Application Security
,
Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
How Claude’s New AI Code Scanning Tool Will Challenge Application Security Leaders

The debut of Claude Code Security brought Anthropic into direct competition with the biggest pure-play cybersecurity vendors in the world, and investors have noticed.
See Also: How 72% of Enterprises Are Rewriting Cyber Resilience Playbooks
The new capability scans codebases for security vulnerabilities and suggests targeted software patches for human review. This is a space many big security vendors have bought into, with Palo Alto Networks spending $157 million on Bridgecrew in 2021 to codify infrastructure configuration during development and $198.3 million on Cider Security in 2022 to secure engineering processes from code to deployment (see: Palo Alto Networks to Buy Startup Cider Security for $250M).
Then in 2023, CrowdStrike spent $239 million on Bionic to obtain visibility into application behavior and prioritize vulnerability remediation. And in 2024, Wiz spent $450 million on Dazz to procure root-cause analysis and remediation capabilities for application vulnerabilities. Palo Alto’s stock has fallen 7.3% since Claude Code Security was announced Friday, while CrowdStrike’s stock fell 18.4% over the same period (see: Wiz Fortifies Application Security With $450M Dazz Purchase).
While Claude Code Security could commoditize the code scanning market and devalue CrowdStrike and Palo’s existing bets, it represents a very small part of their overall platform strategy. CrowdStrike was born in the endpoint security space and today offers 29 modules across multiple large markets, while Palo Alto has platforms for network security, security operations, cloud security and threat intelligence.
In contrast, Claude Code Security could disrupt the core business of application security incumbents like Veracode, Checkmarx, Snyk and Black Duck Software. Anthropic eschews using static analysis for security testing, saying they often miss more complex vulnerabilities such as flaws in business logic or broken access control. Anthropic said it can read and reason about code the way a human security researcher would (see: Anthropic’s AI Bug Hunter Jolts Cyber Stocks).
Anthropic Faces Pressure From Many Code Security Assistants
Getting visibility into investor sentiment around the application security mainstays is more challenging since all are privately held. Checkmarx was acquired by Hellman & Friedman for $1.15 billion in April 2020, Veracode was acquired for $2.5 billion by TA Associates in May 2022, Black Duck was acquired by Francisco Partners and Clearlake Capital for $2.1 billion in October 2024 and Snyk is venture-backed.
At the same time, the Gartner Magic Quadrant illustrates how much broader Claude must go to rival application security testing leaders. Existing firms offer dynamic and interactive application security testing, secrets detection, API security testing, container security testing, infrastructure-as-code scans, application security posture management, software supply chain security and secure coding assistants.
New entrants into a crowded market tend to prioritize feature depth over feature breadth, and Claude out of the gates is attempting to do code scanning better than incumbents in the space. But Claude is unable to address the broad range of application security use cases required by large enterprises and organizations in highly regulated industries, who wish to buy from fewer vendors.
Given the decade or multi-decade head start existing application security testing vendors have, it could take Claude many years to get to feature parity through organic investment. In addition to competing against code security startups acquired by large platform vendors, Claude will have to take on artificial intelligence code security assistants with years of R&D behind them that have been built or acquired by AppSec vendors.
Black Duck Assist is an AI code assistant for remediation guidance and code fixes, and shows higher-than-median acceptance rates for automated remediation suggestions, Gartner found. Checkmarx’s AI Code Security Assistant provides secure coding support by monitoring and prompting secure code assistants for secure code, according to Gartner.
Microsoft-owned GitHub has Copilot Autofix – one of the most widely adopted AI code security assistants – which leverages AI to suggest secure code fixes for vulnerabilities and provides actionable guidance directly within pull requests. Veracode Fix provides human-in-the-loop remediation suggestions that developers can review and accept within IDEs, pull requests or in bulk via the CLI.
Semgrep Assistant leverages AI to automate triage and provide custom, step-by-step remediation guidance based on Semgrep rules and code context, according to Gartner. And HCLSoftware’s CodeSweep provides real-time integrated development environment feedback and AI-powered autofix recommendations, Gartner said.
Why Price Will Be a Differentiator for Claude Code Security
While Claude Code Security doesn’t depend on scanning for known patterns, it faces headwind from the fact most firms use a combination of traditional and AI tools for generating code, not just Claude. Claude will be at a disadvantage when it comes to protecting code that it didn’t generate itself since Anthropic rivals would rather pursue deep integrations and road map visibility with a neutral code security vendor.
The biggest element working in Anthropic’s favor is price, where Claude Code Security will significantly undercut everyone in the market. Anthropic is already describing Claude Code Security as a capability built into Claude Code on the Web rather than a standalone product or module. Anthropic’s decision to not productize Claude Code Security will be significant for price-sensitive buyers.
Anthropic just raised $30 billion on a $380 billion valuation, so it can afford to give code security away at a loss if it means gaining market share and displacing existing tools. Incumbents are operating under much tighter budgets, with Black Duck, Snyk and Veracode cutting headcount by 8%, 9% and 19% since the end of 2024, respectively. They can’t afford to bundle in AI code security assistants at no added cost.
Claude Code Security will be a good fit for “born in AI” companies that standardize on Anthropic and Claude as well as for small businesses and mid-market organizations that face limited regulatory and compliance issues and don’t have particularly complex code security requirements.
For larger enterprises or companies in highly regulated industries including financial services or healthcare, Claude Code Security is unlikely to be a good fit until the offering matures to address a broader set of use cases, likely through large, strategic acquisitions. The company would also benefit from making an inorganic play to achieve parity around securing code that’s generated by entities other than Claude.
