Vercel Labs Launches Deepsec AI Vulnerability Scanner
20 Jul 2026
Vercel Labs has released Deepsec, an agent-powered vulnerability scanner built to run inside a team's own infrastructure and hunt down security issues that have been sitting unnoticed in large codebases.
What Deepsec does
Deepsec is designed for on-demand review of all the code in existing large-scale repositories, aiming to surface hard-to-find issues that have lurked in applications for a long time — the kind of latent vulnerabilities manual code review tends to miss.
For large codebases, Deepsec fans work out across parallel worker machines. If a scan is interrupted or errors out partway through, it picks up where it left off rather than restarting from scratch. Large monorepos can distribute work across Vercel Sandbox microVMs, with configurable sandbox and concurrency parameters.
Under the hood, Deepsec can use Claude and Codex models, and it requires the Vercel AI Gateway to run real scans — a single key covers both model providers.
The cost and risk trade-offs
Deepsec isn't cheap. Scans on large codebases can run from thousands to tens of thousands of dollars. According to the report, customers have found this cost worth it given how quickly they were able to patch vulnerabilities that would otherwise have gone unfixed — though no data is available on how many customers have used the tool or what measurable outcomes look like.
There are also structural risks to weigh:
- Full shell access: Vercel Labs says Deepsec should be treated like a coding agent with full shell access to the environment it runs on — meaning misconfiguration could expose sensitive infrastructure.
- Prompt injection: Because scans touch external dependencies and vendored code, prompt injection is a live concern. The report notes no details are available on how this risk is mitigated in practice.
- Unclear pricing structure: There's no public information yet on how scan costs scale with codebase size, pricing tiers, or a release/availability timeline.
Why founders should care
For founders sitting on large, aging codebases, a tool like Deepsec could plausibly help surface security debt before it turns into an incident — particularly for teams that haven't had the bandwidth for thorough manual audits. But the economics likely make this more relevant to well-funded or security-critical teams than to cash-constrained early-stage startups, given that a single large scan could cost as much as tens of thousands of dollars.
Founders considering Deepsec should probably scrutinize infrastructure isolation and trust boundaries carefully before deployment, given the full shell access requirement. It's also worth assessing vendor lock-in: since Deepsec depends on the Vercel AI Gateway and specific models (Claude, Codex), integrating it into a CI/CD pipeline may create dependencies that are hard to unwind later.
What's still unclear
Several important details remain unspecified in Vercel Labs' announcement: exact pricing tiers, a release or availability timeline, how many customers have actually used Deepsec, and how it stacks up against other vulnerability scanning tools on the market. Founders evaluating Deepsec today will largely be doing so on trust rather than published benchmarks.