Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

HackRead
HackReadMar 3, 2026

Companies Mentioned

Why It Matters

Embedding developer‑origin data into AppSec workflows accelerates remediation and improves accountability, a critical need as AI‑assisted coding proliferates across enterprises.

Key Takeaways

  • Archipelo adds DevSPM context to Checkmarx ASPM
  • Identifies developer identity and AI involvement for each vulnerability
  • Enables faster remediation decisions using origin evidence
  • Supports modern AI‑assisted coding workflows with provenance data
  • Joint webinar on March 11 showcases integration details

Pulse Analysis

The rapid adoption of AI‑assisted coding tools has reshaped software delivery, but it also introduces new layers of risk that traditional application security platforms struggle to surface. While static and dynamic scanning can flag vulnerable code, they rarely reveal the human or machine actions that introduced the flaw. Developers and security teams now demand granular provenance data—who authored a change, which AI model suggested it, and under what pipeline conditions—to make informed risk decisions.

Archipelo’s DevSPM technology captures these creation‑time signals across source‑control and CI/CD environments, mapping each code commit to its originating identity and tooling. Checkmarx’s ASPM layer, meanwhile, aggregates vulnerability findings and prioritizes remediation across the entire application portfolio. By integrating the two, the partnership delivers a unified view where each security alert is enriched with actionable context, allowing teams to pinpoint the exact change, the responsible developer, and any AI assistance involved. This correlation reduces the time spent on forensic analysis and enables remediation strategies that target root causes rather than symptoms.

For enterprises racing to maintain velocity while safeguarding code, the combined solution offers a strategic advantage. It aligns with emerging governance frameworks that emphasize traceability and accountability in AI‑driven development. The upcoming March 11 webinar will provide a deep dive into implementation best practices, showcasing real‑world use cases and ROI metrics. As regulatory scrutiny intensifies around AI‑generated code, partnerships like Archipelo‑Checkmarx set a precedent for embedding provenance into the core of modern AppSec ecosystems.

Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM

Comments

Want to join the conversation?

Loading comments...