tools
Wiz Code
Wiz Code secures source code, CI/CD pipelines, and cloud deployments with scanning, prioritization, and code-based remediation.

Wiz Code is a cloud security product for application security, development, DevOps, and platform teams. It connects code, repositories, CI/CD systems, and cloud environments to identify vulnerabilities and prioritize issues using runtime and reachability context.
It scans dependencies, infrastructure as code, secrets, sensitive data, malware, and CI/CD configurations. Developers can receive findings in IDEs, pull requests, CI/CD workflows, Slack, and GitHub. Pricing is quote-based, and the product is not presented as a general-purpose code editor or coding assistant.
Features
- Scans direct and transitive dependencies and provides SCA and SBOM visibility
- Scans Terraform, CloudFormation, Azure Resource Manager, Kubernetes, and Docker IaC
- Finds hardcoded secrets in code, IaC templates, and container images
- Identifies and classifies sensitive data such as PHI and PII in code
- Detects malware before it reaches CI runners and cloud environments
- Hardens VCS and CI/CD systems against misconfigurations and insecure defaults
- Correlates code risks with cloud impact and suggests one-click fixes in source code
- Supports GitHub scanning, Slack integration, MCP Server, and IDE scanning
Use cases
- Scan repositories and pull requests for vulnerabilities, secrets, and IaC misconfigurations
- Prioritize code issues using reachability and runtime context
- Trace cloud risks back to the source code that created them
- Enforce security policies in CI/CD pipelines before deployment
- Give developers security findings and remediation guidance in their IDE
- Inventory and secure AI-driven development workflows