Cycode launches agentic workflows for security teams
Wed, 29th Jul 2026 (Today)
Cycode has launched Agentic Workflows for software security teams. The feature is available in early access.
The San Francisco company says the product lets security teams deploy AI agents to detect, prioritise and fix risks across the application development lifecycle, within rules set by human operators.
Cycode is positioning the launch as a response to the growing speed and volume of software risk, particularly as companies adopt AI tools in development and face a wider range of vulnerabilities. Traditional security processes, which rely on people to identify and initiate responses to each issue, struggle to keep pace with new code, faster disclosure cycles and AI-specific weaknesses, it says.
Under the new model, a security team creates a workflow by setting the trigger events, the sequence of agent actions and the confidence thresholds for each step. Once configured, the workflow runs automatically when a specified event occurs, such as the appearance of a critical common vulnerability and exposure in an important application, a missed service-level agreement on an exploitable finding, or a high-risk issue a developer has ignored.
Teams can decide which actions proceed without review and which still require staff approval. Cycode describes the approach as a shift from human-led security operations with AI assistance to a model in which agents handle first-line action while people retain oversight.
Template library
To support adoption, Cycode is offering a library of pre-built workflow templates that teams can use as provided or adapt to their own policies. The templates cover autonomous triage and remediation, backlog reduction, service-level agreement escalation, exception management and container remediation.
One example centres on exception management for known vulnerabilities. If a developer marks a high-risk vulnerability with a known exploit as ignored, that status change can trigger an analysis of exploitability.
If the analysis finds no or limited exploitability, the agent recommends accepting the exception. If it confirms exploitability with high confidence, the workflow can reopen the vulnerability, depending on how the security team has configured the process.
The announcement reflects a broader shift in cybersecurity tooling as suppliers look to move beyond AI assistants towards systems that can automatically take defined actions. In software development environments, that trend has focused on areas where automated systems can handle repetitive triage, prioritisation and remediation tasks more quickly, while humans set policy and intervene in edge cases.
Cycode says its workflows are designed to operate across the application development lifecycle, or ADLC, rather than at a single security testing point. That means the system is intended to respond to risks as they arise in the software delivery process instead of waiting for periodic review or manual escalation.
The company also linked the launch to the growing gap between the speed of development and the pace of security review. Developers are shipping code more quickly, often with AI assistance, while security teams face pressure to address a larger number of findings without a corresponding increase in headcount.
"Risk now moves at machine speed while security stays bottlenecked at human speed, and no team can hire its way out of that gap. Waiting for a person to notice each risk and start each response is no longer a viable way to operate," said Lior Levy, co-founder and chief executive officer of Cycode.
Levy said the system is designed to preserve human oversight while allowing agents to act faster than manual processes.
"Agentic Workflows remove that constraint without removing control. Agents triage and remediate the moment risk appears, and security teams set the scope and the boundaries of autonomy. This is how security finally becomes as agentic as the development it protects: agent-driven and human-controlled," Levy said.
Early access begins with the workflow feature and the template library for common security use cases. The launch adds to a growing market focus on using AI not only to identify software risk, but also to decide when and how remediation should begin.