Using AI agents to investigate every vulnerability across code and cloud.

Very similar to how we think at Maze. It sounds cool to train your own model but it’s not what matters when you’re building multi-agent systems handling specialised tasks. Slightly tuning the weights of a model matters much less than training and orchestrating the entire system.
There is no best model. There's a lot of noise about models right now. Who is training them, who owns them, where legal intelligence should live. One question actually matters: what produces the best outcome for the legal task in front of you? That's how we decide things at @WeareLegora. We optimize for the end-to-end outcome on a legal task. The model is one layer of that system, not the system. Models are uneven and the frontier changes almost weekly. One model plans a long job well, another runs deep analysis across thousands of documents. Some have to be told exactly what to do, and some are fine with a vague brief. They all break in different ways. So our lawyers write evals and we test them with the Legora BAR, our benchmark for agentic reasoning. Every model takes every test, and the model that wins gets the work. We post-train when we know it buys our customers better performance on a specialized task. Training is a tool we reach for when it helps, nothing more than that. The intelligence that compounds sits in the orchestration layer. Precedents, review standards, client requirements. That knowledge has to stay editable, auditable and portable. In our system, a changed review standard is an edit that takes effect the same day, with no new model training required. No lawyer should have to worry about which model did the work, any more than they think about which chip is in their laptop. They should only care about the quality of the work. That's what we are focused on. If you want the engineering version of this argument rather than the CEO version, our CPO, Bryan Tsao, and CTO, @jacsebl, take it apart in the video below.
1
3
83
AI didn't kill false positives. It made them more convincing. Long, detailed, confident answers that are still wrong. The real shift in AppSec is not better results, it is results you can trust. @HarryWetherald from @Maze_Security
1
2
141
Anyone can point an LLM at a codebase and find something. That is not an AI security product. If the tool is a black box that cannot explain how it reached a decision, walk away. @HarryWetherald on how to evaluate AI security vendors before you buy. @Maze_Security
1
1
107
"Security always comes second" is what the AI boom looks like from the inside. The backlog is a to-do list for attackers. That is why Harry built @Maze_Security.
3
3
3
1,509
Maze retweeted
Chatting about OpenAI and Hugging Face 🤗🤗🤗 on The Low Down presented by Maze Security.  Listen to the conversation: piped.video/watch?v=o340SGs9… 🎙️ @LowLevelTweets @mattjay
1
2
81
Security always comes second, and attackers know it. Our Head of AI @BEBischof sits down with @HarryWetherald, co-founder and CEO of @Maze_Security, for an In-Practice episode on the AI-driven arms race with attackers and what else teams can do since guardrails can't separate good hacking from bad. Watch: piped.video/watch?v=MXnLdZ9U…
1
1
9
2,607
The first time an AI security agent ran across a Fortune 100 cloud environment, the projected cost was $4M a week. There is a ceiling on what anyone will pay, so wasted spend is accuracy you never get to buy. Cost and accuracy are the same budget @HarryWetherald @Maze_Security
2
2
198
🚨 WARNING: A new challenger has appeared. A new podcast. The Low Down (Presented by @Maze_Security) IS NOW LIVE. DO YOU LIKE HACKING: Yes DO YOU LIKE YAPPING: Yes DO YOU LIKE PODCASTS: Yes 👇
8
8
141
11,756
Maze retweeted
Pssst. Me and @LowLevelTweets started a podcast. We recorded our 2nd episode live in SF last week. It's YouTube first but available wherever you get your podcasts. Introducing... The Low Down! Thanks @Maze_Security for being an awesome launch partner in this! Czech it out! piped.video/5pgvSbh8L_0 (If you love me, pls RT and send to your mom, moms love us)
8
17
77
15,472
If you’re interested in a) watching @BEBischof and I getting interupted filming by everything from guards to puppies or b) building ai agents for security, this could be for you… @Theoryvc piped.video/MXnLdZ9UHy0?si=TQXA… via @YouTube
1
1
5
261
1
1
108
Today we're launching Maze Code: AI agents that investigate vulnerabilities in your dependencies (AI-SCA) and your code (AI-SAST). With Maze Cloud, our agents investigate all vulnerabilities in your code and cloud on one engine.
3
1
4
215
Maze AI agents understand your code the way a security engineer would. They use context from your code, cloud, and business to investigate every vulnerability, figure out what matters, and automate remediation. Read more here: mazehq.com/blog/maze-code
1
36
We're constantly training our agents through layers of automated and human review, first for accuracy, then to be efficient. They learn to run the kind of deep, multi-step investigation that would take a security engineer hours, reasoning through every step and working as a team.
1
27
If a vulnerability is exploitable, Maze tailors a fix to exactly what the investigation found. It can flag inside your coding agent or land as a ticket to the developer responsible. When several vulnerabilities share a root cause, Maze closes them all with one fix.
1
82
Most AI code security products look good in a demo but struggle in production. Too unreliable, too expensive, or both. Today we're launching Maze Code, AI agents that find and fix vulnerabilities in your dependencies and in your own code. We built it to overcome the problems that usually hold AI code security products back. We think it's code security you can finally trust. More: mazehq.com
1
5
14
340