Build1 publisher3 min readPublished
Harness bundles six security agents into its pipelines, betting deployment control beats scanner quality
The set runs from AI SAST to virtual patching. Harness has published no customer results, so the case rests on owning the pipeline rather than on detection quality.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Harness launched a package of AI-assisted security tools on August 19th that moves vulnerability scanning, triage, remediation and temporary production protection into the same pipelines used to ship software.
- Harness already controls deployment workflows for its customers, and the new security agents are designed to use that position to follow a vulnerability from detection to a proposed code fix, then protect production while a developer reviews the permanent repair.
- Bansal is trying to make Harness the control plane for both shipping and securing software; the advantage depends on whether its agents produce reliable fixes, not simply more findings.
- Harness says all six capabilities are available as part of its platform: AI SAST, LLM Scan Orchestration, a Triage Agent, a Remediation Agent, a Zero-Day Agent and virtual patching.
- AI SAST pairs deterministic static analysis with an AI layer intended to suppress noisy findings and catch authorization flaws such as insecure direct object references, where an application improperly exposes another user's data or resources.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Harness released a package of AI-assisted security tools on August 19th that pulls vulnerability scanning, triage, remediation and temporary production protection into the same pipelines its customers already use to ship code [1]. The interesting part is not the detection technology but the consolidation logic: Harness already controls its customers' deployment workflows, and the agents are built to ride that position from a finding to a proposed fix to protection of production while a developer reviews the permanent repair [2].
Six capabilities are shipping as part of the platform: AI SAST, LLM Scan Orchestration, a Triage Agent, a Remediation Agent, a Zero-Day Agent and virtual patching [4]. AI SAST pairs deterministic static analysis with an AI layer meant to suppress noisy findings and catch authorization flaws such as insecure direct object references [5]. LLM Scan Orchestration accepts customers' own model-based scanners and pipes their output into the Harness workflow [6]. The Triage Agent ranks findings by exploitability [7]. The Remediation Agent writes and validates a repair and opens a pull request [8]. The Zero-Day Agent watches newly disclosed vulnerabilities, maps them to a customer's pipelines and artifacts, and prepares a fix [9]. Virtual patching applies a temporary protection layer without an immediate code change [10].
Read that list as a product taxonomy and it is unremarkable. Read it as an ingest-and-route architecture and the strategy is clearer. LLM Scan Orchestration explicitly treats third-party scanners as feedstock [6], which means Harness does not need to win the detection argument. It needs to be the place findings go. The company's own framing is that findings become more useful when the system holding them can also see repositories, pipelines, artifacts and deployment controls, because that context indicates whether vulnerable code is reachable and where a fix belongs [13]. Rahul Sood, who leads the portfolio, said Harness built the agents to "make security a first-class part of the delivery pipeline itself" [17][12].
The corporate plumbing behind this is recent. Harness and Traceable announced a definitive merger on February 10, 2025 and closed it effective March 4, 2025 [11]. Traceable co-founder Sanjay Nagaraj joined as an application-security engineering leader, with Sood, formerly chief product officer at Pindrop and an executive at Palo Alto Networks, Google, Meta and SAP, running the portfolio [12]. In December 2025, roughly nine months after the merger closed, Harness raised a $240 million Series E at a $5.5 billion post-money valuation, with Goldman Sachs leading $200 million of primary investment and IVP, Menlo Ventures and Unusual Ventures joining a related $40 million employee tender offer [14][21][20]. Jyoti Bansal founded Harness in 2017 after selling AppDynamics to Cisco for $3.7 billion the day before its planned IPO [18], and the company started in continuous delivery, automating deployments and rollbacks [19].
What is missing is evidence. Harness has attached no public customer results to the release, so its assertions about faster remediation and fewer false positives are company-supplied [15]. Its claim that the combined workflow compresses discovery-to-deployment from weeks to hours has not been established by independent benchmarks, and the release does not say how many customers are running the agents [16].
Two things decide whether this holds. First, the merge rate on Remediation Agent pull requests, since a proposed fix a developer rejects is just a finding with extra steps [8]. Second, how long virtual patches stay live [10]; a temporary layer that persists indefinitely is the metric that would show the fixes are not landing. Harness's own stated bet is that reliable fixes, not more findings, are the advantage [3].