Aptori has released its latest AI agent, called Code-Q. It claims it will automatically generate, validate and apply code-level remediations for confirmed vulnerabilities. It’s an interesting twist in how security teams and developers respond to security issues. It shifts testing into being proactive based on known vulnerabilities rather than just repeatedly running scripts.
Code-Q is the next step in Aptori’s plan to improve software testing and quality. In September, it released AI Triage. It marks a shift in dealing with vulnerabilities by focusing on those that can be exploited. In doing so, it helps security teams prioritise systems at risk. With Code-Q, it not only identifies real risk but delivers code correction.

Sumeet Singh, Founder and CEO of Aptori, said, “Security tools have gotten better at identifying problems. The challenge is turning that insight into action.
“Aptori’s Code-Q generates and validates the same kind of fix a skilled developer would write, complete with explainable context, letting organizations resolve the most critical vulnerabilities without adding friction. We designed Code-Q to deliver verified, reproducible outcomes that developers can trust. It’s security automation that speaks their language.”
Directly addressing risk improves security
Patching is a major time suck. Security teams are faced with an increasing number of patches to apply every month. It takes time to filter through those patches to find products that need patching. But all that delivers is a list of patchable products. It does not imply risk, which means a lot of time is lost patching systems that are either not at risk or where the risk is very low.
The major security risk players, like BlueVoyant, have shifted their risk focus to where vulnerabilities exist in exposed systems. It allows security and operations teams to create priority lists of what to patch first. That means that resources are more focused on improving security rather than just ticking boxes.
But at the code level, it is a different story. Many of the AI efforts for developers are based on saving them time in writing code. The AI agents generate code, and if the developers want, can also generate testing for that code. The issue with this is that the AI tools are often not trained on vulnerabilities or what to look for.
Aptori is focused on the code that is in use. Its AI agents are trained on known vulnerabilities and risks. This allows tools such as AI Triage to identify the risk to code in both development and production. The addition of Code-Q takes that known risk and delivers a way to test and resolve it.
According to Aptori, Code-Q does this by using “a semantic graph of the codebase to reason about intent and generate verifiable, testable fixes. Developers can review, validate and merge directly within their IDE or CI/CD environment. The result is a closed-loop system where every confirmed finding can be remediated quickly and transparently.”
Making shift left a reality, not PowerPoint fluff
What is interesting about this is that it marks a real delivery point on the idea of shifting left. That is the goal of moving security earlier into the development cycle, rather than leaving it to testing or production. Most of the efforts to date are about process and repurposing tools.
Both AI Triage and Code-Q are built on Aptori’s SMART (Semantic Modeling for Application & API Risk Testing) engine. By mapping the entire stack in real time, it can see what is running, where it runs and what risks it poses. Where there is an issue with code vulnerability, it can also help with a prioritisation list of what to deal with.
Perhaps the biggest gain here, however, is that SMART also looks at misconfigurations. That represents a significant area of risk that is not addressed by other security software. Fidelis Security claims that cloud misconfigurations cause 99% of security failures. That’s up from 80% of exposures identified by XM Cyber (registration required) in its 2024 analysis of 40 million exposures.
Another move by Aptori to make this developer-friendly is that Code-Q can be embedded into existing workflows. It lowers the learning curve for developers to incorporate it into their processes. According to the announcement, “It can be triggered automatically as part of a “git push → scan → fix” sequence or invoked manually by developers reviewing triaged vulnerabilities.”
Enterprise Times: What does this mean?
Identifying and remediating vulnerabilities is hard. The effort taken distracts from other security efforts, taking both time and budget. Aptori is refocusing security where it can do the best by doing it earlier in the development cycle. For organisations that have adopted the mantra of shift-left, this finally gives them a way to prove ROI from doing so.
But this is more than just a developer solution. Support for detecting misconfigurations is critical for improving IT operations, especially in multi-cloud environments. As noted, this is a major cause of security breaches, and it will be interesting to see if Aptori starts releasing statistics about the number of breaches prevented.
For developers, having this as part of their workflow will make adoption easier. The easier it is to integrate, the more likely they are to use it. If it delivers trusted alerts, tests and remediation code, adoption is likely to be rapid.

















