Cycode Launches Agentic Workflows To Automate Application Security Response

Cycode has introduced Agentic Workflows, a new capability that uses AI agents to detect, prioritize, and address application security risks as soon as they appear.

The launch expands Cycode’s Agentic Development Security platform and is intended to move security programs from human-driven and agent-assisted processes toward an agent-driven model governed by human-defined controls.

Security teams can configure a workflow by defining the event that triggers it, the sequence of actions agents should perform, and the confidence thresholds or approval requirements governing each step.

Once configured, the workflow can begin automatically when a qualifying security event occurs.

Potential triggers include the discovery of a critical vulnerability in a high-value application, a missed remediation deadline for an exploitable issue or a developer ignoring a finding that the security team considers high risk.

Organizations determine which actions agents can complete autonomously and which require human review before proceeding.

The capability is designed to address the growing gap between the speed of software development and the capacity of security teams to investigate and remediate every identified risk.

AI-assisted development allows organizations to produce and modify code faster, but it can also increase the volume of applications, dependencies, and security findings that require review.

Security teams must also contend with newly disclosed vulnerabilities, AI-specific attack techniques and shorter periods between the public disclosure of a weakness and its exploitation by attackers.

Traditional workflows frequently depend on a person noticing a finding, determining its importance, contacting the appropriate developer and tracking the issue until it is resolved.

Cycode argues that this operating model cannot scale as development activity and security data increase.

Agentic Workflows are designed to perform much of this analysis and coordination automatically while keeping security teams responsible for defining the boundaries of autonomy.

Cycode CEO and co-founder Lior Levy said organizations cannot solve the problem solely by hiring more security professionals because risk is outpacing human-operated processes.

The company offers a library of preconfigured workflow templates that customers can use without modification or customize to meet their own security policies.

The templates cover autonomous vulnerability triage and remediation, security backlog reduction, service-level agreement escalation, exception management, and container remediation.

Security backlogs consist of vulnerabilities and policy violations that have been identified but not yet resolved. These backlogs can become difficult to manage when security tools generate more findings than development teams can reasonably address.

An agentic workflow can continuously review the backlog, determine which issues present the highest risk and initiate appropriate actions based on the organization’s rules.

For service-level agreement management, an agent could detect that a critical vulnerability has remained unresolved beyond the permitted period and automatically escalate the issue to the relevant team.

Container remediation workflows could address vulnerabilities involving packaged application environments used to deploy software across cloud and data center infrastructure.

Cycode also provided an example involving exception management.

Developers may occasionally mark a vulnerability as ignored because they believe it does not present a meaningful risk within the application’s specific environment.

Under Cycode’s template, changing a high-risk vulnerability with a known exploit from open to ignored can automatically trigger an exploitability analysis.

When the analysis determines that the issue is not exploitable, the agent may recommend accepting the developer’s exception.

When the workflow identifies high-confidence evidence that the vulnerability is exploitable, it can reopen the finding, depending on the permissions and controls established by the security team.

This approach is intended to reduce unnecessary work without allowing potentially dangerous exceptions to remain unexamined.

A vulnerability’s severity rating does not always indicate whether attackers can exploit it within a particular application.

Context such as application exposure, runtime behavior, security controls, reachable code and the importance of the affected system can determine whether a finding requires immediate action.

Cycode’s broader platform correlates this information across the application development lifecycle to help agents make more informed decisions.

The application development lifecycle includes the processes used to plan, create, test, deploy and operate software.

Cycode describes its platform as securing AI development from the initial prompt through runtime operations.

The technology identifies risks across development environments, monitors the AI tools developers use and connects information from code repositories, build systems, cloud platforms and other parts of the software supply chain.

Cycode then uses that context to deploy and manage agents that can prevent or address risks at the speed of AI-assisted development.

Agentic Workflows are designed to convert that intelligence into action rather than limiting the platform to detection and recommendations.

The company’s model keeps human experts involved through policy design, confidence thresholds and approval requirements.

A security team could allow an agent to gather evidence and autonomously prioritize an issue, but require approval before changing application code or closing a vulnerability.

For lower-risk, highly repeatable activities, the organization could allow the agent to complete the entire workflow without manual intervention.

This structure allows customers to gradually increase their autonomy as they gain confidence in the agents’ accuracy and reliability.

Cycode said Agentic Workflows are currently available through an early access program.

The company plans to demonstrate the technology at Black Hat USA 2026 in Las Vegas.

KEY QUOTE:

“Risk now moves at machine speed while security stays bottlenecked at human speed, and no team can hire its way out of that gap. Waiting for a person to notice each risk and start each response is no longer a viable way to operate.”

“Agentic Workflows remove that constraint without removing control. Agents triage and remediate the moment risk appears, and security teams set the scope and the boundaries of autonomy.”

Lior Levy, Co-Founder and CEO of Cycode