of AI-generated code fails the security test
Tested across more than 100 models and 80 coding tasks. For Java the failure rate reaches 72 percent.
Veracode GenAI Code Security ReportRule-based scanners still reliably find what they were built for: syntax flaws. What hurts today — broken authorization, business logic, wrongly assumed permissions — has no signature. We bring rules, AI reasoning and exploit validation into an order your team can actually operate.
All from publicly available primary and operator sources. Together they explain why volume and speed became a problem at the same time.
Tested across more than 100 models and 80 coding tasks. For Java the failure rate reaches 72 percent.
Veracode GenAI Code Security ReportThe 2025 edition explicitly covers BOLA and BFLA — precisely the flaws no pattern can express.
OWASP Top 10:2025Share of KEV entries with exploitation on or before the CVE publication date, first half of 2026.
CISA KEV catalogThe NVD has been operating in triage mode since April 2026. Waiting for complete databases is no longer a strategy.
NIST on the NVD transitionThe difference is not a tooling problem, it is a class problem. Both examples come from the same application.
# Findet jede Regel-Engine seit 2005query = "SELECT * FROM users WHERE id=" + req.iddb.execute(query)# → CWE-89 · SQL Injection · deterministisch erkennbar
A concatenated SQL query has a stable shape. That is exactly what rules are built for: fast, reproducible and cheap enough to run on every commit. Nobody replaces this layer.
That is why we replace nothing. We add a second layer on top that can reason about intent.
Each layer has its own class of flaws, its own cadence and its own price. Select a layer to see the deployment rule.
The question is never “which layer”, it is “which layer on which repository at which cadence”. We derive exactly that mapping with you — from exposure and data class, not from gut feeling.
Four steps separate a flagged piece of code from a real risk. Skip them and you are prioritising by feeling.
A rule or a model flags a location in the code. At this point, that is all it is.
The flagged location sits on a path that can be invoked from outside.
The service really is reachable: network path, identity, configuration.
The attack was executed against the running environment and it worked. From here it is no longer a suspicion.
What sits behind the path decides the order in which things get fixed.
Every step skipped without proof creates work in the wrong place. A finding rated critical without an attack path costs a development team real hours and erodes trust in the next finding. Conversely, a proven path justifies stopping a release immediately. The two are only distinguishable when validation is part of the process rather than a matter of debate.
We do not build a parallel organisation. We bring your existing toolchain into an order that holds — and take on the parts that need specialist knowledge.
Before another tool joins the stack, we clarify which layer makes sense on which repository at all.
Semantic code analysis is only as good as its acceptance criteria. We define them before the first run.
We test against the running system whether a finding really leads to an attack path.
Assistant-written code fails in predictable classes. That is exactly where the review starts.
The most mature finding goes nowhere if nobody is named. We close the gap between discovery and fix.
The same artefacts carry the audit, the customer questionnaire and the incident record — if they are produced that way from the start.
No platform migration, no big bang. The path works with what most organisations already have in place.
We review repositories, existing scanners, finding history and ownership. The result is a classification by exposure and data class — and an honest baseline.
AI SAST on the most critical repositories, calibrated against known findings. In parallel the first validations: which paths are actually reachable?
Gates in the build, fix proposals to the code owners, SLAs by exploitability. Exceptions get documented and receive an expiry date.
Periodic frontier analysis for the most critical applications, metrics reporting, course correction. As a managed service on request.
Artefacts you can keep using — in the sprint, in the audit and in the customer questionnaire.
All repositories by exposure, data class and ownership — the basis of every cadence decision.
Which layer on which repository at which frequency, including a cost and runtime estimate.
Confirmed attack paths with chain of evidence and reproduction steps — cleanly separated from unconfirmed leads.
Root-cause fix proposals, delivered as pull requests to the responsible code owners wherever possible.
In a form that fits the technical documentation required by CRA Annex I.
Share of validated findings, time from discovery to fix, ownership coverage and security debt by age.
We work along established references — so results convince internally and can be evidenced externally.
Annex I Part II requires effective vulnerability handling across the support period; test and assessment reports belong in the technical documentation.
Regulation (EU) 2024/2847A01 Broken Access Control remains number one and explicitly covers BOLA and BFLA. New at A03: Software Supply Chain Failures.
owasp.orgTestable requirements instead of opinions: the verification levels give code review and testing a defined scope.
Verification StandardThe reference frame for secure development practices that customers and regulators increasingly cite.
csrc.nist.govSupply chain integrity from source to artefact — the layer code scanning alone does not cover.
slsa.devA maturity model for security work: makes progress comparable across years rather than merely reportable.
owaspsamm.orgThe statements on this page rest on publicly available primary and operator sources. Here they are in the original.
Free knowledge pages from the Secure Software Development topic area — no form, no registration.
30 minutes, no sales pitch. We work out together which layer makes the biggest difference for you — and what you can safely skip.