The AppSec Cheese Has Moved: AI-Driven Auto-Remediation
Techstrong Group’s Alan Shimel sits down with StackHawk co-founders Joni Klippert and Scott Gerlach live from Broadcast Alley at RSAC to discuss how the explosive rise of AI-generated code has completely moved the cheese in the application security landscape. With developers now churning out ten times the amount of code, the historical AppSec bottleneck has shifted from merely finding vulnerabilities to automatically fixing them right inside the IDE. Klippert and Gerlach explain how StackHawk’s agentic testing capabilities empower engineering teams to verify and auto-remediate these flaws at the speed of AI creation, ensuring security doesn’t stall the modern CI/CD pipeline.
Transcript
Hey everyone, welcome back here to Techstrong TV. We're continuing our Wednesday afternoon coverage from RSAC here on Broadcast Alley, and I'm reaching way back to my Boulder people for this one. Let me introduce you to the founding team of StackHawk.
We have Joni Clifford, who I found out is still Joni Clifford. Even though, you know? And- But married.
But married. Well, just don't call her late, but Joni Klippert, who I've known as Joni Klippert for, I don't know, 10 years. No, more.
Probably closer to 15 years- ... I think. Yeah.
Because I- Let me just stop there. Yeah. Because there's no more time after that.
That. That was... Dang.
Let's not even get wreck. And Scott Gerlach. Gerlach.
Gerlach. Also co-founder, who I've also known now probably seven, eight, nine years. Yeah.
At least. When did you found StackHawk? Was it about eight years ago?
2019. Seven. Seven years ago.
Yeah, almost. All right, I wasn't that far off. Close.
I remember the first time I met Scott, we were in the Foundry offices- Yep ... on in Boulder. Yeah.
Right off of Pearl Street. Yep. Yeah.
Anyway, though, enough reminiscing. Well, we're not done reminiscing, actually. Joni, I'm going to ask you to kick off.
I said I knew you... I think the first time I knew you was VictorOps. That's right.
That's right. And that might, may or may not be a name you remember. A lot of my DevOps people out here, you remember VictorOps?
They were actually acquired by PagerDuty. No. Splunk.
Splunk. Competitor to PagerDuty, acquired by Splunk. Yep.
I don't know why I thought PagerDuty. You know why someone from VictorOps went to PagerDuty? Yeah.
Was it Jason Hand? We can play this later. So, tell us your story.
Yeah. So Joni Klippert, CEO, co-founder of StackHawk. My background is in DevOps, so what you were just saying.
Right. Largely building software for software engineers. We just went over VictorOps.
It was a competitor to PagerDuty, and that company was so important because it was really in this hyper active, we're finally releasing, DevOps is a real thing. And we had to make sure that if there was downtime or latency or anything, we were shipping those alerts directly to the software engineers who wrote the code. And I think that kind of arc of digital transformation is really what led me here.
And so, with StackHawk, it felt like application security testing was just the next mile of digital transformation. Yep. Why are we waiting until production to actually find vulnerabilities?
How come we're not collaborating with our software engineers or automating the findings so they can actually fix these and treat them like bugs? Mm-hmm. Not like even security vulnerabilities because they found them before they deployed to production.
So, that is what I wanted to work on. And in the process of really getting to know, I didn't know the cybersecurity market. Right.
And it felt like a very obvious process to tackle, but I interviewed a lot of security professionals. I remember. You interviewed me.
Yes. We wanted to know- No, I do. I remember ...
what was this domain? Right. And that's how I met Scott a long time ago.
And Scott, tell us a little bit of your path. Yeah, definitely. So, security operations, security engineer by background.
Worked at GoDaddy, leading security teams there for about 10 years. Mm-hmm. And from there, moved to Colorado and joined another great Colorado company, SendGrid.
Sure. I was a CSO there for three years. Techstars company.
Yeah, right before Twilio acquired them, and I've been working on application security at pretty much all of those roles in some sort of fashion. Like, either deep in it or tangential to it, those kinds of things. And so I had a deep passion for how to fix a pretty broken process, how do we empower engineers.
We did some of that on transition to cloud at SendGrid, like getting engineers involved early. " Yeah. They're the one that start the code, and then way, way later they get to know about the problems that they have to fix.
" But- And so we had a really good conversation about how can we help empower those teams, let them know about security vulnerabilities, and build safer software. Mm-hmm. I think back to those early heady days of DevOps- Right ...
when VictorOps was founded. So Raj, my friend Raj, was at JumpCloud. You guys are in the building next up on the second floor there- Yeah ...
that brick building. Yeah. And what a revelation it was.
Hey, let's alert the end, the developers. Not just the help desk guy, but we're going to cut that handoff from level one, to level two, to level three, we'll get back to you in 36 or 72 hours, to one boom. That's right.
One time and it's done. Now, today we almost take that for granted, that developers are part of this chain or part of this, my code's not working, I know pretty much right away if customers have it. It was the same thing as you said with AppSec.
It's similar to observability, quite frankly. All the action was on the other side of the event horizon, the event horizon being deployed. Deployment.
Deployment. Right. That's where the action was.
And that was part of this whole shift left. We're going to- Mm-hmm ... shift to this side of the event horizon.
Now-Shift left has had an interesting journey in the DevOps space, right? " And we came to find out the developer wants to write quality software. He doesn't necessarily want to be a security pro either, though.
And we need the security people in all these things. So it's been a journey which you guys have actually lived through- That's right ... over these last seven years, right, of, well, did we overshift?
How do we keep the security team involved? How do we empower the developer without expecting him or her to be a security pro? Mm-hmm.
What about the rest of the software team, the CI/CD team, the testers, the QA folks, the SREs, everybody that's involved here along this SDLC? And then just when we thought we figured that out, AI drops from the sky. Boom.
Because life can never be easy. Never. Talk to us about...
" Yeah. It's really interesting because how we were founded was about making this type of testing that used to happen in prod, took a really long time, making it portable, easy to run on a software engineer's machine, easy to run in CI/CD. And that's very unique.
I don't know of another company doing runtime testing that has the same approach, right? They're all using these cloud-hosted scanners that can't be portable. They can't be fast.
So there was this really interesting architectural decision we made early on that set us up perfectly for this period. And we're now closing customers and having our existing customers come to us and say, "I think CI/CD is too right. We're living in Cursor.
" Yeah. " Yeah. And I think the AI DLC or AI-supported DLC is the place where we're really focused, which is on agentic DaaS.
Right. So yeah, with runtime, you want to kind of hit the whole gamut. You want to be able to test with AI and auto-remediate issues in Claude or in Cursor.
But you may also want to test closer to prod as the- ... secondary check from your AppSec team, and you can totally do that. So, I feel like we really have a leg up.
It was just this early decision we made that now suits us perfectly for this moment. The interview before you guys came on, I was talking to the CEO of a company called Anvil Logic. Not related to you at all.
Okay. But more of a big data lake security company. Mm-hmm.
Same thing, founded maybe two years before you, 2017. Okay. He didn't think of AI when he founded the company.
It was this problem, though, of how do you secure, at the time, Hadoop and- Mm. Yeah ... stuff like that back in the day.
But AI has made his life a lot easier because- Yeah ... he didn't realize it back then, but he really needed that technology to really wrap your head around that kind of big data. It's the same thing here.
We wanted to radically change how we look at testing code, testing applications. Well, AI, and this is only in the last two months, right, with Claude Opus and all these things, all of a sudden, we have the ability to test- Yeah ... like, as we're making the code.
That's right. Soon as we commit the code. Any time along this CI/CD, virtually, and without manpower involved, right?
We just report it back to the human in the loop, or as a lot of people are saying now, the human at the helm- Mm ... because we don't have enough humans to be in the loop anymore. Mm.
Mm. Too many loops. There's too many loops.
There's too much code. Yeah. And so you guys, right place, right time.
I always learned that from Brad Feld. Sometimes it's better to be lucky than smart. It's good to be both, right?
But that's, I think, what we're dealing with here, right? And at the same time, though, Scott, as we just said, we have so much more code. So much.
Yeah. Right? And so I wrote this piece about a couple of weeks ago.
In AppSec anyway, we've moved from the question of how do I find bugs, or how many bugs do I find- Yeah ... to what's governance look like here, right? So it's no longer enough to do the scan.
Yeah. " And ultimately, you'd get half of the people say finding, half of the people say fixing. We had great tools to find problems.
Prioritizing those fixes has always been hard. And we're just not fixing problems that are discovered in code. But the power that comes with the agent being able to understand what the problem is and be able to actually fix without wasting mental power from a dev, or interrupting a cycle for delivering product, delivering value, is just-Radically changed how application security has worked.
Look, we moved the cheese in AppSec. That's what happened here. Yeah.
We went from a focus of finding to a focus on fixing, because as much new code as we have, we could find vulnerabilities till the cows come home. That's right. But we've got to decide what to do with them.
What to fix them, not fix them. Are they real? Are they not?
Are they reachable? All the things that you guys know, right? Exactly.
I saw a study on this, what was it? Claude Code found, I think it was 122 potential vulnerabilities in Firefox in an hour or two hours, whatever it was. 11 of them were actually real, call them real vulnerabilities.
Two of them were exploitable. Mm-hmm. Right?
That's a huge problem in that- And that's pretty much the ratio. Yeah. " Because the punchline to the story is always, and then we tested it in runtime to see what was actually exploitable.
Right. Which is what we've been doing for the last seven years inherently. Right.
So being able to get into that loop, be the part and the function that's doing the testing of the behavior, not just, does it look like it's vulnerable? Right. And validate, yeah, this is vulnerable, and we should fix this one thing or these two things, and get rid of the other 120 other things- Other things.
Right ... that are irrelevant. And this sounds like a nothing thing if you're not into security- Right ...
or you're not into development. But if you are, you realize just how radical this is. Mm-hmm.
Right? It's a totally different focus for what an AppSec solution needs to do. Yeah.
And so all these people who developed the DAST and the SAST and the SCAs, they're all good. We've got great scanners. But if that's what your business is today, I don't know if you've got a great business if you're not dealing with the how do I fix these things?
Yes. Or what should I fix? That's right.
And how to fix it, and are you going to let me fix them automatically or not? Mm-hmm. I'm sorry, but you're the first AppSec people I've interviewed here in two days, so- Oh.
All right ... yeah, so I'm dumping it on your laps. Well, you're like on it.
Well, I've been, right? Yeah. I know a little bit about it.
And I've been writing about it because, to me- Yeah ... remember, I came from before the AppSec piece. Mitchell and I standing over there, we were at Still Secure.
We were vulnerability management. We were begging people to scan their systems once a year. Oh, wow.
And that was considered radical. "What do you mean once a year? " Yeah.
But that's what it was back then. It was job security because you gave them a list of vulnerabilities like a telephone book. If you don't know what a telephone book is, Google it.
And they'd start on New Year's, they finish on Christmas. Yeah. Then we start again.
And then you do another scan- And then you get- ... and give them the book bag. Yep.
A new book. New list. So this is what progress is- Yeah ...
in security. How now does- Yeah ... you go to market with this and get that message across?
It's a total sea change. If we think about it, software engineering is the first job to be completely changed by AI. Yeah.
Tip of the spear. Our senior engineers haven't written a line of code since August. They are just using prompts.
We've 8X'd software engineering in the last six months. So everything around that surrounding code delivery has to change, and AppSec is the next most important thing. We just closed a customer who was handwriting 25,000 lines of code a month.
Could you imagine? Yes. And they're in financial services, by the way, so a mid-market financial services company.
They employed Cursor. The next month, it was 250,000 lines of code. Wow.
Next month, even more. So literally 10X. And they called us, and they're like: We're sitting on a million lines of code that we can't deploy- Who's been tested ...
because we haven't been able to test it. And they're in a regulated industry, so they needed to. So we've been co-creating with them this new AI DLC, and to your point about static code analysis tools, we have to totally rethink it.
Because at 10X, where we're just getting started- Geez ... software engineering, it's called the vuln apocalypse, right? Yeah, it is.
You're like, there's just no way we can fix these things. So our perspective is you have to focus on what's reachable and exploitable. There's no time to focus on anything else.
You can't take a food chain. I don't know if you ever read... So Brad Feld used to give this book out to all of his founding teams, "The Goal" by Goldratt.
I forgot his first name, but it was like standard MBA book in the '80s and '90s. But it introduced something, you're probably familiar with this, the theory of constraints- Mm ... where as soon as you undo one bottleneck, there's another bottleneck- ...
behind it. Another bottleneck. Actually, Gene Kim's Phoenix Project- Mm-hmm ...
is the IT version- Right ... " "The Goal" is about manufacturing. But similar, if you ever read "The Goal," you'll see where Gene got Phoenix Project from.
We're not familiar with the theory. We're living it. Well, we all live it.
We all live it. So we removed the bottleneck of humans writing code, and I can only do 25,000 lines of code. And man, I could do 250,000.
I just 10X'd my lines of code. Yeah, but now you just discovered the next bottleneck. That's right.
I can't even test this. Mm-hmm. But what's going to happen is, okay, now I tested it, I found out originally that, I don't know, 300 vulnerabilities are really only seven vulnerabilities.
Boom, I removed another bottleneck. I'm doing that automatically. Well, now here's the next bottleneck.
What's it going to take? Or maybe I'll be able to do it agentically. So we're going to do that, but there'll be another bottleneck.
Mm-hmm. Yeah. That's the theory of constraints.
But from your point of view, this is really a game-changing- Mm-hmm ... kind of new era, right? And you have marketing people, I'm sure, right?
But I think that's what the marketing message has to be here. Mm-hmm. " The thing that I've found is a lot of engineering teams are in this same mode as the AppSec team- Yep ...
where they're tinkering with AI, and messing around with OpenClaw, and trying to figure out what works in their environment. And then once they kind of figure that out, they're starting to standardize, "Here's the tools that we use. " Mm-hmm.
Now's a great time, as an AppSec person, go sit with the engineering team and watch them go through this iteration. Watch how they're hooking different parts of their process so that they can actually work that into their process. Into the SDLC.
Yeah, exactly. It is. And so- Into the chain ...
knowing what's out there, what's capable, and then being able to understand the process at your business of what your engineering team is doing, and how do I fit a new AppSec process into my new engineering process? PS, there's budget attached with that because everyone's working together to get more value to the customer. Yeah, but you know how it is with budget.
Again, don't take my cheese, right? It's my budget. You go get your own budget.
That's right. And there'll be some turf wars around that, too. Yeah, I think, from a CEO perspective, from the C-suite perspective, we're spending a lot of money on tokens, right?
And the whole point is, how do we improve efficiency- Say that again for me. We're spending a lot of money on tokens. Spending money on tokens.
You ain't kidding. Yeah. I think you're spending a lot of money on tokens.
Yeah, yes. Yeah. " And they also want to do it securely.
Yes. So being able to say, "Hey, I want to empower this process- Mm-hmm ... and enable this process, and I'm going to need some extra budget," it's not an easy conversation, but it's a way more acceptable conversation than- Absolutely ...
I'm trying to slow everybody down. That's right. Because when did that ever work, right?
Never. That never worked. And that's been a security problem, too, for years, right?
No. You're saying that as you see the train pulling- That's right. out of the station.
No. So let me ask you the ultimate question then, Joni. If I'm a reporter, I'm not a reporter, I'm just Shimmy, but- ...
is StackHawk an AI-empowered AppSec solution? Of course. All right.
In two ways, right? We are empowered by the wave. Runtime has never been more important, and it's pretty exciting to see it happen.
We're six, seven months, or seven years, we'll pretend it's months- Yeah ... years in. Well, the time, it seems like months.
You've been having so much fun. Yeah. Of course.
But also, we were talking about by using AI, what you're then able to do with your product. We've been able to release capabilities that would've been whole companies before. We are using AI to really help bridge the gap.
The knowledge gap between what an AppSec person knows about software delivery that's happening in their own organization, and how fast it's happening versus what they know today, is enormous. So, beyond the testing piece, over time, we've added this lens of observability component into, based on what's happening in your source code repositories, you have this many APIs, web applications, LLMs, LLMs talking to APIs, that need to be tested with something like StackHawk, able to show them what contains sensitive data. The amount that we can get out of the code base to help inform the AppSec team as to where to focus is incredible, and we've been- ...
totally empowered by AI to do that. So, really exciting to use it so natively, but then also just be able to draft on- Absolutely ... the change that's happening.
What's going on. Yeah. So I've got a CTO question for you then, Scott.
Hit me. How long until you're doing remediations? Not long.
It already happens today in this agentic loop, right? There you go. So I don't have to make tickets, which is awesome.
Those days are done. Yeah. " Go fix it.
Fix it right there, before we even get anywhere near CI/CD. Yep. It's happening.
And it's crazy exciting. Mm-hmm. Mitchell and I had this discussion this morning on it.
The days of just reporting- Mm ... without doing are over. That's right.
You got to do. You got to do. It's an age of doing.
Yeah. And look, I don't know how all this ends. Yeah.
But it's really an exciting time- It really is ... to be doing it. You know what we haven't mentioned, guys?
People want to get more information about StackHawk. Mm. How do we do that?
com. You can learn a little bit more there. We have a ton of blogs, content, ability to learn more about this AI transition and wave, and we're also pretty active on LinkedIn, so feel free to follow us, engage with us there.
I follow you all. Absolutely. And if you're at RSA, you can play Where's Waldo with the giant guy in a purple jacket and/or his companion.
Okay. So you're there on- Yeah. Stop us.
We're going to be there. I've got to tell you, I haven't even had a chance to walk down to the floor. It's pretty calm.
I heard it was a little chill this year. Not super loud. Not very many lights.
It's pretty nice. So Monday, we put on our dev, well, we used to call it DevSecOps. I don't even call it DevSecOps anymore- Yeah ...
because I don't know what to call it. I do know what to call it. We called it Defending AI Native Dev.
Right. And because it is all about AI native dev. And so we were there Monday, and it was interesting.
But I also snuck down to the Innovation Sandbox. Yeah. And everything there was AI.
Yeah. " So it's an interesting time. They're watching this live, so they probably are not there.
Where could we see you next after RSAC? Oh. Black Hat.
Black Hat. For sure. Lots of regional events.
Lots of regional events. With some of our partners- Yeah ... Guide Point and WWT and some of our great partners.
We're always doing regional events, some informational, come learn something, and maybe have a good steak dinner. But our next big one is probably Black Hat. Is Black Hat, early August.
Yeah. I'll be there. Awesome.
So there, I do go on the floor to do video. Here, I'm on Broadcast Alley, so I get at least to... I'm stationary.
People come to me. In Black Hawk- That's funny ... I got to go to them.
I'm the Black Hawk. I did StackHawk and Black Hat together. Black Hawk.
That's a new conference you probably haven't heard of yet. Right. But if you do, that's a good name for your conference, Black Hawk.
Joni, it's great seeing you. Good to see you. Scott, always a pleasure to see you.
Thank you for having us. My pleasure. We're live.
We're at RSAC. We're going to be back in a little bit. com.
Yes. Check it out. We'll be right back.