All news
aicybersecurityproduct

OpenAI Launches Codex Security, Formerly Aardvark

11 Jul 2026

OpenAI's AppSec agent goes public—minus the SAST

OpenAI has moved its application security agent out of private beta and into a research preview. Formerly known as Aardvark, the tool is now called Codex Security, and it began rolling out on March 6, 2026, to ChatGPT Pro, Enterprise, Business, and Edu customers via Codex web.

The product started life last year as a private beta with a small group of customers under the Aardvark name. The public research preview marks its first broader release, and OpenAI is offering free usage for one month starting from the announcement date.

What the beta cohort found

OpenAI shared numbers from the beta period to make the case that Codex Security is ready for wider testing:

  • Over 1.2 million commits scanned across external repositories over 30 days
  • 792 critical findings and 10,561 high-severity findings identified
  • Critical issues appeared in under 0.1% of scanned commits
  • Noise reduced by 84% in one case since initial rollout
  • Over-reported severity findings cut by more than 90%
  • False positive rates fell by more than 50% across all repositories
  • 14 CVEs were assigned from vulnerabilities the tool discovered, with two reported through dual channels

OpenAI says it reported critical vulnerabilities to open-source projects including OpenSSH, GnuTLS, GOGS, Thorium, libssh, PHP, and Chromium. A NETGEAR product security executive said the tool integrated effortlessly and results exceeded expectations.

No SAST, on purpose

In a follow-up post on March 16, 2026, OpenAI explained a deliberate design choice: Codex Security does not start from a Static Application Security Testing (SAST) report. Instead, it uses repo-specific context and threat models to validate issues in an isolated environment before surfacing them to users.

OpenAI's argument is that traditional SAST tools struggle to determine whether security defenses actually work—particularly with transformation chains and constraint propagation. The company cited CVE-2024-29041, an Express open-redirect vulnerability, as an example of the kind of issue that illustrates SAST's blind spots.

This is a real tradeoff, not just a marketing point: skipping a SAST-based starting point could mean certain vulnerability classes traditionally caught by SAST tools are missed. OpenAI hasn't published a direct comparison against SAST tools or competitor products, so it's not yet possible to independently verify the tradeoff.

A push into open source

Alongside the research preview, OpenAI launched a Codex for OSS program, offering free ChatGPT Pro and Plus accounts, code review, and Codex Security access to open-source maintainers. Combined with the vulnerability reports already sent to major projects, this suggests OpenAI is positioning Codex Security as much as an ecosystem-security play as a commercial product.

Why founders should care

  • Teams evaluating AppSec tooling may find the reported drop in false positives and noise meaningfully lowers triage overhead, though this is based on one beta cohort and may not generalize across all repo types or languages.
  • The free one-month trial gives founders a low-risk window to test the tool before committing budget—worth prioritizing if security review capacity is a bottleneck.
  • Because Codex Security is still in research preview, it's reasonably likely the product carries stability or coverage limitations that haven't surfaced yet; founders should be cautious about wiring it into critical production workflows just yet.
  • Security-tooling founders should watch how the no-SAST approach differentiates in practice—if it holds up, it could reshape expectations for what AppSec agents are expected to catch versus miss.
  • Pricing and access after the free month, eligibility criteria for the research preview, and the path to general availability are all still undefined, which matters for any team budgeting beyond a short-term trial.

What's still unclear

OpenAI hasn't specified what pricing or access model kicks in once the free month ends, nor how research-preview access might expand beyond current ChatGPT tiers. The details behind the 14 CVEs—and why two received dual reporting—haven't been fully explained. It's also unclear how representative the beta's 1.2 million commits are of typical enterprise codebases, or when Codex Security might graduate from research preview to general availability.

Sources