Tired of ads? Enjoy an ad-free experience by signing up.
Adinda Pryanka · · 3 min read

Automating software security fixes at a fraction of the cost

This article is a part of Startup Spotlight, a series that features young, up-and-coming startups.

Image credit: Timmy Loen

The founders of AppSecAI used AI to write a country-western song, then tested it on something riskier, finding and exploiting software vulnerabilities. The results were surprising enough to convince them that the same capability needed to be turned toward defense instead of attack.

Realizing the threat automated AI attacks now pose to enterprise software, they built a platform that uses AI to automatically fix security flaws instead of just finding them.

😟 Problem

Enterprises currently spend an average of US$10,000 and 272 days to manually remediate a single software vulnerability. Companies carry tens of thousands of these expensive flaws across legacy systems.

The release of advanced AI models has turned this backlog into an enterprise emergency. These tools allow threat actors to exploit vulnerabilities at scale. Security teams lack the resources to counter these automated attacks manually.

💡 Solution

The platform integrates into existing deployment pipelines on GitHub to deliver code fixes to engineering teams. The technology offers several distinct capabilities, including:

  • Automatically generates necessary code patches when a vulnerability is detected.
  • Creates a workflow where developers verify functions while security validates fixes.
  • Reduces an 11-step manual process into an automated workflow completed in minutes.

Image credit: AppSecAI

📊 Market size

The global application security market is projected to reach US$14.1 billion in 2025. Industry forecasts expect this figure to double by 2030. The company targets a US$250 million segment based on a conservative five percent penetration rate.

🤝 Team

  • Bruce Fram. CEO. He has served as a six-time venture-backed chief executive and founding CEO of US$1.5 billion unicorn Contrast Security.
  • Kevin Fealey. CTO. Former chief information security officer with leadership experience at Ernst and Young and Bullish.
  • Michael Cartsonis. CPO. He has cybersecurity leadership experience, holds multiple patents, and has served as chief product officer at Contrast Security.

🚀 Traction

  • Reduces remediation time from 272 days to 30 minutes, cutting costs from US$11,000 to US$250.
  • Achieved highly favorable unit economics with US$0.10 cost of goods sold per fixed vulnerability.
  • Onboarding more than 100 target customers through OWASP-OASIS.org open-source proof-of-concept initiatives.
  • Secured commercial deals while maintaining zero customer acquisition costs via industry partnerships.

🏆 Competition

Legacy security tools like BlackDuck focus exclusively on finding vulnerabilities. Developer tools such as Snyk still require manual intervention from engineers.

💰 Financials

🚩 Risks

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

TIA Writer

Adinda Pryanka

Jakarta-based content writer