AGP Picks
View all

Phoenix Security launches Purple to scan AI-generated code

Jul. 28, 2026
By AI, Created 11:21 UTC, Jul 28, 2026, AGP -

Phoenix Security has launched Phoenix Purple, a new application security platform built to analyze code produced by AI coding agents and deliver fixes as pull requests. The company says the graph-native system can cut token-scanning costs by a modeled 10x to 33x versus file-by-file scanning while extending its existing ASPM platform into the code-generation stage.

Why it matters: - AI coding agents are producing more of the code that ships into production, which raises the risk of vulnerabilities entering repositories before human review catches them. - Security teams are under pressure to find and fix issues faster as the time between vulnerability disclosure and active exploitation continues to shrink. - Token cost is becoming a practical limit for organizations using large language models to scan code at scale.

What happened: - Phoenix Security announced general availability of Phoenix Purple, an application security platform for analyzing code produced by AI coding agents. - The launch extends Phoenix Orange, Phoenix Security’s existing Application Security Posture Management platform. - The platform integrates with AI coding assistants and supports Cursor, VS Code, Claude Code, and Windsurf through Purplephx integration. - A GitHub application scans pull requests without continuous-integration setup and adds inline comments that explain the issue, its relevance, and a proposed fix. - An MCP server integration makes the knowledge graph queryable from the coding agent.

The details: - Phoenix Purple builds a knowledge graph once, parsing seven programming languages and mapping call graphs, taint traces, entry points, and reachable paths. - Subsequent scans navigate that graph instead of re-reading the full repository. - In a modeled scenario covering 1,000 repositories with 250,000 lines each and monthly scans, Phoenix Security calculated graph-native scanning at $3.60 per confirmed vulnerability versus $64.30 for a file-by-file approach. - The company says that is about 87% lower for equivalent findings and provides a public cost calculator. - The platform performs pull-request analysis against the graph, including call-graph neighbors affected by a change even if those files were not directly modified. - Phoenix Security calls that N+1 contextual analysis. - Across multiple repositories, Phoenix Purple attributes a vulnerability in a shared library to each repository that imports it, assesses reachability per repository, and routes findings to the owning team. - Findings are ranked using reachability, threat intelligence, fixability, ability to chain and combine into an exploit, weaponization signal, and business context. - Confirmed findings are delivered as pull requests with threat context. - Breaking or high-risk changes require explicit human approval before merging. - No change is merged automatically.

Between the lines: - Phoenix Purple is aimed at the gap between AI-assisted development speed and traditional security review workflows. - The graph-based approach is designed to reduce repeated model calls by focusing analysis on code paths that matter, rather than scanning an entire repository each time. - The product also reflects a broader push to move application security earlier in the development lifecycle, where remediation may be cheaper and faster. - Phoenix Security is positioning cost efficiency as a key differentiator in AI-assisted security scanning, not just detection quality.

What's next: - Phoenix Purple is now generally available, and Phoenix Security is steering users toward its public cost calculator to estimate savings. - The platform is intended to work alongside Phoenix Orange, which continues to aggregate findings, filter unreachable issues, attribute problems to owning teams, and connect code findings to cloud services. - Phoenix Security says Phoenix Orange is in production at ClearBank, Bazaarvoice, and Integral Ad Science (IAS). - The company reports Phoenix Orange deployments have delivered a 98% reduction in container vulnerabilities at ClearBank, $6.3 million in developer time saved at Bazaarvoice, and a 78% reduction in active container vulnerabilities plus $1.95 million saved at IAS. - Phoenix Purple extends that platform to the code-generation stage of software development.

The bottom line: - Phoenix Security is betting that graph-native analysis can make AI-era code scanning faster, cheaper, and more actionable without removing human approval from higher-risk fixes.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Grand Canyon State News

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Grand Canyon State News

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.