Orca Security Bolsters Platform with AI-Powered Application Security Tools
Orca Security introduces two new AI-driven capabilities to secure applications developed both within traditional pipelines and by AI builders outside of them.
Orca Security has announced the release of two significant AI-powered capabilities designed to enhance application security across the entire development lifecycle. Orca AI AppGen Security aims to discover and secure AI-generated applications built on platforms like Claude and Supabase, which often operate outside traditional development pipelines. Complementing this, the AI Code Security Auditor provides advanced AI-driven static analysis for code developed within standard development workflows.
These new features extend the Orca Platform's reach, enabling it to secure software regardless of how it's created. This is particularly crucial as the company's "State of AI Security Report 2026" indicates that 52% of organizations are now building custom applications with AI. As business teams increasingly deploy AI-generated applications that connect to sensitive data and cloud resources, the scope of software development is expanding beyond the traditional purview of security teams, while exploitable risks persist within established development pipelines.
The financial implications of insecure AI applications are substantial. IBM estimates that breaches involving shadow AI cost organizations an average of $670,000 more than other incidents. This highlights the urgent need for consistent security measures across all software development, whether it's crafted by professional engineers or by employees leveraging AI tools.
Gil Geron, CEO of Orca Security, emphasized the evolving landscape: "Everyone is a builder now. Developers are creating software in the pipeline, employees are building AI applications outside it, and the next generation of frontier AI models will increasingly generate and modify software on their own. Organizations need security that can keep pace with this shift without slowing innovation." He added that the AI Code Security Auditor prepares customers for AI-assisted development, while AI AppGen Security addresses applications built outside traditional boundaries, ensuring security teams have the context needed to prioritize exploitable risks.
Orca AI AppGen Security is designed to provide security teams with much-needed visibility and control over applications developed outside the standard pipeline. It achieves this by discovering AI-generated applications and their creators, mapping the associated risks across APIs, integrations, and data access, and prioritizing high-risk exposures based on their potential business impact.
On the other hand, the Orca Code Security Auditor focuses on securing AI-assisted development within traditional workflows. It employs AI-powered code analysis to find vulnerabilities that traditional static analysis tools might miss, conducts full repository scanning for advanced model vulnerabilities, and prioritizes exploitable risks, allowing development teams to focus on threats that attackers can realistically leverage.
Sangram Dash, CISO at Sisense, shared his perspective on the challenges: "My developers and my business teams are both shipping software faster than my team can review it, and the apps built outside our pipeline were a complete blind spot." He noted that having visibility into exploitable code and employee-built AI applications on a single platform allows for faster innovation while maintaining governance.
Ultimately, Orca Security's new capabilities aim to provide a unified security approach for the modern software development environment. By extending the Orca Platform to cover both AI-assisted and AI-generated applications, the company seeks to ensure that security teams can maintain visibility, context, and risk prioritization, regardless of where or how software is created.