Checkmarx Fusion Launch – Hybrid AI‑Rules Vulnerability Scanning

On July 30, 2026, from Pune, Maharashtra, Checkmarx announced the availability of Checkmarx Fusion in early access for its customers. Fusion is positioned as a hybrid scanning approach that merges Checkmarx’s long‑standing application security (AppSec) engines and proprietary security context with frontier AI models from Anthropic, specifically the Claude family, accessed through Amazon Bedrock.

The solution is designed to provide “the most complete vulnerability detection available, spanning every language, every codebase, and every stage of the software development lifecycle,” according to the company. Checkmarx’s 2026 Future of Application Security report is cited, stating that 49 % of production code is now AI‑generated, underscoring the urgency for AI‑aware security tools.

Technical Performance

Checkmarx Fusion achieves an F1 score of 0.741, which the release claims is nearly four times the category average. The architecture synthesizes outputs from multiple scanning engines to confirm true positives and suppress false positives, delivering what the company describes as the highest‑fidelity vulnerability detection in the industry. A multi‑model AI engine extends detection to any language beyond a fixed rule set, including emerging and AI‑generated languages.

Deployment and Compliance

Scanning workloads run entirely within the customer’s own cloud environment via Amazon Bedrock, ensuring that source code never leaves the client’s infrastructure. This design directly addresses data‑residency and compliance concerns for regulated industries, allowing organizations to meet stringent security and privacy requirements while leveraging AI‑driven analysis.

Cost and Efficiency

Model optionality enables customers to balance cost and performance without sacrificing coverage, resulting in faster scan times and lower operational costs. The hybrid approach combines deterministic, rules‑based precision with AI reasoning, reducing the operational burden on application security teams.

Executive Commentary

  • Sandeep Johri, CEO of Checkmarx, said the company is at an “inflection point in application security” and positioned Fusion as the answer to AI‑driven code volume, delivery speed, and risk complexity.
  • Ashraf Alhashim, Head of Enterprise Cybersecurity GTM at Anthropic, highlighted the partnership as a compelling example of applying frontier AI within deep security context.
  • Erik Brown, Business Information Security Officer, AppSec Leader at Nelnet, emphasized that security must be an enabler, not a bottleneck, and praised the hybrid approach for scaling while maintaining high fidelity.
  • Mustapha Kebbeh, Chief Security Officer at UKG, noted that board‑level conversations now focus on discovering critical vulnerabilities quickly, a need Fusion is built to address.

Availability and Demonstration

Checkmarx Fusion is available now in early access as part of the Checkmarx One platform. The product will be demonstrated at Black Hat USA in Las Vegas, with the Checkmarx booth numbered #4553. Interested parties can register for a meeting via checkmarx.com/black-hat/ or request early access through Checkmarx.com/platform/checkmarx-fusion.

Company Background

Checkmarx describes itself as the leader in “agentic application security,” scanning trillions of lines of code annually and claiming to cut vulnerability density by more than half. Its autonomous security agents continuously detect and counter AI‑driven threats across the software development lifecycle, supporting legacy, modern, and AI‑generated code at enterprise scale.