BetaEditorial Listing

CodeMender

Google · CodeMender: Google Cloud's AI Agent That Finds, Verifies, and Fixes Code Vulnerabilities

Open CodeMender

CodeMender is Google Cloud's managed AI code-security agent, originally developed by Google DeepMind, that scans a codebase for vulnerabilities, verifies them in a local sandbox, and proposes tested patches for developers to review. It is in public preview for a limited set of Google Cloud customers and suits security and platform teams that already work in Google Cloud.

PricingPaid
Setuphard
Runs onDesktop
Open sourceNo
DocsYes
CategorySecurity
Code SecurityVulnerability RemediationGoogle CloudGeminiApplication SecurityCLIPreview

Best for

Security and platform teams already on Google Cloud who want an agent that verifies vulnerabilities and proposes tested patches, and who can join a preview program

Not ideal for

Teams that need a generally available product for production use today, organizations outside Google Cloud, and anyone looking for a free or self-serve tool

Who it's for

Enterprise security, AppSec, and platform engineering teams on Google Cloud

Capabilities

  • Find, verify, and fix workflow: scan code, confirm findings, and generate tested patches
  • Import findings from external scanners and have CodeMender verify and fix them
  • Verification and patch testing run in a local process-level sandbox with outbound network blocked by default
  • Patches are built and unit-tested before you approve each file write; nothing is pushed to version control automatically
  • Local-first CLI (`cm`) that sends only targeted code snippets to the hosted agent
  • Resumable sessions, reports in HTML, Markdown, JSON, or SARIF, and pull-request delta scans with a CI failure threshold
  • Choice of Gemini models per command, with Gemini 3.8 Flash as the default
  • Enterprise controls including VPC Service Controls, per-project isolation, and no training on customer source code
  • Available on Gemini Enterprise Agent Platform or as part of AI Threat Defense with Wiz

Limitations

  • Public preview for a limited set of customers; access is through Google Cloud sales
  • Preview terms say it may be used only for limited testing and evaluation, not for commercial or production purposes
  • Requires a Google Cloud project with the Vertex AI API, IAM permissions, and application default credentials
  • You may analyze only code you own or are authorized to use, or open-source code under an OSI-approved license
  • Google says the built-in sandbox is weaker than a fully isolated virtual machine, and Windows sandboxing is experimental
  • Network access in the sandbox is all-or-nothing, so builds that fetch dependencies need pre-fetching or an open network
  • The Gemini Cyber model is restricted to Fairwind Program participants, and third-party model support was announced but not yet available
  • Session data, including code snippets, is retained for up to seven days unless deleted

Use cases

  • Scanning a service's source code and getting verified findings instead of a raw scanner list
  • Importing results from an existing SAST tool and having CodeMender confirm and patch them
  • Generating a tested patch for a confirmed vulnerability and reviewing the diff before committing
  • Running delta scans on pull requests and failing CI on high-severity findings
  • Connecting code-level remediation to cloud risk findings through AI Threat Defense and Wiz

Our take

CodeMender is aimed at the part of security work that usually stalls: turning a finding into a fix someone trusts. Verifying findings and testing patches against your build before proposing them is the right design, and the local-first CLI addresses code-privacy concerns. For now it is a preview for select Google Cloud customers, not something most teams can adopt for production, so treat it as one to evaluate rather than standardize on.

Who should use it

Google Cloud customers with security or platform teams who want to evaluate an agent that verifies vulnerabilities and drafts tested patches, and who can accept preview terms.

Who should skip it

Teams that need a production-ready, generally available tool today, organizations not on Google Cloud, and small teams looking for a free or self-serve option.

Strengths

  • Verifies findings and tests patches before proposing them
  • Local-first CLI sends only targeted snippets, with no training on customer code
  • Imports findings from other scanners
  • Token-based pricing at the underlying Gemini model's rate
  • Backed by Google DeepMind research and Google Cloud enterprise controls

Weaknesses

  • Preview only, for select customers, and not for production use yet
  • Tied to Google Cloud and Gemini models for now
  • Setup requires Google Cloud project, IAM, and CLI configuration
  • Sandbox is weaker than full VM isolation

CodeMender pricing

Usage-based (Gemini 3.8 Flash)

$1.50 / $7.50 per 1M input / output tokens

  • Introductory $0.75 / $3.75 through December 31, 2026
  • Billed through Google Cloud

Usage-based (Gemini 3.1 Pro)

$2.00 / $12.00 per 1M input / output tokens

  • Higher-capability model option

Note: Google states CodeMender pricing is token-based and determined by the model used; no separate seat fee is published. Access during preview is through Google Cloud sales.

Technical specs

Available models

Gemini 3.8 Flash (default)Gemini 3.7 FlashGemini 3.6 FlashGemini 3.5 FlashGemini 3.1 Pro PreviewGemini 3.8 Flash Cyber (Fairwind Program only)

Where CodeMender excels

Reducing scanner backlog

Importing findings from existing tools and verifying them helps separate real issues from false positives before engineers spend time on fixes.

Drafting tested security patches

Patches are built and run against unit tests before review, so developers start from a candidate fix rather than a bare report.

PR-level security gating

Delta scans on pull requests and a CI failure threshold catch new issues without rescanning the whole codebase.

CodeMender vs. competitors

CodeMender vs. Strix

Strix is open-source software that tests running applications and APIs and has its own cloud platform; CodeMender is a managed Google Cloud agent centered on verifying and patching vulnerabilities in source code.

CodeMender vs. Shannon

Shannon is a free, self-hosted white-box pentester that tests a running web app; CodeMender works on source code across many languages and focuses on producing tested patches for review.

Frequently asked questions

What is CodeMender?

CodeMender is an AI code-security agent from Google Cloud, originally developed by Google DeepMind. It finds vulnerabilities in a codebase, verifies them in a sandbox, and generates tested patches that developers review before committing.

Is CodeMender generally available?

No. CodeMender is in public preview for a limited set of customers under Google's Pre-GA terms, and access is through Google Cloud sales. The preview terms say it is for limited testing and evaluation, not commercial or production use.

How much does CodeMender cost?

Pricing is token-based and matches the Gemini model you use. For example, Gemini 3.8 Flash is listed at $1.50 per million input tokens and $7.50 per million output tokens, with introductory pricing of $0.75 and $3.75 through December 31, 2026. Usage appears in Cloud Billing.

Which languages does CodeMender support?

By default it covers C/C++, C#/.NET, Go, Java, JavaScript and TypeScript, Kotlin, Python, Ruby, Rust, and PHP, and other languages can be added in configuration. Google notes it does not publish per-language evaluations.

Does CodeMender change my code automatically?

No. It applies patches only after you approve each file write, and it does not push code to your version control system.

Integrations & fit

Google CloudGemini Enterprise Agent PlatformVertex AIAI Threat DefenseWizCloud BillingSARIF
Good fit forEnterprise
Pricing modelPaid· Paid subscription required
See pricing on CodeMender →

Alternatives to consider

About CodeMender

CodeMender splits work between a hosted multi-agent system and a local `cm` CLI that also acts as a daemon on your machine. You run `cm find` on a path to scan for vulnerabilities, or import findings from other scanners; `cm verify` builds the code and checks whether a finding is real inside a local process-level sandbox; and `cm fix` generates a patch, applies it to a copy of the code, runs your build and unit tests, and re-checks the finding before asking you to approve each file write. Full repositories are not uploaded; the CLI sends targeted snippets and tool results, and Google says customer source code is not used to train models. Findings and patches are exported as HTML, Markdown, JSON, or SARIF, and recent CLI releases added pull-request delta scans and a CI gate. You access it through Gemini Enterprise Agent Platform with generally available Gemini models (Gemini 3.8 Flash by default), or as part of Google's AI Threat Defense alongside Wiz; a specialized Gemini 3.8 Flash Cyber model is limited to organizations approved for Google's Fairwind Program. Billing is token-based at the price of the chosen model. The tradeoffs: it is pre-GA, available only through sales to select customers and not licensed for commercial or production use during preview, it requires a Google Cloud project, and the built-in sandbox is weaker than a fully isolated VM.

Updates from CodeMender

New FeatureCodeMender adds C#, Kotlin, PHP, Ruby, and Rust to default languages

A September CLI release expanded the default language set to C/C++, C#/.NET, Go, Java, JavaScript and TypeScript, Kotlin, Python, Ruby, Rust, and PHP.

New FeatureGemini 3.8 Flash becomes the default model

CodeMender switched its default model to Gemini 3.8 Flash, and Gemini 3.8 Flash Cyber became available to allowlisted Fairwind Program customers.

LaunchCodeMender launches in public preview on Google Cloud

Google Cloud made CodeMender available in public preview for select customers through Gemini Enterprise Agent Platform and as a component of AI Threat Defense.

Are you the founder? Claim this listing →