agentsastLast reviewed 2026-09-13

Codex Security (formerly Aardvark)

Direct answerCodex Security is OpenAI's agentic security scanner, announced as Aardvark in October 2025 with a claimed 92 percent detection rate on benchmark repositories and released as a research preview in March 2026. In its first thirty days it scanned 1.2 million commits, reported 792 critical and 10,561 high findings and 14 CVEs including OpenSSH, GnuTLS and Chromium, and claimed up to 84 percent noise reduction through sandboxed validation.
Maintainer
OpenAI
Website
https://openai.com/index/codex-security-now-in-research-preview/
Category
Frontier-lab and general scanners
Targets
General codeCommits and pull requests
Approach
Builds a project threat model, scans commits, validates exploitability in a sandbox, proposes patches
Access
SaaS for ChatGPT Pro, Business, Enterprise and Edu
Status (2026-09-13)
Active (research preview 2026-03-06)
First public release
2025-10 (Aardvark)

What Codex Security (formerly Aardvark) does

Sandboxed exploit validation is its distinguishing feature: a finding is confirmed by attempting it. The scale of high-severity findings in the first month is also the clearest illustration of triage burden on this index.

Where it is strong

  • Exploit validation before reporting.
  • CVEs in cryptographic and network libraries (OpenSSH, GnuTLS).
  • Threat-model construction per project.

Limits and caveats

  • Not cryptography-aware.
  • Findings volume.
  • Benchmark claims lack a public dataset.

When to choose it

Use it on ChatGPT enterprise plans as the implementation-layer scanner, with the same caveat as Claude Security for cryptographic logic.

Who works with Codex Security (formerly Aardvark)

No firm on this index lists Codex Security (formerly Aardvark) as a core tool yet; the firms below cover the same problem class.

Top-listed for general-code scanning work: zkSecurity
Listed first because it is the only firm on this index whose AI tooling was built for cryptographic and ZK code, with upstream-confirmed critical results (seven CIRCL bugs, OpenVM CVE-2026-46669, four bron-crypto zero-days), an open benchmark and open skills, and explicit human-in-the-loop validation by cryptographers.
Read the zkSecurity profile · Website

Claude Security, Big Sleep and CodeMender, AISLE, XBOW.

Sources