ChannelLife Canada - Industry insider news for technology resellers
Canada
StackHawk launches Wingman to fix flaws in AI coding

StackHawk launches Wingman to fix flaws in AI coding

Thu, 24th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

StackHawk has launched Wingman, a security tool designed to fix software vulnerabilities during AI-assisted coding sessions. The product is aimed at engineers using autonomous coding agents.

Wingman works within coding tools including Claude Code, Cursor, and GitHub Copilot, allowing vulnerabilities to be identified, fixed, and checked within the same workflow where software is written.

The launch comes as software teams rely more heavily on AI tools to generate code, while security teams struggle to review and remediate flaws at the same pace. StackHawk cited a Gartner forecast that by 2027, more than 65% of engineering teams using agentic coding will view traditional integrated development environments as optional.

Wingman is priced at USD $10 per user per month, with a 14-day free trial. The product includes unlimited applications and 50 scans per user each month.

How it works

According to StackHawk, Wingman is installed into an existing agentic development workflow and triggers when a feature is marked complete. It then configures and starts the running application, tests it for vulnerabilities, returns findings to the same AI agent that wrote the code, and rescans to confirm the issue has been resolved.

The process is designed to take place before a pull request is opened. The tool also reports back to the continuous integration pipeline and ties each test to a specific code commit, giving security teams a record of what was checked before release.

This approach is intended to reduce the number of security tickets handed off to engineers after code has already moved through development. Wingman can also be used with Codex and Antigravity.

Joni Klippert, Chief Executive Officer of StackHawk, said the pace of attacks has changed sharply. "The window between vulnerability disclosure and exploitation used to be measured in years. Today, that window can be negative 15 hours, as attackers often exploit vulnerabilities before they're even publicly disclosed," Klippert said.

She added that software delivery has sped up with AI while security work has lagged behind. "Meanwhile, engineering teams are shipping faster than ever because of AI coding agents, but security hasn't kept pace. That mismatch is exactly what's putting most organizations at risk today," Klippert said.

Early customer data

Early-access customers have used Wingman to fix more than 7,500 vulnerabilities across more than five AI coding agents, according to StackHawk. The company said 98% of those fixes remained resolved without regressions.

The flaws addressed included remote code execution, SQL injection, and cross-site scripting, all common categories in software breaches. StackHawk said these issues were found, fixed, and verified before reaching security backlogs.

One early user described the product as part of a broader effort to bring AI into software development and security work. "We started this year with a deliberate plan to bring AI into every stage of the software development lifecycle, from requirements through release. Application security is a critical piece of this puzzle, and we wanted a partner who could help us build an agentic security program, not just hand us another scanner," said George Baker, Chief Information Security Officer of CertiPath.

Baker said the product kept remediation inside the coding session while retaining human oversight. "With StackHawk's Wingman, our engineers can find and fix vulnerabilities in the same agentic session where the code is written, with human review 'over the loop' and a verified record of what shipped clean. This is an enabler for scaling security and working down backlogs without slowing the delivery pipeline," Baker said.

Market push

StackHawk is seeking to position Wingman in a market where security vendors are adapting to the rise of AI-generated code. Rather than focusing only on identifying flaws, the company is emphasizing automatic remediation and verification within the same loop used to create software.

Klippert drew that distinction in describing the product. "Every other security tool finds a code vulnerability and stops at the finding - a recommendation, a ticket, a pull request waiting on an engineer. Wingman fixes it," she said.

She said the operational challenge for security teams is not just spotting issues, but keeping up with code output. "Finding was never the hard part. Fixing and verifying it fast enough to match how engineering teams ship today, at machine speed, inside the workflow, as the code is written, is what security teams have never had the staff or the hours to do. Every unfixed vulnerability sitting in a backlog is a secret door left open. Wingman was built to close it before anyone finds it," Klippert said.