StackHawk's Groundbreaking Release: Wingman
In the fast-paced world of software development, finding and fixing security vulnerabilities often trails behind the rapid pace at which applications are created. StackHawk, a prominent player in application security, has launched an innovative product named
Wingman that aims to bridge this gap significantly. This new tool provides software engineers with the capability to rectify security flaws immediately during the AI coding session where the code is generated.
Enhancing the AI Coding Process
Wingman integrates seamlessly with various popular AI coding agents, including Claude Code, Cursor, and GitHub Copilot. By operating within these existing workflows, it allows for immediate remediation as the code is written, rather than forcing engineers to wait for potential vulnerabilities to be discovered and ticketed weeks later by security teams.
Joni Klippert, the CEO of StackHawk, emphasized the critical time frame organizations confront regarding security vulnerabilities. "The window between vulnerability disclosure and exploitation can now be as short as negative 15 hours," Klippert stated, highlighting how attackers can manifest breaches before security vulnerabilities are even publicly reported. With application development moving swift as lightning due to AI coding technologies, security measures have lagged behind—a discrepancy that poses significant risks for many organizations.
Proven Success with Wingman
Since its initial rollout, Wingman has proved its efficacy by fixing over 7,500 vulnerabilities for its early-access customers, utilizing various AI coding agents. Remarkably, 98% of these fixes have remained intact, thwarting potential regressions. The vulnerabilities addressed include serious issues such as remote code execution, SQL injection, and cross-site scripting, all of which are common culprits in real-world security breaches. By deploying Wingman, AI agents can now identify, rectify, and verify flaws before they ever reach a security team’s backlog, thereby liberating security professionals to focus on more critical tasks.
CertiPath's CISO, George Baker, noted the significant impact of Wingman in their development process. He explained that the integration of AI throughout the software lifecycle was a deliberate strategy they employed to strengthen application security. With Wingman, engineers can now find and fix vulnerabilities in the same working session where the code is created, supplemented by human review and a verified record of what has been securely shipped.
The Functionality of Wingman
Wingman operates within the unique context of each software development environment. Right from the moment it's initiated, it understands the application's architecture, dependencies, and the coding standards dictated by the rest of the team's workflow. Here’s how it functions:
- - No Context Switching: Wingman works directly within established agents like Claude Code and GitHub Copilot, eliminating the need for developers to change their workflows.
- - Auto-Triggering: Once a feature is marked as complete, Wingman automatically configures the running application, tests it, and identifies vulnerabilities without manual input required from developers.
- - Rapid Fixes and Verifications: It returns findings to the same agent that created the code. The tool resolves the issue and verifies that the fix holds, automatically closing the loop.
- - Early Reporting: Solutions are provided before any pull requests are opened. This ensures that the continuous integration (CI) pipeline is informed on whether the commit is secure.
- - Documentation of Evidence: Each evaluation is linked to a specific code commit, providing a complete attestation record that assures security teams of what has been securely delivered.
With features like unlimited applications and 50 scans per user per month, Wingman redefines the standard for security in fast-paced coding environments.
Klipper reinforces that traditional security tools often stop at merely identifying flaws, whereas Wingman goes a step further by automating the fixing and verification processes, matching the high-speed development today.
Availability and Pricing
Wingman is available for just $10 per user per month. Potential users can explore its capabilities through a 14-day free trial on
StackHawk's website. Organizations with extensive API requirements can also consider StackHawk Scale, a developed enterprise offering to complement Wingman’s functionalities.
Overview of StackHawk
Founded in Denver, Colorado, StackHawk is committed to aiding software engineering and security teams in identifying and fixing exploitable vulnerabilities within the applications they develop before these reach the production phase. The company has established its footprint globally by providing dynamic application security testing (DAST) and API security tools that are trusted by over 200 enterprise organizations. With the introduction of Wingman, StackHawk extends its capabilities into the AI coding agent workflow, enabling teams to secure their code at unprecedented speeds.
For more information, visit
StackHawk.