Thirty years ago, software developers wrote code line by line, and a handful of them per company shipped anything to production. Ten years ago, DevOps engineers automated that pipeline and multiplied what each of them could deploy. Three years ago, AI coding assistants—GitHub Copilot, Cursor, Claude Code—started writing meaningful percentages of that code alongside them. Today, AI app generators let anyone with a browser tab describe an app in plain English and deploy a working version in minutes.

Each wave lowered the barrier to entry. Each wave multiplied the builder population. And each wave added a fresh layer to the attack surface without waiting for security to catch up.

Big idea: The attack surface didn’t grow because AI got smarter. It grew because AI put a builder’s toolkit into every employee’s hands.

The numbers under the shift

The scale is easy to underestimate. A few anchor points:

Together, these stats form one picture: the population creating production-facing software is now an order of magnitude larger than the security team was built to govern, and it’s growing faster than any previous wave of dev tooling ever did.

What builders now ship, and where they ship it

The CNAPP model assumes a discrete list of cloud accounts, provisioned by a DevOps team, changing on a quarterly cadence. That model breaks under builders who spin up production surfaces from a prompt.

Consider a single week inside a modern enterprise:

  1. A developer uses Cursor to refactor a service and pushes to production on a Friday night. The IAM role attached to that service is over-permissioned; nobody reviewed it because Cursor generated it.
  2. A data scientist deploys a Claude-powered inference endpoint from a Vercel project. The endpoint reads from a customer database. The project is set to org-wide visibility because that was the default when v0 created it.
  3. A product manager uses Lovable to prototype an internal tool that pulls from HR data. Lovable ships it. The environment variables holding the HR API key sit in plaintext because the PM didn’t know Vercel had a “sensitive” toggle.
  4. A marketer uploads a customer CSV to a Claude project so it can score her leads. She never wrote a line of code. The project is shared org-wide by default; retention has never been limited at the organization level; the customer file now lives in Claude storage with no expiration.

Every one of those events happens in production. None of them touches an AWS account in a way your CNAPP would flag. They touch Vercel deployments, Claude Enterprise workspaces, GitHub repositories full of agent-generated code, MCP servers wired into internal tools, and dozens of other platforms that live between the developer and the cloud but sit outside most CNAPP tenants.

Big idea: CNAPP covers the cloud accounts your DevOps team owns. It does not cover the platforms where your builders actually build.

Why existing tools miss this

CNAPP was built for AWS, Azure, and Google Cloud. SSPM was built for Salesforce and Microsoft 365. Both categories assume a small, stable set of connected accounts owned by a central team.

The platforms builders use now break both assumptions. Vercel isn’t a cloud account; it’s a control-plane PaaS with team workspaces, deployment-protection rules, WAF configurations, and environment variables holding secret-like strings that most CNAPPs never look at. Claude Enterprise isn’t a productivity suite; it’s a control-plane PaaS where SSO enforcement, data retention, session-duration limits, and project-visibility defaults directly determine whether the LLM your finance team uses can be reached from a personal laptop on a coffee-shop network.

Both are mainstream. Vercel’s v0 alone crossed 4 million users in early 2026. Anthropic’s enterprise deployments sit inside the security perimeter of a growing list of Fortune 500 companies. The challenge is that most security teams have zero posture visibility into either.

This is what AI AppGen Security is built to address.

AI AppGen Security: What coverage looks like when you take builders seriously

AI AppGen Security is a distinct capability set shaped around what makes AI app generators different from every wave of tooling before them: the code is written by an agent, the infrastructure is configured by defaults nobody set, the deployment ships without a human in the loop, and the builder pressing the button is often not a developer or security expert. What’s needed is coverage designed for that reality.

What does AI AppGen Security look like in practice? Two new Orca integrations show the pattern today: the LLM console that powers many AI app generators, and the deployment surface they ship to.

Claude Enterprise. Orca connects to Claude’s Compliance API and identifies misconfigurations across identities, projects, data security, and more. Security leaders can detect unenforced SSO, indefinite retention, non-private projects, sessions with no expiration, over-privileged owner roles.

Vercel. Orca connects with Vercel’s API to inventory teams, users, access tokens, projects, deployments, custom domains, environment-variable metadata, and firewall configuration. Then Orca detects misconfigurations like plaintext secret-like environment variables, production URLs left unauthenticated, non-expiring API tokens, disabled WAFs, and org-wide public projects. Every finding maps to the same unified data model and risk scoring already used for AWS, Azure, and GCP.

Both integrations solve the same problem from different angles: securing the surfaces where AI-generated apps actually live, with detections built for how AI configures them. That’s what AI AppGen Security means in practice: coverage designed for the way these tools ship, not for the traditional pipelines that existed before they did.

Big idea: AI AppGen Security is coverage built from how AI app generators actually work, from the LLM they run on to the surface they deploy to.

The CISO’s real job when everyone is a builder

The temptation, when the builder population outgrows the security team, is to say no. Block the platforms, restrict the tools, require review for every prototype. That approach loses. Builders route around it, shadow-AI numbers prove they already are, and the CISO who blocks Vercel this quarter watches a marketing team ship on a different platform next quarter.

The alternative isn’t to say yes to everything. It’s to turn “no” into “I know” and see everything. Every builder, every platform they ship on, every misconfiguration that ships with them, surfaced in the same risk model, prioritized against the same context, remediated through the same workflows already in place. That is what security for the companies that build has to mean in practice. Not another dashboard. Not another set of alerts to triage. One picture of risk that extends as far as your builders do.

About the Orca Platform

Orca Security delivers security for the companies that build. As cloud, applications, AI and app generation expand the attack surface, Orca transforms security risk into the context teams need to act. The Orca Platform provides complete visibility across cloud, AI, and application environments, correlates risk across every layer, and prioritizes the exposures that matter most so organizations can remediate faster and innovate with confidence. Trusted by hundreds of organizations, including SAP, Autodesk, Gannett, Lemonade, and Digital Turbine, Orca is backed by leading investors including Temasek, CapitalG, ICONIQ Capital, and Redpoint Ventures.

Get notified about updates as Orca expands AI AppGen Security.