AI is writing more code. Who’s checking it? 👀 Our very own James Wickett contributed to IT Revolution’s “Agentic AI and Code Reviews” alongside Zach Davis, Michelle Gill, Elisabeth Hendrickson, Angie Jones, Sha Ma, and Randy Shoup. DryRun Security is featured alongside Block and Cloudflare, with a look at how we review AI-generated code in our own engineering workflow. Free download: https://lnkd.in/dd-p5x5Q
DryRun Security
Computer and Network Security
Austin, TX 2,869 followers
Meet Your Team of Application Security Agents
About us
DryRun Security is the industry’s first AI-native, agentic code security intelligence engine. Powered by our Contextual Security Analysis engine, we secure software built for the future by helping security and developer teams quiet noise, gain insights, and surface risks that pattern-based scanning tools inherently miss.
- Website
-
https://dryrun.security
External link for DryRun Security
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Austin, TX
- Type
- Privately Held
- Founded
- 2023
- Specialties
- Security Testing, Security for Developers, Node.js, Express, Sails, Node Express, Node Security, DevOps, DevSecOps, AppSec, Application Security, API Security, SRE Security, Python Security, DevOps Security, Ruby on Rails, and Agentic Security
Locations
-
Primary
Get directions
Austin, TX, US
Employees at DryRun Security
Updates
-
DryRun Security reposted this
Very proud and excited to publish our white paper "Agentic AI and Code Reviews" with IT Revolution: https://lnkd.in/dd-p5x5Q, along with co-authors Zach Davis, Michelle Gill, Elisabeth Hendrickson, Angie Jones, Sha Ma, James Wickett. Free to download. The paper outlines a Pattern language for evaluating AI-generated and AI-augmented code: * Small Incremental Changes * Shift Left * Design for Verification * Deterministic Engineering Practices * Spec-Driven Development * Context Engineering * Continuous Code Quality Loop * Adversarial LLM Review * Multi-Agent Reviews Then we walk through three real-world case studies from Block, Cloudflare, and DryRun Security that illustrate the Patterns. Enjoy!
-
DryRun Security reposted this
AI Code Reviews done right! Check out the cool things that DryRun Security are working on.
When Claude says, “You’re absolutely right. I don’t know how I missed this.” Asking the same AI that wrote your code to review its own work might not provide the confidence you need. Watch our on-demand webinar with ReleaseTEAM, Inc. to hear Alex Ortiz and Zac F. discuss what secure code review should look like in the age of AI. https://lnkd.in/eD3MfAJq
-
DryRun Security reposted this
We’re doing another DryRun Security founder office hours this Friday. Ken Johnson and I will be live to answer questions about AI-generated code, AppSec, code review, and what we’re working on at DryRun. If your team is trying to figure out how AI changes software security, how to reduce noise, or how to get developers to engage with security findings, bring those questions too. September 25 at 11 a.m. ET: https://lnkd.in/grhPp2YE
-
-
“We started building when LLMs were terrible, and that became our advantage.” Turns out, having to work around early LLM limitations taught us a few things. In this Founder Office Hours clip, Ken Johnson and James Wickett discuss why DryRun built deterministic signals into the product instead of relying on an LLM to get everything right. Watch the full conversation on demand to hear what that means for security teams evaluating AI code review tools. https://lnkd.in/gS-v8cET And register for our next Founder Office Hours to join us live: https://lnkd.in/eZjA2TBc
-
DryRun Security reposted this
🧐DO MORE FINDINGS EQUATE TO BETTER SECURITY❓ The myth, man, and legend and DryRun Security's own - Justin Collins asks that very question in the article, linked below: https://lnkd.in/ggykHqyE
-
When Claude says, “You’re absolutely right. I don’t know how I missed this.” Asking the same AI that wrote your code to review its own work might not provide the confidence you need. Watch our on-demand webinar with ReleaseTEAM, Inc. to hear Alex Ortiz and Zac F. discuss what secure code review should look like in the age of AI. https://lnkd.in/eD3MfAJq
-
Finding more vulnerabilities does not always mean doing more security work. Our CTO and co-founder, Ken Johnson, breaks down what we learned from testing DryRun Security and Claude Security across the same applications. Both tools found real issues. The difference was whether they reported each weakness separately or connected the pieces to show what an attacker could actually accomplish. Ken explains why AI-native #AppSec needs to move beyond better scanner output and start taking on more of the judgment that has historically been left to security teams. Read the full breakdown: https://lnkd.in/gfmQX8AH
-
-
Anthropic reimagined the SDLC. AppSec got markdown files. In our latest Founder Office Hours, Ken Johnson and James Wickett discuss why the future of AppSec should be much bigger than maintaining documents and chasing bug tickets. AI should free security teams to spend more time on secure design, strategy, and the higher-level work that rarely gets enough attention. Read Ken’s full take: https://lnkd.in/eH-8RPCv
-
How do Claude Security and DryRun compare when it comes to finding and prioritizing the risks that actually matter? In our latest Founder Office Hours, Ken Johnson and James Wickett break down what happened when we compared DryRun with Claude Security and why isolated severity ratings can leave serious authorization and account takeover risks buried in the noise. Watch the full on-demand recording to learn how DryRun uses application context and exploit chaining to surface the risks that actually matter: https://lnkd.in/gS-v8cET Check out our next Founder Office Hours to join the conversation live: https://lnkd.in/eZjA2TBc