cd /news/ai-products/orca-security-launches-ai-applicatio… · home topics ai-products article
[ARTICLE · art-80333] src=letsdatascience.com ↗ pub= topic=ai-products verified=true sentiment=· neutral

Orca Security Launches AI Application Security Tools

Orca Security launched AI AppGen Security and AI Code Security Auditor on July 30, extending its cloud security platform to cover applications built with AI-powered builders like Claude, Supabase, and Lovable, as well as code developed in traditional pipelines. The company's State of AI Security Report 2026 found that 52% of organizations build custom applications with AI, and IBM estimates breaches involving shadow AI cost an average of $670,000 more than other incidents.

read3 min views1 publishedJul 30, 2026
Orca Security Launches AI Application Security Tools
Image: Letsdatascience (auto-discovered)

Orca Security announced two AI-powered security capabilities on July 30: AI AppGen Security for applications built outside conventional development pipelines, and AI Code Security Auditor for code developed within them. Help Net Security reports that the releases extend Orca's platform across AI-powered application builders, including Claude, Supabase, and Lovable, and traditional engineering workflows.

Orca Security announced AI AppGen Security and AI Code Security Auditor on July 30, expanding its cloud security platform to cover applications produced through AI-powered builders and code created in conventional development pipelines.

According to Help Net Security, AI AppGen Security is designed to discover and secure applications created outside established development processes on platforms including Claude, Supabase, and Lovable. The second capability, AI Code Security Auditor, provides AI-driven static analysis for code developed within traditional pipelines.

Security coverage beyond conventional pipelines

The launch addresses a growing distinction between software created by professional engineering teams and applications assembled by employees using AI application-generation services. Orca's product page describes such applications as a form of shadow IT that can run on vendor-operated infrastructure, connect to organizational data, and fall outside security teams' normal visibility.

Help Net Security reports that Orca's State of AI Security Report 2026 analyzed anonymized telemetry from more than 1,200 production cloud environments through the Orca Research Pod. The report found that 52% of organizations build custom applications with AI, according to the publication.

The same article cites an IBM estimate that breaches involving shadow AI cost organizations an average of $670,000 more than other incidents. That figure is external research cited in Orca's announcement, rather than an independently reported result of the product release.

Implications for security teams

The two capabilities separate two security problems that often appear together in AI-assisted development: asset discovery for applications created outside governed pipelines, and code analysis for software still passing through engineering workflows. Help Net Security characterizes the combined release as coverage for both professional developers and AI-assisted builders.

Comparable shifts toward low-code and AI-generated application delivery commonly expand the number of identities, endpoints, data flows, and third-party hosting environments that require inventory and access review. The practical value of tools in this category depends on whether they can associate externally created applications with underlying cloud assets, exposed secrets, public endpoints, and business data, while producing findings that security teams can prioritize alongside existing application-security workflows.

Orca's announcement provides no independent evaluation of detection accuracy, supported AI application platforms beyond the examples named, or integration details for developer tooling. Those implementation details will determine how readily organizations can incorporate the capabilities into cloud security and software-development governance processes.

Key Points #

  • 1Orca released separate tools for discovering AI-generated applications and statically analyzing code in conventional development pipelines.
  • 2Orca's reported telemetry found that 52% of organizations build custom applications with AI.
  • 3Comparable AI application-generation adoption expands asset inventory and data-flow visibility requirements beyond established developer tooling.

Scoring Rationale #

The release targets an increasingly relevant security gap created by AI-assisted and low-code application development. It is a notable platform capability announcement for cloud and application-security practitioners, but the available sources provide no independent performance validation or broad deployment evidence.

Sources #

Primary source and supporting public references used for this report.

Practice with real Ad Tech data

90 SQL & Python problems · 15 industry datasets

[Active Search Campaigns by BudgetEasy](/problems/sql/active-search-campaigns-by-budget)

[High CPC Clicks & Poor Landing PagesMedium](/problems/sql/high-cpc-clicks-poor-landing-page)

[Campaign ROAS by Attribution ModelHard](/problems/sql/campaign-roas-by-attribution-model)

250 free problems · No credit card

See all Ad Tech problems

── more in #ai-products 4 stories · sorted by recency
── more on @orca security 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/orca-security-launch…] indexed:0 read:3min 2026-07-30 ·