AI doesn't replace established security testing tools, but it can augment them — if you're thoughtful about how you do so. We've been in the lab for months working on generating real data on various approaches that improve overall accuracy (not just reducing FPs, but reducing FNs / increasing coverage too).
There's exciting news coming soon, but meanwhile we thought it might be nice to share how we built our research system to make sure we're making data-driven decisions about results quality. There are already too many vendors building hype and then trying to cherry-pick data to justify it, we don't want to be that.
So we figured out a way to assess scan accuracy that's highly repeatable, reflects real-world applications, and introduces as little error as possible while still being affordable to run. And with that process in place, we're seeing dramatic AI SAST accuracy improvements in the lab, some of which will be coming to our product soon!
Learn about our approach and what we're seeing in the data:
checkmarx.com/zero-post/proo…