

Blitzy has made available a sandbox where DevOps teams can reverse-engineer up to one million lines of code, generate up to 25,000 lines of tested end-to-end code, and identify security vulnerabilities across a codebase at no cost.
Blitzy provides that capability by building a knowledge graph that spans architecture, dependencies, business logic, and data flows, mapped back to the actual code. That graph is queryable and continuously evolves as a codebase changes. Known and previously undiscovered vulnerabilities get traced through their execution paths, checked against dependencies, and validated for remediation.
Thousands of AI agents are then used to build, validate and test code in parallel, with the output surfaced as a set of pull requests prioritized by risk level that human software engineers can review and approve.
Additionally, DevOps teams can use Proactive Insights to reverse-engineer an undocumented legacy application, add a new feature to an existing system, upgrade a service to a modern framework or build an entirely new application, noted Ochs. Blitzy also ensures that no code is ever used to train an AI model and that all data is encrypted in transit and at rest to ensure compliance mandates are met.
Blitzy is now making a sandbox environment available at no cost in the hopes of exposing that capability to more DevSecOps teams at a time when many of them are now hunting for vulnerabilities in their codebase that might be discovered first by cybercriminals using any number of AI platforms. In effect, DevSecOps teams are now locked in a race against time that requires AI tools to discover and remediate what could be thousands of vulnerabilities before they are exploited. The only way to meet that challenge will be to rely more on an AI platform capable of understanding how a codebase was constructed at scale, said Ochs.
While most DevOps teams are using AI to generate code, it’s clear AI will soon need to be embedded into the DevSecOps workflows used to discover, validate and remediate vulnerabilities. The challenge is that whatever AI platform is used to provide those capabilities will need to understand the underlying codebase. In the absence of that context, much of the code generated isn’t likely to actually run as intended in a production environment.
At this point it’s apparent that software engineers are evolving into managers of AI agents that are assigned specific tasks to autonomously complete. Each DevOps team will make that transition at their own pace, but in the face of what is becoming a tsunami of vulnerabilities that are likely to be discovered in the weeks and months ahead, there may actually be no better time than the present to get started.
