IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Orca launches AI security tools for all software builders

Orca launches AI security tools for all software builders

Fri, 31st Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Orca Security has launched two tools to secure software built both inside and outside traditional development pipelines, targeting the growing use of artificial intelligence in software creation.

The products are Orca AI AppGen Security and Orca AI Code Security Auditor. The first is designed to discover and secure AI applications created on platforms such as Claude, Supabase and Lovable. The second applies static code analysis to software produced in more conventional engineering workflows.

The announcement reflects a broader shift in how companies build software. Instead of relying solely on professional developers working in established pipelines, businesses are increasingly seeing employees in non-engineering roles create applications with AI tools that connect to company data, application programming interfaces and cloud systems.

That shift has created a new challenge for security teams. Applications built outside formal development processes can sit beyond established review systems, while code written inside those pipelines still carries vulnerabilities that may be difficult to identify and prioritise.

Orca's State of AI Security Report 2026, based on anonymised telemetry from more than 1,200 production cloud environments analysed by the Orca Research Pod, found that 52% of organisations now build custom applications with AI. Orca also cited IBM estimates that breaches involving shadow AI cost organisations an average of USD $670,000 more than other incidents.

Two tracks

AI AppGen Security is aimed at what Orca describes as a new generation of AI builders. It is intended to give security teams visibility into applications created outside the development pipeline, identify who built them, map risks tied to APIs, integrations and data access, and rank exposures by business impact.

By contrast, Code Security Auditor focuses on software developed in standard pipelines. It uses AI-driven static analysis to detect vulnerabilities that traditional testing tools can miss, scan full repositories and help teams focus on risks that are exploitable in practice.

Orca is positioning the pair as a single approach to application security as AI changes who can create software inside an organisation. The argument is that security teams now need oversight not only of developers, but also of business users using AI systems to generate applications.

Gil Geron, Chief Executive Officer and Co-Founder of Orca Security, linked the launch to that wider change in software development.

"Everyone is a builder now. Developers are creating software in the pipeline, employees are building AI applications outside it, and the next generation of frontier AI models will increasingly generate and modify software on their own. Organisations need security that can keep pace with this shift without slowing innovation. Our AI Code Security Auditor prepares customers for the next wave of AI-assisted software development, while giving security teams the deep, accurate context they need to understand what's truly exploitable. Combined with AI AppGen Security, Orca helps organizations secure every builder and every application, wherever and however it's created," Geron said.

Wider governance

The launch also points to a broader issue in corporate technology governance. As AI tools make software creation more accessible, companies are managing a population of internal builders that extends beyond software engineers. That raises questions about visibility, policy enforcement and responsibility for code and applications that may have direct access to sensitive systems.

Recent additions to the Orca platform include support for Anthropic Claude through its Compliance API, which the company described as part of a unified approach to AI governance. Its strategy is to bring cloud, AI and application security into one platform so security teams can identify risk across different layers of an organisation's technology estate.

For many companies, the practical concern is that software built quickly by business teams can enter use before formal checks take place. That can leave security teams trying to catch up after deployment, especially when apps rely on external integrations or connect to internal data sources.

Sangram Dash, Chief Information Security Officer at Sisense, described the problem in operational terms.

"My developers and my business teams are both shipping software faster than my team can review it, and the apps built outside our pipeline were a complete blind spot. Seeing exploitable code and the AI apps our employees stand up in one platform lets us say yes to builders instead of slowing them down - and still know exactly what we're governing," Dash said.

According to company information, Orca counts SAP, Autodesk, Gannett, Lemonade and Digital Turbine among its customers as it seeks to expand its role in cloud, AI and application security.