The service is accessible by way of the Gemini Enterprise Agent Platform and also can function as a element of Google AI Menace Protection. It marks the transition of CodeMender from a Google DeepMind analysis mission into an enterprise product that may be built-in with growth instruments and software program supply pipelines.
CodeMender differs from typical code scanners by trying to determine whether or not a detected weak spot can really be exploited. The agent creates proof-of-concept exploit code and runs it inside an remoted sandbox managed by the client. This permits safety groups to tell apart sensible threats from theoretical findings and direct sources in direction of flaws presenting the best danger.
After confirming exploitability, the agent produces a patch, assessments the change and provides it to builders as a code distinction for assessment. CodeMender doesn’t routinely commit modifications to repositories or push them into manufacturing. A developer should look at and approve every proposed repair, sustaining a human checkpoint inside the remediation course of.
Google mentioned the agent can scan for reminiscence corruption, injection vulnerabilities, internet safety defects, cryptographic weaknesses and unsafe information dealing with. It helps C and C++, Go, Java, Python, Ruby, Rust and TypeScript, masking languages broadly utilized in enterprise purposes, cloud providers and open-source infrastructure.
The underlying system combines synthetic intelligence fashions with safety instruments reminiscent of static evaluation, dynamic evaluation, fuzzing, differential testing and mathematical solvers. Slightly than relying solely on patterns related to recognized bugs, the agent analyses management movement, information movement, utility behaviour and the broader context of a software program repository.
Code compilation, testing and exploit execution happen inside customer-controlled native sandboxes or remoted digital machines. The agent’s reasoning and orchestration features are hosted by way of Google’s platform. Organisations can route site visitors by way of their digital personal cloud, whereas Google says source-code information is remoted, encrypted and topic to a zero-retention coverage.
Builders can function CodeMender by way of a light-weight command-line interface or integrations with instruments together with Visible Studio Code. It might probably additionally run as a headless agent inside steady integration and steady supply pipelines, permitting safety checks and patch technology to turn into a part of routine software program growth.
The launch comes as safety groups battle with massive volumes of scanner alerts, lots of which require guide investigation earlier than their significance may be established. False positives can delay remediation by forcing engineers to look at warnings that don’t characterize a workable assault path. Exploit-based verification is meant to cut back that burden, though operating routinely generated assault code introduces operational dangers that make robust isolation important.
Safety analysis has proven that coding brokers and their sandboxes can face prompt-injection assaults, supply-chain manipulation and makes an attempt to cross execution boundaries. Malicious directions hid in repositories, documentation or dependencies might affect an agent’s actions. Buyer-managed environments due to this fact give organisations extra management, however in addition they place duty on directors to configure, patch and monitor these environments securely.
CodeMender started as a DeepMind mission introduced in October 2025. Throughout its first six months of growth, it contributed 72 safety fixes to open-source tasks, together with codebases containing as many as 4.5 million strains. Its early work included tracing advanced reminiscence errors and making use of broader safeguards supposed to stop whole classes of buffer-related vulnerabilities.
The agent has been examined by corporations together with Salesforce, Robinhood and Palo Alto Networks. Google can also be positioning it alongside Wiz, the cloud safety firm it agreed to accumulate, and Mandiant, its incident response and menace intelligence operation. Deliberate integrations would use deployment context from the Wiz Safety Graph to determine uncovered purposes and instruct CodeMender to generate focused repairs.
Prospects can choose from a number of fashions relying on the required steadiness of velocity, value and scanning depth. Help for third-party frontier fashions is deliberate later this yr, probably making CodeMender much less depending on a single mannequin household.













