Apiiro Launches AutoFix AI to Fix Design and Code Risks

thumbnail Apiiro Launches AutoFix AI to Fix Design and Code Risks

Apiiro launches AutoFix AI Agent to auto-remediate code and design risks in IDEs using runtime context, bridging AI coding and secure development.

Written By: Jordan Smith
Aug 4, 2025
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Agentic application security platform Apiiro is debuting AutoFix AI Agent, an industry-first AI agent that automatically fixes design and code risks using runtime context. 

Meeting developers where they are through MCP connection

The tool can operate within a developer’s integrated development environment (IDE) without needing plug-ins, using a remote Model Context Protocol (MCP) connection.

“We’re meeting developers where they are– in their IDEs with deep code-to-runtime context– and giving them the secure path forward without slowing them down,” said Moti Gindi, Chief Product Officer at Apiiro. “It’s about empowering developers to fix risks and not vulnerabilities– in real time, with the runtime context, software architecture, and organization policy.”

Apiiro cites the growth of AI coding assistants in the market, such as GitHub Copilot, Gemini Code Assist, and Cursor, as a key reason for developing the tool. Since AI code assistants operate without or with limited context and aren’t governed by existing security tools. This opens the door for more vulnerabilities, unvetted technologies, business logic risks, and code that can bypass organizational security policies and architectural standards.

Risks found in AI-generated code

According to the Center for Security and Emerging Technologies (CSET), a policy research organization within Georgetown University’s Walsh School of Foreign Service, up to 50 percent of AI code assistants generate code containing vulnerabilities. In comparison, 10 percent of those are actively exploitable with true business impact.

CSET states that the ability of large language models (LLMs) and other AI systems to generate computer code poses direct and indirect cybersecurity risks. Among these risks are models generating insecure code, models being vulnerable to attack and manipulation, and downstream cybersecurity impacts, such as feedback loops that affect the training of future AI systems.

CSET found that code generation models require evaluation for security, a task that is currently challenging.

“Evaluation benchmarks for code generation models often focus on the models’ ability to produce functional code, but do not assess their ability to generate secure code, which may incentivize a deprioritization of security over functionality during model training,” the report states.

Tool built for scale and reliability

The AutoFix AI Agent scales expertise across development teams and automatically generates threat models for risky feature requests before any code is written, and fixes SAST, SCA, secrets, and API security findings. The agent leverages a unique runtime context to make precise, risk-based decisions, understanding each organization’s specific software architecture, security policies, business impact, and risk acceptance lifecycle. This enables the tool to deliver autofixes that align with enterprise standards, rather than relying on one-size-fits-all solutions.

“AI code assistants represent one of the most transformative productivity tools of our lifetime. But by focusing solely on code, they lack context– missing critical signals like security policies and standards, compensating controls, and business risk,” said Idan Plotnik, Co-founder and CEO of Apiiro. “This disconnect introduces significant risk to enterprises, as ungoverned AI coding tools are adopted faster than application security teams can keep up. Our AutoFix AI Agent doesn’t just detect issues– it intelligently fixes them using the same contextual understanding and organizational knowledge that application security and risk management teams rely on to make informed decisions.”

The AutoFix AI Agent utilizes unique data generated from Apiiro’s platform that creates a map of software architecture across all material changes, powered by its Deep Code Analysis (DCA), Code-to-Runtime matching, and Risk Graph engine.

Among the core capabilities of the AI Agent are:

  • AutoFix, which automatically fixes designs and code risks with runtime context.
  • AutoGovern to enforce policies, standards, and secure coding guardrails automatically.
  • AutoManage for automating risk lifecycle management measurement across the SDLC.

“In a world where AI generates code, no software should ship without an AI AppSec agent securing it,” said Plotnik. “We’re enabling security teams to unlock full developer productivity while automatically fixing the most critical risks to the business.”

AI is impacting nearly every aspect of the channel, and we’re seeing more channel marketers begin to adopt the technology to equip themselves with the necessary tools and strategies. Read more about the AI webinars, guides, and certifications from the CMA and channelWise geared toward practical AI adoption. 

thumbnail Jordan Smith

Jordan Smith is a news writer who has seven years of experience as a journalist, copywriter, podcaster, and copyeditor. He has worked with both written and audio media formats, contributing to IT publications such as MeriTalk, HCLTech, and Channel Insider, and participating in podcasts and panel moderation for IT events.

Recommended for you...

Guardrails for AI Agents: Noma Secures $100M Boost

Noma Security raises $100M Series B to help enterprises govern and secure autonomous AI agents as demand for agent oversight rapidly accelerates.

Trend Micro and Google Cloud Double Down on AI Security

The expanded alliance emphasizes AI-driven defenses, sovereign cloud capabilities, and new anti-scam protections for businesses worldwide.

Allison Francis
Jul 30, 2025
Arctera Updates Platform to Reduce AI Compliance Risks

Arctera updates Insight to help organizations capture, chronicle & contain AI data, easing compliance and unlocking insights from LLM interactions.

TA Wordpress
Jul 30, 2025
Video: How Port Is Redefining Developer Portals for the AI Era

Discover how Port’s AI-native developer portal is helping engineering teams streamline workflows, reduce DevOps bottlenecks, and build scalable software faster.

Katie Bavoso
Jul 29, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.