top of page
Search

How Tech Ascension’s Best Application Security Solution Winner Mend.io Is Rethinking Application Security for the AI Era

5 days ago
4 min read

We sat down with Azi Cohen, Co-Founder and CEO of Mend.io, to discuss the company’s 2026 Tech Ascension Award for Best Application Security Solution and how Mend.io is helping organizations secure software as development becomes faster, more distributed and increasingly AI-driven. In this interview, Azi discusses how AI is changing the application security landscape, why visibility and risk prioritization have become critical, and how organizations can keep pace with development without compromising security.


Mend.io was named Best Application Security Solution in the 2026 Tech Ascension Awards. What do you believe sets Mend AppSec apart in today’s market?


The application security landscape has fundamentally changed. Organizations are no longer securing just proprietary code and open-source dependencies; they are also securing AI-generated code, large language models, AI agents, retrieval-augmented generation pipelines, system prompts and other AI components.


Mend AppSec was built for this reality, bringing application security, software supply chain security and AI security together in a unified platform. It gives organizations visibility across the code and AI layers of modern applications while integrating into the developer workflows they already use.


Just as importantly, Mend.io is focused on helping teams act on risk, not simply generate more findings. By combining contextual risk prioritization, reachability analysis and AI-powered remediation, Mend AppSec helps security teams focus their limited resources on the vulnerabilities that present the greatest business risk.


Mendo.io

How is AI changing the application security challenges organizations face today?


AI is accelerating both software development and the complexity of what organizations need to secure. AI coding assistants are increasing the volume of code developers produce, while applications are incorporating new components such as models, agents and prompts.


That creates new security challenges. Teams need to understand not only whether traditional code and dependencies contain vulnerabilities, but also what AI components exist in their environment, how they are configured and how they could behave when exposed to adversarial inputs.


The challenge is that security teams have not received more people or more time to manage this growing risk. They need security processes that can operate at the same speed as development, with continuous visibility, automated testing, intelligent prioritization and faster remediation.


Why is visibility such an important starting point for securing AI-powered applications?


You can’t secure what you can’t see. One of the biggest challenges organizations face is that they often have far more AI embedded across their applications and environments than they realize.


AI can enter an organization through developer tools, third-party services, models, agents and APIs, making it difficult to track manually. Before organizations can assess the security of these components, they first need to understand where AI exists, how it is being used and how it connects to the broader environment.


That makes discovery the foundation of an effective AI security strategy. Organizations need a continuously updated view of their AI footprint that enables them to identify risks, apply the right controls and continuously test and secure AI systems as they evolve.


Why has risk prioritization become so important for security teams?


Finding vulnerabilities has never been the only challenge. The harder—and increasingly important—task is determining which vulnerabilities represent meaningful risk and where security teams should focus their attention first.


Not every vulnerability is equally exploitable or impactful. A flaw in a critical, internet-facing application may demand immediate attention, while a higher-severity vulnerability in an isolated environment may pose far less risk.


Mend AppSec uses contextual signals and reachability analysis to help teams distinguish between these scenarios and prioritize the vulnerabilities that matter most. This becomes even more critical as AI accelerates software development and increases the volume and velocity of code and security findings.


When teams treat every finding as equally urgent, AI-driven development can quickly overwhelm security teams and developers alike. Effective risk prioritization helps organizations focus on the vulnerabilities that pose the greatest real-world risk and allow security programs to scale with development without overwhelming the teams responsible for fixing the issues.


How does Mend AppSec help organizations secure traditional and AI-powered applications without adding complexity?


Security cannot become another bottleneck for development. Organizations need to protect applications throughout the software development lifecycle while allowing developers to move quickly.


Mend AppSec brings security for proprietary code, open-source dependencies, containers and AI components into a unified platform and integrates directly into developer environments, repositories and CI/CD pipelines.


Mend.io also extends application security practices into the AI layer, giving organizations capabilities to discover AI components, identify AI-specific weaknesses, harden system prompts, assess agent configurations and protect AI applications at runtime.


The result is a more connected approach to security that reflects how modern applications are actually built and operated.


What measurable impact can organizations achieve with this approach?


The goal is to reduce the time and effort required to identify, prioritize and remediate meaningful vulnerabilities.


According to Mend.io’s Open Source Risk Report, organizations that implemented Mend repository integration and remediation best practices reduced average remediation time from 271 days to 70 days – a 75% improvement – while increasing remediation rates from 13% to 40%.


We have also seen significant results at the customer level. Global advisory firm WTW reduced both developer remediation time and mean time to remediate vulnerabilities by at least 80% after implementing Mend.io.


These results demonstrate the value of integrating security into development workflows. When teams can prioritize risk and give developers actionable remediation guidance within the tools they already use, they can improve security outcomes without sacrificing development velocity.


What comes next for Mend.io and the application security market?


Application security and AI security will increasingly become part of the same conversation. AI is becoming embedded in how software is built, deployed, and operated, and security needs to evolve alongside it.


For Mend.io, that means continuing to expand visibility across the AI attack surface, strengthen risk prioritization and remediation and help organizations protect AI-enabled applications throughout their lifecycle from development and testing to production.


The goal isn’t to give organizations another endless list of vulnerabilities. It’s to help security teams understand what matters, prioritize the risks that matter most, fix them faster and continuously protect the applications they’re building.


AI is accelerating the pace of software development. Security needs to accelerate with it.

 
 
bottom of page