Aptori Launches Code-Q for Automated Vulnerability Remediation
San Francisco-based Aptori has announced the general availability of Code-Q, an AI-driven agent that automates code-level remediation for confirmed vulnerabilities, according to a press release. The new tool extends Aptori’s AI Triage system by not only validating vulnerabilities but also generating and verifying fixes directly within developer environments.
Code-Q uses a semantic graph of the codebase to reason about logic and produce deterministic, testable patches. Developers can review and merge these fixes within their IDE or CI/CD pipelines, supporting tools such as GitHub, GitLab, and Azure DevOps. This approach creates a closed-loop workflow from detection to remediation without leaving the development environment.
The system builds on Aptori’s SMART engine (Semantic Modeling for Application & API Risk Testing), which maps data flows and authorization logic to identify root causes of vulnerabilities. Each fix is transparent and auditable, showing what changes were made and why, enabling compliance with standards like SOC 2 and PCI DSS.
Code-Q is available now as part of the Aptori platform, offering integration options for enterprises with strict data governance and compliance needs.
We hope you enjoyed this article.
Consider subscribing to one of our newsletters like AI Programming Weekly or Daily AI Brief.
Also, consider following us on social media:
Subscribe to AI Programming Weekly
Weekly news about AI tools for software engineers, AI enabled IDE's and much more.
Market report
2025 State of Data Security Report: Quantifying AI’s Impact on Data Risk
The 2025 State of Data Security Report by Varonis analyzes the impact of AI on data security across 1,000 IT environments. It highlights critical vulnerabilities such as exposed sensitive cloud data, ghost users, and unsanctioned AI applications. The report emphasizes the need for robust data governance and security measures to mitigate AI-related risks.
Read more