Maze launches AI security agents for code and cloud
Maze has launched Maze Code, a new product suite that uses AI agents to investigate vulnerabilities in application code and dependencies, verify which issues are exploitable and automate fixes. The move extends the company’s existing cloud security platform into code security and aims to cut noise for teams shipping software faster.
Why it matters: - Maze is trying to replace rules-based security scanning with AI agents that judge whether vulnerabilities are exploitable in a specific environment. - The launch targets a core pain point for security teams: most scanner findings are noise, while attackers and coding agents are both increasing the pace of risk. - Maze says the combined Maze Code and Maze Cloud platform gives teams one engine for code and cloud risk, which could reduce duplicate alerts and speed remediation.
What happened: - Maze launched Maze Code on June 23, 2026, expanding its platform from cloud security into code security. - Maze Code uses AI agents for AI-SCA, which investigates dependency vulnerabilities, and AI-SAST, which investigates vulnerabilities in code teams write. - The product is designed to separate noise from risk and automate remediation. - Maze says Maze Code and Maze Cloud make the company the first security platform to investigate every vulnerability with AI agents across both code and cloud on a single engine.
The details: - Maze agents analyze a team’s code, cloud environment, compensating controls and business context before judging whether a finding is exploitable. - When a vulnerability is exploitable, the agents trace the root cause, verify a fix and deliver it as a pull request, inside a coding agent such as Claude, Cursor or Windsurf, or as a ticket to the developer who owns the code. - Maze Code can ingest findings from existing scanners or operate as the scanner itself. - For dependency issues, the agents build AI call graphs to trace reachability through dynamic calls. - The system then weighs build and runtime context to distinguish real risk from noise. - For code written by the team, Maze agents read structure and data flow to understand how the code works. - Maze says the platform can detect SQL injection, cross-site scripting, hardcoded credentials, novel vulnerabilities and business logic flaws. - When several findings share a root cause, Maze Code prioritizes remediation with a single fix. - Every verdict includes the evidence behind it. - Maze says about 80% to 90% of vulnerabilities are not exploitable, and early results suggest about 90% of CVEs are not exploitable in context. - Maze Code has already found CVEs in open-source projects and surfaced issues in customer environments, including MFA bypass and cross-tenant data access, with verified fixes. - Maze Code works on its own or alongside Maze Cloud. - More information is available at Maze's contact page and the company website.
Between the lines: - Maze is positioning AI as the answer to a broader industry shift: more code is shipping faster, while attackers also get AI tools that can find and exploit flaws faster. - The company is also arguing that not all AI security products are equal, and that training agents on verified investigations matters more than adding AI features to legacy scanners. - By linking code and cloud context, Maze is betting that security teams want one decision engine rather than separate tools that repeat the same alert.
What's next: - Maze is directing prospects to book demos to see Maze Code in action. - The company appears to be using early findings in open-source and customer environments to support broader adoption of the product suite. - If Maze can sustain low-noise, verified remediation at scale, the platform could appeal to teams trying to secure both software delivery and cloud environments with fewer manual reviews.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The Business Gazette Online
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.