Secure AI Agent · AppSec
AI applied to
the security of AI-generated code
A specialist configured to audit what the AI wrote before it reaches production: static analysis, secrets in the diff, and dependencies, within your team's rules.
Companies that trust UPX
Capabilities
What the AppSec Specialist
can do
Main areas of work for the AppSec Specialist AI Agent in your operation.
Static analysis
Analyzes code for insecure patterns before human review.
Secrets in the diff
Identifies keys, tokens, and credentials exposed in the changes.
Dependency audit
Checks added libraries, versions, and known vulnerabilities.
AI code review
Assesses AI-generated snippets with the rigor the team applies to its own code.
Readiness opinion
Summarizes what blocks the release, in language leadership understands.
Fix tracking
Tracks open findings until the team addresses them.
Skills
Capabilities that compose the specialist
Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.
- Secret scanning
- Identifies exposed credentials in the changes before the merge.
- Dependency audit
- Checks libraries, versions, and known vulnerabilities.
- Code review
- Flags insecure patterns with a reference to the snippet.
How it worksFrom the diff to the opinion,
From the diff to the opinion,
with review at every step
Connect your repositories, define what the agent can do, and let the audit happen within your team's limits.
- Connect repositories and scanners
- The agent works where the code already lives.Connect repositories, scanning tools, and the issue tracker so the Secure AI Agent has access only to what it needs to audit each change.
- Ask for the work
- Talk to the agent in natural language.Request a pull request audit, a secret check, or the readiness opinion through the available channels. The agent understands the context, applies the configured skills, and follows the rules your team defines.
- The agent flags. The team decides.
- From audit to decision, with control.The agent scans, assesses, and prepares the opinion within the defined permissions. Fixing the code, approving the merge, and deciding the deploy stay with the responsible team.
01
02
03
Integrations
Connected to the tools where code is written and reviewed
The AppSec Specialist AI Agent can query your repositories and run tasks in the systems your team already uses.

Snyk Semgrep SonarQube
Flow
What goes in,
what the agent does, and what comes out
From the raw diff to the opinion, following your team's rules and permissions.
Inputs
- PR changesDIFF
- Dependency listList
- Security policyDOC
Processing
Secure AI Agent
Processing the task
- Read
- Scan
- Assessrunning
- Report
Skill appliedPolicy verified
Output
Completed
Opinion prepared
- Insecure patterns flagged
- Secrets checked
- Dependencies audited
Control
You define how far the Agent can act
Different actions can operate with different autonomy levels, always within your team's rules.
- 1
Query
Reads the code and answers with a reference to the snippet.
- 2
Prepare
Gathers the findings and drafts the opinion.
- 3
Request review
Waits for validation from the module owner.
- 4
Execute
Performs the action within the defined limits.
Levels are configured per type of action, according to each company's policy. Fixing code, approving merges, and running deploys always stay under human approval.
Get started
Put a Secure AI Agent to work.
Start on the platform or choose the plan that fits the pace of your operation.
Security and compliance
Security that can be verified.
Certifications and attestations
UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.
Privacy and regulation
- LGPD
- Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
- Zero Data Retention
- A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
- Retention and deletion
- The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.
Frequently asked questions
Common questions about the AppSec Specialist
What teams usually ask before putting an agent to audit code.
Does the agent fix the code or merge it?
Not by default. It flags the problem, points to the snippet, and explains the risk. Fixing, approving the merge, and running the deploy stay under approval from the module owner.Does the opinion guarantee the code is secure?
No. The opinion gathers what was checked and what remains open, with evidence for each finding. No audit removes risk entirely, and the decision to ship stays with the team.Does it work with code that was not AI-generated?
Yes. The scans and dependency audit apply to any change. The AI-generated framing exists because that volume has grown and often reaches review without the same scrutiny.How does it handle the secrets it finds?
The agent flags the exposure and points to where it is, without reproducing the secret value in the report. Rotating the credential and cleaning history stay with the team.Is our code used to train models?
No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.Can we audit what the agent did?
Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.How long does it take to go live?
It depends on the repositories and the tools already in use. The starting point is connecting one repository and the scan your team already runs, then expanding the scope as results come in.
Secure AI Agent
Bring a Secure AI Agent to your code security
Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.















