Secure AI Agent · AppSec

AI applied to the security of AI-generated code

A specialist configured to audit what the AI wrote before it reaches production: static analysis, secrets in the diff, and dependencies, within your team's rules.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Capabilities

What the AppSec Specialist can do

Main areas of work for the AppSec Specialist AI Agent in your operation.

Static analysis

Analyzes code for insecure patterns before human review.

Secrets in the diff

Identifies keys, tokens, and credentials exposed in the changes.

Dependency audit

Checks added libraries, versions, and known vulnerabilities.

AI code review

Assesses AI-generated snippets with the rigor the team applies to its own code.

Readiness opinion

Summarizes what blocks the release, in language leadership understands.

Fix tracking

Tracks open findings until the team addresses them.

Skills

Capabilities that compose the specialist

Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.

Secret scanning
Identifies exposed credentials in the changes before the merge.
Dependency audit
Checks libraries, versions, and known vulnerabilities.
Code review
Flags insecure patterns with a reference to the snippet.
How it works

From the diff to the opinion, with review at every step

Connect your repositories, define what the agent can do, and let the audit happen within your team's limits.

01

Connect repositories and scanners
The agent works where the code already lives.Connect repositories, scanning tools, and the issue tracker so the Secure AI Agent has access only to what it needs to audit each change.

02

Ask for the work
Talk to the agent in natural language.Request a pull request audit, a secret check, or the readiness opinion through the available channels. The agent understands the context, applies the configured skills, and follows the rules your team defines.

03

The agent flags. The team decides.
From audit to decision, with control.The agent scans, assesses, and prepares the opinion within the defined permissions. Fixing the code, approving the merge, and deciding the deploy stay with the responsible team.

Integrations

Connected to the tools where code is written and reviewed

The AppSec Specialist AI Agent can query your repositories and run tasks in the systems your team already uses.

  • GitHub
  • GitLab
  • Snyk
  • Semgrep
  • SonarQube

Flow

What goes in, what the agent does, and what comes out

From the raw diff to the opinion, following your team's rules and permissions.

Inputs

  • PR changesDIFF
  • Dependency listList
  • Security policyDOC

Processing

Secure AI Agent

Processing the task

  • Read
  • Scan
  • Assessrunning
  • Report
Skill appliedPolicy verified

Output

Completed

Opinion prepared

  • Insecure patterns flagged
  • Secrets checked
  • Dependencies audited

Control

You define how far the Agent can act

Different actions can operate with different autonomy levels, always within your team's rules.

  1. 1

    Query

    Reads the code and answers with a reference to the snippet.

  2. 2

    Prepare

    Gathers the findings and drafts the opinion.

  3. 3

    Request review

    Waits for validation from the module owner.

  4. 4

    Execute

    Performs the action within the defined limits.

Levels are configured per type of action, according to each company's policy. Fixing code, approving merges, and running deploys always stay under human approval.

Get started

Put a Secure AI Agent to work.

Start on the platform or choose the plan that fits the pace of your operation.

Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.

Frequently asked questions

Common questions about the AppSec Specialist

What teams usually ask before putting an agent to audit code.

  • Does the agent fix the code or merge it?

    Not by default. It flags the problem, points to the snippet, and explains the risk. Fixing, approving the merge, and running the deploy stay under approval from the module owner.
  • Does the opinion guarantee the code is secure?

    No. The opinion gathers what was checked and what remains open, with evidence for each finding. No audit removes risk entirely, and the decision to ship stays with the team.
  • Does it work with code that was not AI-generated?

    Yes. The scans and dependency audit apply to any change. The AI-generated framing exists because that volume has grown and often reaches review without the same scrutiny.
  • How does it handle the secrets it finds?

    The agent flags the exposure and points to where it is, without reproducing the secret value in the report. Rotating the credential and cleaning history stay with the team.
  • Is our code used to train models?

    No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.
  • Can we audit what the agent did?

    Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.
  • How long does it take to go live?

    It depends on the repositories and the tools already in use. The starting point is connecting one repository and the scan your team already runs, then expanding the scope as results come in.

Secure AI Agent

Bring a Secure AI Agent to your code security

Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.