SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
Enterprise devops secops room dashboard threat graphs containers

Armis unveils AI-native Centrix platform for app security

Wed, 11th Feb 2026

Armis has launched a new application security product under its Centrix brand, pitching it as a single platform to secure software across the development lifecycle as organisations contend with growing volumes of code and more AI-assisted development.

The product, Armis Centrix for Application Security, targets security teams managing risk across source code, build pipelines, and production environments. Armis positions application code and related components as a primary attack vector, with vulnerabilities introduced during rapid development cycles and propagated through software supply chains.

Nadir Izrael, CTO and co-founder of Armis, tied the launch to changing development practices and the use of generative AI coding tools.

"To effectively manage risk, it's essential to get to the root cause of the problem and weed it out," Izrael said. "Code-based vulnerabilities are being embedded into organisational infrastructure, and AI-generated code is exacerbating the problem, containing exponentially more vulnerabilities when compared to code written by human developers. As enterprises embrace AI-assisted coding and drive continuous development pipelines, they need a smarter, more dynamic, and unified approach to securing software at scale."

Platform approach

Armis describes the application security market as fragmented, with multiple point tools creating overlap and noise. It says the new product focuses on detection, contextualisation, and remediation. The platform is described as "infrastructure-aware," taking into account the CI/CD pipeline and production controls.

Armis says the product scans across an organisation's application estate, including source code, third-party dependencies, container images, and configuration files. It also claims support for an unlimited number of programming languages and variants.

The platform is designed to detect known issues as well as variants that can evade template-based approaches. Armis says it flags problematic code before it creates operational or security impact, aiming to reduce alert fatigue and improve response times for development teams.

DevSecOps pressures

The launch comes as security leaders face pressure to align security checks with faster release cadences. Armis is pitching the product as part of a broader shift toward embedding security throughout development workflows, rather than relying on late-stage testing.

Katie Norton, research manager for DevSecOps and software supply chain security at IDC, said AI-assisted coding changes how quickly vulnerabilities can enter software.

"With AI-assisted coding, developers can ship faster, but they can also introduce security vulnerabilities just as fast. As a result, security teams are under pressure to respond at the same speed and scale," Norton said. "The AI-native scanning, platform-level context, and independent validation Armis Centrix delivers could benefit security teams trying to keep up with this new era of development."

Claims and metrics

Armis made several performance claims for the platform, including a 70% reduction in false alarms and faster mean time to resolution. It also says it automates remediation workflows by routing findings to the appropriate developer with instructions.

The platform is designed to integrate with existing development and security tools, with onboarding and coverage from source code through production systems. Armis says these elements help reduce friction between security and software teams.

Dana Gilboa, chief product officer of Armis, said the company differentiates on detection accuracy and coverage across programming languages.

"Armis is delivering smarter detection, faster fixes, reduced cost, and higher trust between security and development teams," Gilboa said. "Other solutions on the market cannot compete; Armis' AI graduates from the pattern matching capabilities offered by other solutions providers and is highly accurate, catching all of the vulnerability variants across an unlimited number of languages, not just a few. This solution is the enterprise foundation for secure-by-default software delivery at scale."

Armis also pointed to results from the Public CASTLE Benchmark C@250, which it described as a third-party verified test of a tool's ability to detect and stop code issues before deployment. It said Armis Centrix for Application Security achieved the highest performance in that benchmark compared with other listed tools.

Armis Centrix for Application Security is available immediately.