AGP Picks
View all

Phoenix Security adds graph-native SAST and SCA to Phoenix Purple

Jul. 28, 2026
By AI, Created 11:14 UTC, Jul 28, 2026, AGP -

Phoenix Security on July 28, 2026 launched graph-native static and dependency scanning in Phoenix Purple, its agentic code analysis platform, with one-click assessment and remediation. The release aims to cut through fragmented scanner output by ranking findings by reachability, exploitability and fix impact before teams merge changes.

Why it matters: - Application security teams often get thousands of isolated findings from separate scanners with no shared context. - Phoenix Security is trying to turn that noise into a single ranked remediation plan that shows which issues are reachable, chainable and safe to fix. - The update matters because the time between vulnerability disclosure and real-world exploitation is now measured in hours.

What happened: - Phoenix Security launched graph-native SAST and SCA in Phoenix Purple, its agentic code analysis platform, on July 28, 2026. - The release adds one-click assessment and one-click remediation. - The platform combines deterministic, rule-based scanning with a continuously rebuilt knowledge graph. - The goal is to convert fragmented scanner output into a ranked, actionable remediation plan.

The details: - Graph-native SAST runs static analysis against the knowledge graph instead of file by file. - The graph resolves call paths, taint flow and entry points, so analysis follows reachable paths through code. - Teams can choose the ruleset appropriate to their language. - SCA summarizes findings per library and surfaces associated CVEs and affected code. - Reachability analysis identifies which vulnerable libraries are actually reachable in running code. - Phoenix Purple offers four scan modes: quick, full, smart and deep. - Quick and full are the default everyday modes. - The chainability map correlates findings across code and libraries. - The map ranks issues by complexity, chainability and exploitability. - The platform can show how multiple vulnerabilities can combine into a working attack path. - One-click assessment evaluates whether a finding is real, reachable and chainable into an active exploit. - The assessment returns an exploitability ranking and a breaking-change verdict. - The verdict tiers are simple to execute, potentially breaking, definitely breaking or unknown. - One-click remediation generates a plan instead of a ticket. - Phoenix identifies affected files, bundles related fixes and surfaces compensating controls. - The platform delivers the fix as a pull request with the reasoning included. - Fixes are broken down by simplicity so teams can schedule them by effort. - Breaking changes are held for human approval. - Nothing merges without review. - All capabilities run on the continuously rebuilt knowledge graph, which is designed to keep token consumption low by avoiding repeated codebase re-reading. - Modeled cost comparisons are available at ai-scan-cost.phoenix.security.

Between the lines: - Phoenix Security is positioning the product around remediation speed, not just detection. - The emphasis on reachability and chainability reflects a broader shift in application security toward triage that prioritizes exploitable risk over raw vulnerability counts. - The knowledge-graph approach is also meant to reduce compute overhead, which could matter for teams running large codebases or frequent scans.

What's next: - Additional capabilities are set to ship through the Phoenix Purple launch campaign over the following weeks. - Phoenix Security plans to release the control framework white paper at Black Hat. - Cost modeling is already available online.

The bottom line: - Phoenix Security is trying to make application security output more actionable by linking code, dependencies and exploit paths into one ranked fix list.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Grand Canyon State News

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Grand Canyon State News

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.