, and apply consistent governance as AI becomes an increasingly important part of how software is created and business work gets done. Organizations are now built by developers,...

Orca Security Report: 99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, a leader in cloud and AI security, today released its 2026 State of AI Security Report, offering a first-hand view into how AI is being deployed across more than 1,200 production cloud environments. The findings show AI is no longer limited to isolated pilots or developer experiments. Organizations are embedding AI into production applications, cloud services, and autonomous workflows faster than security programs can adapt. More than half (56%) o...

Orca Security Named to Rising in Cyber 2026 for Third Consecutive Year

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, the pioneer in agentless cloud security, today announced its inclusion in Rising in Cyber 2026, an independent annual list launched by Notable Capital to recognize the 30 most promising private cybersecurity startups. Now in its third year, Rising in Cyber has become a trusted signal of what is actually moving the needle in enterprise security. Unlike traditional rankings, Rising in Cyber honorees are selected through voting by 150 active CISOs an...
Back to Newsroom