The news
OpenAI launched Codex Security Cloud at its DevDay developer conference on Tuesday, September 29, adding a service that scans GitHub code for security flaws and prepares fixes in the cloud, even when a developer's laptop is closed. It is aimed at security teams.
The tool can scan an entire repository on demand or on a schedule, and keep checking new commits as they arrive, TechCrunch and The Decoder reported. Codex then investigates what it finds, removes duplicate alerts and prepares fixes. OpenAI's documentation describes the steps: Codex builds a threat model of the project, ranks likely issues, tries to reproduce each one in a temporary, isolated container to cut false positives, and returns findings with a severity rating, evidence and remediation guidance.
OpenAI's documentation is explicit that the system does not patch code on its own. When a finding has a proposed fix, a person reviews it before selecting Create draft pull request, and the tool does not directly modify an existing pull request branch. The same documentation says Codex Security does not replace manual security review, and that it complements rather than replaces static application security testing (SAST), the rule-based scanners many companies already run.
Codex Security Cloud also opens up OpenAI's Daybreak Blue models without a separate Daybreak application, according to TechCrunch and The Decoder. OpenAI describes Daybreak Blue as flagship models with reduced refusals for authorized defensive security work, such as vulnerability discovery, secure code review and patch validation. The Decoder reported that access previously required identity verification, among other steps.
The Decoder reported that Codex Security Cloud is available on ChatGPT Pro, Business, Enterprise and Edu plans on desktop and web. OpenAI's documentation labels it a research preview. None of the sources reviewed disclosed pricing. The Decoder also noted that OpenAI released the open-source Codex Security CLI, a command-line scanner that can run in build pipelines, in July.
The security tool arrived alongside other Codex updates. Codex now offers reusable cloud environments that give teams a shared, pre-configured workspace; SiliconANGLE reported that a task's state can be recovered for up to seven days after last use, and that cloud environments do not yet support GitLab or self-hosted GitHub Enterprise Server. OpenAI also added voice control to the Codex command-line tool and a code review view in the ChatGPT desktop app that can run automatic first-pass reviews.
The numbers
- Launch
- September 29, 2026, at OpenAI DevDay
- Plans with access, per The Decoder
- Pro, Business, Enterprise, Edu
- Scan modes
- Whole repository, or monitoring of new commits
- Cloud task state kept after last use, per SiliconANGLE
- Up to 7 days
Why CEOs should care
For CTOs and engineering leaders, the question is ownership. A machine-proposed patch still needs a named reviewer, passing tests and the same approval path as human code. Before connecting repositories, decide who triages findings, who signs off on fixes and how AI-drafted pull requests are labeled so you can track how many are merged, reworked or reverted. Ask OpenAI or your account team how many findings are validated versus merely suspected, and what the false-positive rate looks like on code similar to yours.
CISOs should look at access as much as accuracy. Including Daybreak Blue by default means more people in a workspace may reach models built with fewer refusals for security tasks. OpenAI's own guidance says those models should be used only on systems you own or are authorized to assess, with least-privilege permissions and human oversight. Check which users and repositories are enabled, what permissions the GitHub connection grants, and how long cloned code and findings are retained.
CFOs and boards should treat this as an addition to existing application security spending, not a replacement. OpenAI says the tool does not replace SAST or manual review. Useful measures are time to fix critical vulnerabilities and backlog size before and after rollout, rather than the number of alerts produced.
The bigger picture
Security fixes written by machines are moving from demos into the tools engineers use every day. OpenAI is pairing scanning with its Daybreak cyber program and with cloud agents that keep working when no one is at a keyboard. The design choice to stop at a draft pull request keeps a person accountable for what ships. How well that gate holds up will depend on reviewers who have time to read patches closely rather than approve them in bulk.
What’s next
Watch for pricing, a move out of research preview, support for GitLab and self-hosted GitHub, and any data OpenAI publishes on validated findings and accepted fixes. Companies piloting the tool can start with a few non-critical repositories, compare its findings with their current scanners and write review rules before expanding.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








