Aptori Is Building an Agentic AI Security Engineer

The New StackAbout 4 min readJun 4, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

AI security engineer, Gen AI, SDLC, code scanning, vulnerability testing, access control, triage, code fixes, private instance deployment, compliance controls, alert fatigue, assistive technology, agentic systems, determinism, secret sauce, ML, proprietary technology.

Apptory: An AI Security Engineer

Background and Motivation

  • Apptory was born out of the experience of helping large, regulated companies (telecoms, financial institutions) digitally transform.
  • These companies wanted to achieve DevOps practices and release software quickly, but were hindered by extensive security requirements.
  • The core problem: Security checks were a bottleneck, preventing rapid releases despite advancements in infrastructure automation.

Apptory's Solution: AI-Powered Security

  • Apptory is positioned as an "AI security engineer" designed to integrate into the Software Development Life Cycle (SDLC).
  • It uses AI agents to:
    • Scan code for security weaknesses.
    • Test applications and APIs for vulnerabilities, especially related to access control.
    • Triage issues, providing a transparent thought process behind the findings.
    • Generate code fixes in real-time.
  • The goal is to enable developers to build secure software from the start, rather than bolting security on at the end.

How Apptory Works

  • Real-time Integration: Apptory integrates into the Git workflow. As a developer creates a merge request, Apptory immediately scans the code, identifies issues, suggests fixes, and provides reasoning.
  • Interactive Agent: Developers can interact with the AI agent directly within Git, asking for more information or clarification on the suggested fixes.
  • Private Instance Deployment: Apptory is deployed as a private instance within the customer's environment (VPC or on-prem), ensuring data privacy and control. Apptory (the company) has limited visibility into customer usage.

Target Customers and Their Needs

  • Apptory targets large enterprises in regulated industries (banks, telecoms).
  • These organizations typically have:
    • A vast number of APIs (15,000-20,000).
    • Thousands of engineers.
    • Hundreds of compliance controls.
  • Apptory acts as a "proxy" for the security engineering team, automating the validation of compliance controls and providing real-time feedback to developers.

Addressing Alert Fatigue

  • A key challenge in security is alert fatigue, where developers are overwhelmed with security warnings.
  • Apptory addresses this by:
    • Providing code fixes, not just identifying problems.
    • Explaining the reasoning behind the fixes, helping developers learn and avoid repeating mistakes.
    • Offering a two-way communication channel for developers to ask questions and get clarification.

Evolution of the Product

  • The initial version of Apptory relied more heavily on traditional Machine Learning (ML).
  • The integration of Gen AI, particularly models like Gemini Flash, has significantly improved the product's capabilities, especially in generating code fixes and providing real-time responses.
  • Early versions struggled with the speed of generating code fixes, which made them less usable.

Acceptance of AI-Generated Code

  • Internally, Apptory's engineers find the AI-generated code fixes very useful.
  • The acceptance rate among enterprise customers is not directly tracked due to the private deployment model.
  • The speaker emphasizes the importance of evaluating AI systems not just on autonomy, but also on the quality of their work and their impact on privacy.

Beyond Security: Expanding Agent Capabilities

  • Apptory is exploring expanding its capabilities beyond security, leveraging its agent framework for other tasks.
  • One potential area is compliance, where an agent could answer compliance-related queries and help fill out forms.
  • The underlying framework is designed to tailor itself to specific needs, with the enterprise owning the weights of the models.
  • The speaker acknowledges the challenge of focus for startups but emphasizes the mission to build secure, high-quality software from the start.

The Agent-Based Architecture

  • Apptory's architecture is based on the concept of "agents," each with its own persona and specific skills.
  • Each agent could potentially be a standalone startup, highlighting the rapid pace of innovation in the field.

Competitive Advantage: The "Secret Sauce"

  • Apptory's competitive advantage lies in its combination of Gen AI with proprietary ML and deterministic processes.
  • It's not "all Gen AI."
  • For example, when scanning code or APIs, Apptory ensures that all relevant security controls are checked, rather than relying solely on the AI's "greedy" approach.
  • This "secret sauce" is crucial for building reliable and trustworthy security systems.

The Reality of AI in Enterprise

  • The speaker notes that even with advanced AI systems, the underlying infrastructure often relies on traditional technologies.
  • He uses the example of a transaction in a keynote demonstration, pointing out that the final step likely involved a REST API call to a mainframe.

Conclusion

Apptory is leveraging AI to address the critical need for faster and more secure software development in regulated industries. By providing AI-powered security agents that integrate directly into the SDLC, Apptory aims to empower developers to build secure software from the start, reducing the burden on security teams and enabling faster release cycles. The company's focus on private deployment, combined with its "secret sauce" of combining Gen AI with proprietary technologies, positions it as a unique player in the evolving landscape of AI-powered security solutions.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.