Skip to content

Plexicus

Plexicus is a European AI-native application security posture management platform that auto-generates fix pull requests for vulnerabilities across code, containers, and cloud configuration, aimed at reducing the remediation backlog that traditional AppSec scanning tools only identify but never fix.

Visit Website ↗ + Add to Compare
52/100Incremental Innovator

Overview

Plexicus positions its ASPM platform around remediation rather than detection alone: it identifies vulnerabilities across code, AI-generated code specifically, containers, and cloud configuration, then auto-generates pull requests with proposed fixes rather than leaving developers to interpret and patch scanner output manually. Its offering spans ASPM, software supply chain security, and AI-specific security scanning.

Built in Bilbao, Spain, Plexicus is SOC 2 Type II compliant, listed on the Microsoft Marketplace, and cites Telefónica and Deloitte among organizations referencing its platform.

Innovation Matrix Assessment

Innovation Velocity 6/10

Achieving SOC 2 Type II compliance, a Microsoft Marketplace listing, and named enterprise reference customers within a short window since founding indicates a fast early execution pace.

Operational Value 6/10

Auto-generating fix pull requests rather than leaving developers to manually interpret scanner findings directly addresses the remediation bottleneck that limits most AppSec programs' actual risk reduction.

Market Momentum 4/10

Named references from Telefónica and Deloitte suggest real enterprise interest, though no independently disclosed funding round or customer count was found to corroborate broader market traction.

Category Disruption 5/10

Explicitly targeting AI-generated code vulnerabilities as a distinct problem, combined with auto-fix pull requests rather than detect-only scanning, is a meaningfully different posture than legacy ASPM tools.

Real-World Efficacy 4/10

No independent, third-party benchmark of fix accuracy or false-positive rate was found; efficacy evidence is limited to vendor claims and customer name-drops rather than controlled testing.

Enduring Relevance 6/10

As AI-assisted code generation accelerates the volume of code entering production, remediation-focused ASPM addressing AI-introduced vulnerabilities specifically is likely to grow in importance.

Why CISOs Should Care

The gap between vulnerabilities found and vulnerabilities actually fixed is one of AppSec's most persistent operational failures; Plexicus targets that gap directly by shipping remediation as pull requests rather than just another dashboard of open findings.

What Makes It Different

Plexicus explicitly targets vulnerabilities introduced by AI-generated code as a distinct problem category, combining that with auto-remediation pull requests rather than the detect-only model most ASPM and cloud security scanners still use.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A young, Europe-based ASPM entrant with a sensible remediation-first thesis and real enterprise reference customers; scores reflect early-stage status with limited independently verifiable funding and efficacy data.

Editorial Note: Claims vs. Verified Findings

SOC 2 compliance, Microsoft Marketplace listing, and named reference customers are stated on the company's own site; specific funding amount and founding date are not independently confirmed beyond the company's own materials.

Sources