
15 Sep 2026
StackHawk launches Wingman to fix security holes while the AI is still coding
StackHawk launched Wingman, a $10-per-user-per-month product that the company says finds, fixes, and rechecks security holes in the same AI coding session that wrote the code — before a pull request opens.
SAFETY desk — same-day company primary that an application-security vendor put a find-fix-verify loop inside the AI coding session, not another scanner that only files a ticket weeks later.
Wingman, as the same wire has it: a product that lets software engineers autonomously fix security vulnerabilities in the same AI coding session in which the code was written. Autonomously here means the tool runs the find-fix-recheck loop without waiting for a later security ticket. The company says Wingman installs into existing agentic workflows, including Claude Code, Cursor, and GitHub Copilot, so the fix happens as code ships, not as a ticket created by security weeks later. Agentic workflows here means the AI coding-agent setups teams already use. File that same-session / install-into-the-agent picture as StackHawk’s. This desk did not sit in a coding session.
Once installed, still company: Wingman auto-triggers when a feature is marked done. It auto-configures and boots the running app, then tests it the way an attacker would — no manual steps. Findings go back to the same agent that wrote the code. That agent fixes the issue. Wingman rescans to confirm the fix held, and the loop closes automatically. The company says this fires before the pull request opens — a pull request is the usual review step before new code is merged — and reports back to the continuous integration, or CI, pipeline on whether the commit is clean. Every test is tied to a specific commit, which the company calls an attestation record of what shipped secure. File that auto-trigger / boot / attacker-test / fix / rescan / before-PR / CI / attestation picture as StackHawk’s. This desk did not trip the loop.
Supported agents on the same wire, still company: Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity. No context switch required, the company says. The product includes unlimited applications and 50 scans per user, per month. File those five agent names and the unlimited-apps / 50-scans-per-user-per-month terms as StackHawk’s. This desk did not count a team’s scans.
Early-access claim, company: since its initial rollout, Wingman has automatically fixed more than 7,500 vulnerabilities for early-access customers, using more than five different AI coding agents. Ninety-eight percent of those fixes remain resolved, with no regressions. The company says the fixes include exploit-confirmed, high-severity flaws such as remote code execution, SQL injection, and cross-site scripting — the categories it says are most commonly implicated in real-world breaches. Remote code execution means an attacker can run their own code on the app. SQL injection means sneaking database commands through an input field. Cross-site scripting, or XSS, means sneaking hostile script into a page other people view. File the 7,500 / more-than-five-agents / 98% / no-regressions / those three flaw types as StackHawk’s. This desk did not count the fixes or retest them.
Named voice on the release: Joni Klippert, chief executive officer of StackHawk. She says the window between vulnerability disclosure and exploitation used to be measured in years and can now be negative 15 hours, because attackers often exploit flaws before they are publicly disclosed. File the name, title, and that negative-15-hours line as hers, via StackHawk. Her other quotes are color only and stay in Sources.
A second named voice on the same wire: George Baker, chief information security officer at CertiPath. CISO means the person in charge of a company’s information security. Baker appears as a quoted early-access customer. File the name and title as his, via StackHawk. This desk is not inventing a broader customer-logo roster. His quotes are color only and stay in Sources. This desk did not interview CertiPath.
Availability and pricing, company: Wingman is priced at $10 per user, per month. A 14-day free trial is available at stackhawk.com/product/wingman. Teams that need larger-scale API discovery and attack-surface visibility can pair Wingman with StackHawk Scale, the company’s enterprise offering. An API is an application programming interface — the machine-to-machine doors an app exposes. File the $10 / 14-day trial / Scale pairing as StackHawk’s. This desk did not buy a seat.
About-box context, still company: StackHawk helps engineering and security teams find and fix exploitable vulnerabilities in the applications and APIs they build, before those flaws reach production. Founded in Denver, Colorado by CEO Joni Klippert and chief security officer Scott Gerlach. The company builds dynamic application security testing, or DAST — testing a running app the way an attacker would — and API security tools it says are used by more than 200 enterprise organizations worldwide. With Wingman, the company says it extends that testing engine into the AI coding-agent loop. File the Denver founding, the Gerlach title, the DAST / API-security line, and the 200-plus enterprises figure as StackHawk’s. This desk did not count those customers.
Plain English for the rest of the card: DAST = dynamic application security testing, testing a running app the way an attacker would. pull request = the usual review step before new code is merged. CI = continuous integration, the automated checks that run when code is pushed. attestation here = a saved record that a specific commit was tested and came back clean. SQL injection = sneaking database commands through an input field. XSS / cross-site scripting = sneaking hostile script into a page other people view. remote code execution = an attacker can run their own code on the app. agentic workflow = the AI coding-agent setup a team already uses.
PRIMARY here: StackHawk’s 15 Sep 2026 PR Newswire company release — Tier A PRIMARY company source, the original record. The Wingman product page is product-home context, not a second originating newsroom. The public launch, the same-session find-fix-verify loop, the Claude Code / Cursor / GitHub Copilot / Codex / Antigravity install list, the auto-trigger / boot / attacker-test / rescan / before-PR / CI / attestation picture, the unlimited-apps / 50-scans-per-user-per-month terms, the more-than-7,500 / more-than-five-agents / 98% / no-regressions early-access lines, the remote-code-execution / SQL-injection / XSS flaw types, the Klippert title and negative-15-hours line, the Baker / CertiPath quote on the wire, the $10-per-user-per-month / 14-day-trial / Scale pairing, the Denver founding, the Gerlach title, the DAST / API-security line, and the 200-plus-enterprises about-box are company-attributed. Early-access counts stay company-attributed — not independently verified here. NOT claimed: independently verified fix counts or hold rates, a broader customer-logo roster beyond the quoted CertiPath endorsement, that this desk tested Wingman, a stock tip, or investment advice. Distinct from the already-filed digicert-ai-trust-manager, nofire-brig-open-source, rockwell-anthropic-glasswing, esentire-atlas-aidr, testmu-kane-assurance, and wso2-agent-manager-ga.
RELATED
- NOFire open-sources Brig, a microVM sandbox for AI coding agents
- DigiCert launches AI Trust Manager with agent passports and a kill switch
- Rockwell joins Anthropic’s Project Glasswing for industrial cyber defense
- TestMu AI’s Kane CLI now designs tests straight from the PRD
- WSO2 ships Agent Manager GA to govern enterprise AI agents without locking to one stack
- eSentire buys stealth AI security startup, ships Atlas AIDR
On 15 Sep 2026 StackHawk announced the public launch of Wingman. The company PRIMARY is StackHawk’s PR Newswire release “StackHawk Launches Wingman to Autonomously Fix Vulnerabilities During AI Coding Sessions,” dated September 15, 2026, 08:00 ET, SOURCE StackHawk, and datelined DENVER. That company wire is the filing event. These are company claims. This desk did not run Wingman.