Skip to content
TECH CEO Daily
AILaunch

OpenAI's Codex Security Cloud hunts code flaws and drafts fixes while laptops are shut

Launched at DevDay on September 29, the service scans GitHub repositories, validates likely bugs and proposes patches that a person must review before a pull request.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Codex Security Cloud scans GitHub repositories on demand, on a schedule or as commits land, then prepares proposed fixes.
  • 2OpenAI's documentation says it never auto-applies patches; a person reviews each one before a draft pull request.
  • 3Users get OpenAI's Daybreak Blue cyber models without a separate application, so admins should check who has access.

The news

OpenAI launched Codex Security Cloud at its DevDay developer conference on Tuesday, September 29, adding a service that scans GitHub code for security flaws and prepares fixes in the cloud, even when a developer's laptop is closed. It is aimed at security teams.

The tool can scan an entire repository on demand or on a schedule, and keep checking new commits as they arrive, TechCrunch and The Decoder reported. Codex then investigates what it finds, removes duplicate alerts and prepares fixes. OpenAI's documentation describes the steps: Codex builds a threat model of the project, ranks likely issues, tries to reproduce each one in a temporary, isolated container to cut false positives, and returns findings with a severity rating, evidence and remediation guidance.

OpenAI's documentation is explicit that the system does not patch code on its own. When a finding has a proposed fix, a person reviews it before selecting Create draft pull request, and the tool does not directly modify an existing pull request branch. The same documentation says Codex Security does not replace manual security review, and that it complements rather than replaces static application security testing (SAST), the rule-based scanners many companies already run.

Codex Security Cloud also opens up OpenAI's Daybreak Blue models without a separate Daybreak application, according to TechCrunch and The Decoder. OpenAI describes Daybreak Blue as flagship models with reduced refusals for authorized defensive security work, such as vulnerability discovery, secure code review and patch validation. The Decoder reported that access previously required identity verification, among other steps.

The Decoder reported that Codex Security Cloud is available on ChatGPT Pro, Business, Enterprise and Edu plans on desktop and web. OpenAI's documentation labels it a research preview. None of the sources reviewed disclosed pricing. The Decoder also noted that OpenAI released the open-source Codex Security CLI, a command-line scanner that can run in build pipelines, in July.

The security tool arrived alongside other Codex updates. Codex now offers reusable cloud environments that give teams a shared, pre-configured workspace; SiliconANGLE reported that a task's state can be recovered for up to seven days after last use, and that cloud environments do not yet support GitLab or self-hosted GitHub Enterprise Server. OpenAI also added voice control to the Codex command-line tool and a code review view in the ChatGPT desktop app that can run automatic first-pass reviews.

The numbers

Launch
September 29, 2026, at OpenAI DevDay
Plans with access, per The Decoder
Pro, Business, Enterprise, Edu
Scan modes
Whole repository, or monitoring of new commits
Cloud task state kept after last use, per SiliconANGLE
Up to 7 days

Why CEOs should care

For CTOs and engineering leaders, the question is ownership. A machine-proposed patch still needs a named reviewer, passing tests and the same approval path as human code. Before connecting repositories, decide who triages findings, who signs off on fixes and how AI-drafted pull requests are labeled so you can track how many are merged, reworked or reverted. Ask OpenAI or your account team how many findings are validated versus merely suspected, and what the false-positive rate looks like on code similar to yours.

CISOs should look at access as much as accuracy. Including Daybreak Blue by default means more people in a workspace may reach models built with fewer refusals for security tasks. OpenAI's own guidance says those models should be used only on systems you own or are authorized to assess, with least-privilege permissions and human oversight. Check which users and repositories are enabled, what permissions the GitHub connection grants, and how long cloned code and findings are retained.

CFOs and boards should treat this as an addition to existing application security spending, not a replacement. OpenAI says the tool does not replace SAST or manual review. Useful measures are time to fix critical vulnerabilities and backlog size before and after rollout, rather than the number of alerts produced.

The bigger picture

Security fixes written by machines are moving from demos into the tools engineers use every day. OpenAI is pairing scanning with its Daybreak cyber program and with cloud agents that keep working when no one is at a keyboard. The design choice to stop at a draft pull request keeps a person accountable for what ships. How well that gate holds up will depend on reviewers who have time to read patches closely rather than approve them in bulk.

What’s next

Watch for pricing, a move out of research preview, support for GitLab and self-hosted GitHub, and any data OpenAI publishes on validated findings and accepted fixes. Companies piloting the tool can start with a few non-critical repositories, compare its findings with their current scanners and write review rules before expanding.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

OpenAICodexDevDayCybersecuritySoftware development

Earlier coverage of OpenAI

All OpenAI coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.