Claude Code Security is a new capability built into Claude Code on the web that scans codebases for security vulnerabilities and suggests targeted software patches for human review. It allows teams to find and fix security issues that traditional methods often miss, putting AI-powered cybersecurity capabilities in the hands of defenders.
Claude Code Security reads and reasons about code the way a human security researcher would, understanding how components interact and tracing how data moves through applications. It catches complex vulnerabilities that rule-based tools miss, with every finding going through a multi-stage verification process before reaching an analyst. Claude re-examines each result to filter out false positives and assigns severity ratings so teams can focus on the most important fixes first.
The system works by scanning codebases for vulnerabilities rather than using traditional rule-based static analysis. It identifies problems and suggests solutions, but developers always make the final decision about applying fixes. Validated findings appear in the Claude Code Security dashboard where teams can review them and inspect suggested patches.
Claude Code Security helps security teams address the challenge of too many software vulnerabilities and not enough people to address them. It protects code against AI-enabled attacks and reduces the risk of exploitation by finding weaknesses faster than attackers can exploit them.
The product is designed for Enterprise and Team customers, with expedited access available for maintainers of open-source repositories. It builds on Claude Code, allowing teams to review findings and iterate on fixes within the tools they already use.
admin
Claude Code Security is designed for Enterprise and Team customers who need advanced cybersecurity capabilities for their codebases. It specifically targets security teams dealing with expanding vulnerability backlogs and maintainers of open-source repositories who want to protect their code against AI-enabled attacks. The product is intended for defenders who need to find and fix security issues that traditional methods often miss, with expedited access available for open-source maintainers.