About this event
We shipped a payments feature in a consumer app this year. Real users, real money, and agents wrote the code. To review it we ran an agentic scanner: one agent hunts for reachable vulnerabilities, and three independent agents try to refute every finding before it counts. Confirmed findings feed a tracker that gates the deploy.
That setup exists because the old cadence stopped working. A design review at kickoff, a pentest before launch, a scan report read when someone has time. That rhythm made sense when a small security team was the scarce resource and the volume of code was bounded. Agents changed the second half of that equation.
Making your security standard machine-readable is what closes that gap. Once it is written in a form agents can apply, it runs in the spec, at design time, and on every pull request, without adding a single person to the security team.
We will show the whole setup, including the parts that misfire: false positives when a tool cannot see the whole application, findings that change between runs, and agent identity, which nobody has solved yet.