{
    "title": "Detectify launches MCP Server to secure the autonomous coding loop",
    "modified_at": "2026-05-26 13:21:23",
    "published_at": "2026-05-26 13:00:00",
    "url": "https://newsroom.detectify.com/detectify-launches-mcp-server-to-secure-the-autonomous-coding-loop",
    "short_url": "http://prez.ly/IiHd",
    "culture": "en",
    "language": "EN",
    "subtitle": "As AI agents take over the software lifecycle, Detectify\u2019s paradigm shift in AppSec embeds continuous, autonomous security validation directly into the fast-paced development loop.",
    "slug": "detectify-launches-mcp-server-to-secure-the-autonomous-coding-loop",
    "body": "<p>STOCKHOLM, Sweden (May 26th, 2026)<strong> </strong><a href=\"https://detectify.com/\"><u>Detectify</u></a>, the Swedish application security platform built and trusted by hackers, today announced the launch of the Detectify MCP (Model Context Protocol) Server, a new integration layer that brings Detectify&rsquo;s security testing engines directly into AI-driven development workflows, helping coding agents find and validate exploitable vulnerabilities and interpret attack surface data with unprecedented precision.</p><p>As organizations increasingly rely on AI agents to write, refactor, and modernize code, software production is accelerating faster than many security teams can realistically review or govern. Whether through official engineering initiatives or shadow AI adoption by developers eager to speed up work, AI-assisted development can help eliminate some common coding mistakes. It is also dramatically increasing the volume of software, services, APIs, and infrastructure organizations must continuously track and secure. The result is a growing visibility and governance challenge, compounded by shadow IT and shadow AI adoption, where organizations may write cleaner code while simultaneously losing track of what they are deploying and exposing.</p><p>The Detectify MCP Server is designed to close that gap by giving AI agents a standardized way to augment development and security workflows with AI-assisted access to Detectify findings and capabilities, \u200b allowing them to access and act on real-time security findings as part of autonomous development workflows. Rather than relying on periodic reviews or delayed security handoffs, organizations can embed continuous validation more directly into the software delivery process as code, infrastructure, and services evolve.</p><p>Key MCP Server capabilities include:</p><ul class=\"release-content-list release-content-list--bulleted release-content-list--align-inherit\"><li><span><strong>&ldquo;Find &amp; Fix&rdquo; Automation</strong>: Instead of security findings landing in a static backlog, they can now be handed directly to AI agents as structured remediation tasks. Agents can generate a patch, trigger a Detectify validation scan to confirm the vulnerability is resolved, and present a verified fix for human review.</span></li><li><span><strong>Conversational Command: </strong>Query scan results, monitor asset status, and surface high-severity findings through natural-language interactions connected to the Detectify MCP Server.</span></li><li><span><strong>Frictionless Setup:</strong> A lightweight configuration allows organizations to connect their preferred AI tools to the remotely hosted Detectify MCP server for simplified deployment and connectivity.</span></li></ul><p><em>&quot;We aren&#039;t competing with the AI&rsquo;s reasoning; we are providing the professional-grade tools that reasoning requires,&quot; </em>says<strong> Rickard Carlsson, CEO of Detectify.</strong> <em>&quot;By structuring our capabilities as modular, high-performance building blocks, we allow agents to call our scanner as naturally as they call a test runner. We are expanding from a dashboard humans check to a skill agents orchestrate.&quot;</em></p><p>Traditional application security workflows were built around slower development cycles, where human review and periodic testing could reasonably keep pace with software delivery. In modern AI-assisted environments, those assumptions are increasingly breaking down as code, infrastructure, and services evolve continuously.</p><p>The launch reflects a broader shift in AppSec toward continuous, real-time security validation. While LLMs excel at reasoning, frontier models operate at a speed and cost-profile that makes large-scale security testing impossible. Detectify solves this by monitoring millions of changing domains using compiled, deterministic code, while the MCP Server combines that scale with agentic workflows to help security operate at the same velocity as engineering.</p><p><em>&ldquo;AI systems are probabilistic by nature. Security validation cannot be. Agents still need deterministic, trustworthy ways to verify whether something is actually exploitable before software reaches production,&rdquo; </em>Carlsson continued.</p><p>As AI-assisted development continues to accelerate engineering velocity, organizations face increasing pressure to move beyond one-time security reviews and maintain continuous visibility into what exists across their attack surface.</p><p>The Detectify MCP Server will be available soon as part of Detectify&rsquo;s continued investment in AI-native application security. For more information, visit Detectify.com.</p><p><strong>About Detectify<br>\u200b</strong>Founded by ethical hackers in 2013, Stockholm-based Detectify is an application security platform trusted by over 2,100 organizations globally, from high-growth startups to the world&rsquo;s largest enterprises and public institutions. Detectify equips modern security teams with clarity and control over their attack surface. Fueled by real-world validated payloads from its global community of elite ethical hackers and scaled through its own AI-driven engines, Detectify enables organizations and their agents to identify and fix truly exploitable vulnerabilities before attackers do.</p><p><strong><br>\u200bMedia Contacts</strong></p><div class=\"release-content-contact\" id=\"contact-72d8bc23-50ce-4ded-b484-41b0a049224a\">\n    <div class=\"release-content-contact__avatar\"><img src=\"https://cdn.uc.assets.prezly.com/0d2368c6-c87d-457d-85e3-0c3fcfd08626/-/crop/2749x2750/1662,856/-/preview/-/scale_crop/128x128/center/-/format/auto/\" alt=\"Jorge Vicente\" class=\"release-content-contact__avatar-image\" /></div>\n    <div class=\"release-content-contact__details\">\n        <strong class=\"release-content-contact__name\">Jorge Vicente</strong>\n        <em class=\"release-content-contact__description\">Global Brand &amp; Communications Manager, Detectify</em>\n        <ul class=\"release-content-contact__details-list\"><li class=\"release-content-contact__details-list-item\"><a href=\"mailto:jorge.vicente@detectify.com\"  class=\"release-content-contact__details-list-item-link\" title=\"jorge.vicente@detectify.com\"><svg class=\"icon icon-paper-plane release-content-contact__details-list-item-icon\">\n                <use xlink:href=\"#icon-paper-plane\"></use>\n            </svg>jorge.vicente@detectify.com</a></li>\n<li class=\"release-content-contact__details-list-item\"><a href=\"tel:+46761146350\"  class=\"release-content-contact__details-list-item-link\" title=\"+46761146350\"><svg class=\"icon icon-phone release-content-contact__details-list-item-icon\">\n                <use xlink:href=\"#icon-phone\"></use>\n            </svg>+46761146350</a></li></ul>\n    </div>\n</div><div class=\"release-content-contact\" id=\"contact-ca6fd0ca-422b-4e20-8df1-98a20e5fc58e\">\n    <div class=\"release-content-contact__avatar\"><img src=\"https://cdn.uc.assets.prezly.com/ad23e41a-1e4e-41c4-8252-c51397f25a9f/-/scale_crop/128x128/center/-/format/auto/\" alt=\"Rachel McIntosh\" class=\"release-content-contact__avatar-image\" /></div>\n    <div class=\"release-content-contact__details\">\n        <strong class=\"release-content-contact__name\">Rachel McIntosh</strong>\n        <em class=\"release-content-contact__description\">San Francisco PR for Detectify</em>\n        <ul class=\"release-content-contact__details-list\"><li class=\"release-content-contact__details-list-item\"><a href=\"mailto:detectify-team@sanfrancisco.fi\"  class=\"release-content-contact__details-list-item-link\" title=\"detectify-team@sanfrancisco.fi\"><svg class=\"icon icon-paper-plane release-content-contact__details-list-item-icon\">\n                <use xlink:href=\"#icon-paper-plane\"></use>\n            </svg>detectify-team@sanfrancisco.fi</a></li></ul>\n    </div>\n</div>",
    "header": {
        "large": "https://cdn.uc.assets.prezly.com/98ba0a94-4a1d-4348-a280-af0488d5f25b/-/preview/1200x1200/-/format/auto/",
        "release": "https://cdn.uc.assets.prezly.com/98ba0a94-4a1d-4348-a280-af0488d5f25b/-/preview/1200x1200/-/format/auto/"
    },
    "contacts": [
        {
            "name": "Jorge Vicente",
            "company": "Detectify",
            "description": "Global Brand & Communications Manager",
            "email": "jorge.vicente@detectify.com",
            "website": null,
            "address": null,
            "telephone": "+46761146350",
            "mobile": null,
            "twitter": null,
            "facebook": null
        },
        {
            "name": "Rachel McIntosh",
            "company": "San Francisco PR for Detectify",
            "description": null,
            "email": "detectify-team@sanfrancisco.fi",
            "website": null,
            "address": null,
            "telephone": null,
            "mobile": null,
            "twitter": null,
            "facebook": null
        }
    ],
    "author": {
        "first_name": "Jorge",
        "last_name": "Vicente"
    },
    "format_version": 5
}