ArmorCode adds AI agents to Anya security platform
Wed, 5th Aug 2026 (Today)
ArmorCode has added four AI agents to its Anya security platform and expanded its Context Risk Graph with new analysis and patching features.
The additions are intended to help security teams identify which vulnerabilities pose material business risk and avoid repeating AI analysis on the same issues.
The new Anya agents are Vulnerability Researcher, Mitigation Engineer, Cloud Security Engineer and Patch Orchestrator. They are aimed at application and product security teams that need to assess exploitability, apply interim controls, review cloud exposures and coordinate software patching.
Vulnerability Researcher examines the real-world exploitability of a common vulnerabilities and exposures entry within an organisation's environment and explains how it could be used in an attack. Mitigation Engineer works with existing compensating controls, such as web application firewall rules and endpoint detection and response policies, while a permanent fix is pending.
Cloud Security Engineer focuses on cloud misconfigurations and exposures, assessing them against the wider environment to identify business-impacting risks. Patch Orchestrator plans and sequences patch deployment across affected systems to reduce disruption during remediation.
Risk context
Alongside the AI agents, ArmorCode has broadened the Context Risk Graph, which it describes as the core system connecting security findings with asset inventory, ownership, business context, threat intelligence and remediation data. The latest changes include expanded attack path analysis, additional network topology and reachability context, and patch management integration.
The attack path analysis is designed to correlate vulnerability findings with environmental data to determine what is reachable and exploitable. The network context traces how exposures connect across applications, cloud environments, containers, infrastructure and networks. The patching integration is intended to help teams understand patch availability and coordinate remediation through existing systems.
ArmorCode says the graph also works with existing compensating controls, including web application firewalls and endpoint detection and response tools, to reduce exposure before permanent fixes are applied.
ArmorCode argues that security teams are dealing with rising numbers of vulnerabilities across applications, infrastructure, containers, cloud estates and software supply chains, while attackers can chain isolated weaknesses into broader attack paths. In that environment, AI systems without enough context can produce poor recommendations and increase costs when multiple tools analyse the same issue separately.
Mark Lambert outlined that position in comments accompanying the launch.
"Finding vulnerabilities was never the hard part. The challenge is understanding which findings create real attack paths and what actions will reduce risk. Threat actors can cheaply chain together findings that teams previously deprioritized in attacks, and defenders find that AI without context is both inaccurate and expensive. ArmorCode gives AI the security context it needs to fix what actually matters, and do it economically," said Mark Lambert, Chief Product Officer, ArmorCode.
Scale claims
ArmorCode says its platform processes more than 300 billion findings a year across more than 375 integrations. Organisations can use prebuilt agents or create custom agents through what it calls the Anya harness to match internal security processes and policies.
The company linked the latest product changes to a broader push among corporate security teams to adopt AI while controlling spending on model usage and automation workflows. The aim is to let teams reuse shared context instead of building separate agents or paying multiple times for similar analysis.
Chandra Sekar, the company's Chief Marketing Officer, framed the move in terms of both budget discipline and security prioritisation.
"Every security team is being pushed to adopt AI, and every finance leader is watching the AI bill climb. ArmorCode brings financial and risk discipline to agentic remediation so enterprises can make smarter security decisions without the runaway costs of pointing AI at everything," said Sekar.
ArmorCode also cited customer outcome figures tied to its wider exposure management platform. It said correlating security and business context helps organisations identify roughly 3% of findings that account for about 80% of actual risk.
According to the company, customers have achieved a 75% reduction in mean time to remediate, a 60% reduction in vulnerability backlog and more than a 3x first-year return on investment.
The launch places ArmorCode in a growing segment of cybersecurity suppliers using AI agents to move beyond detection into remediation planning, while trying to ground automated actions in operational and business context rather than raw alert volumes.