Tenable has announced the expansion of its Tenable One Exposure Management Platform to unify application security risk data with other forms of enterprise exposure data. By integrating static code vulnerability data, the platform is designed to provide visibility across the attack surface, from code to runtime.
According to Tenable, security teams have struggled with vulnerable code reaching production faster than it can be reviewed, a problem the company said is compounded by generative AI, which can help developers ship code three to four times faster while potentially introducing flaws at a higher rate. Application security teams and developers have typically relied on siloed tools that lack the infrastructure context needed to determine whether a code vulnerability represents a genuine risk, an approach Tenable said creates an exploitable blind spot.
Tenable One Exposure Management Platform Unifies Code And Runtime Risk

With this expansion, Tenable One ingests, analyzes, and normalizes data from application development and security sources, including AI-powered application security tools such as Claude Security. The platform connects all ingested exposure data, unifying Tenable telemetry with inputs from endpoint protection, cloud security, vulnerability management, operational technology security, and configuration management databases.
The result is designed to give organizations a consolidated view of enterprise risk, accelerating remediation prioritization. Rather than reacting to individual application scans, security teams can now see code flaws in the context of the runtime systems, cloud workloads, identities, and attack paths those flaws put at risk.
According to Eric Doerr, Chief Product Officer at Tenable, the expansion addresses a long-standing gap in context. He noted that security teams no longer need to work through large volumes of vulnerabilities in isolation. Instead, Tenable One surfaces exposure the moment it is created, whether through an agentic AI tool identifying a zero-day in an open-source library or a human error introducing risk into a codebase.
Application security data integrations are now available to all existing Tenable One customers.
Pokdepinion: Developers are shipping code faster than ever thanks to AI, which apparently also means shipping vulnerabilities faster than ever, so it is reassuring that at least one platform is trying to keep score of the mess in real time.

