Codex Security is a research preview available for ChatGPT Enterprise, Edu, Business, and Pro users. It helps teams identify, validate, and remediate vulnerabilities in code. It is designed to work more like a security researcher than a traditional scanner: it reads code, runs tests, explores realistic attack paths, and proposes patches that teams can review in their normal workflow.
Overview
Codex Security connects to GitHub repositories and builds a threat model tailored to your codebase. You can scan a full repository or scan commits. Codex Security investigates potential vulnerabilities, attempts to validate them in an isolated environment, and proposes fixes for your team to review.
How Codex Security works
Codex Security uses a threat model to guide its analysis. The model describes attacker entry points, trust boundaries, sensitive data, and important code paths. You can inspect and edit it to reflect how your application is deployed. Full-repository scans assess the codebase, while commit scans examine repository changes.
Run a scan
Choose a full-repository scan or a commit scan and allow the scan to finish. Codex Security uses the repository’s threat model to investigate potential vulnerabilities.
Paid usage
Codex Security Cloud uses token-based billing. Existing customers receive notice and must opt in before paid usage begins.
If funding is unavailable for scans, scanning pauses. Review the billing notice and available funding before continuing paid scanning.
Daybreak Blue access
Daybreak Blue access included with Codex Security Cloud applies within the Cloud product. It does not grant access to Daybreak Blue in other Codex Security products or through the API.
Get started
Go to Codex Security.
Connect and enable the GitHub repositories you want Codex Security to scan.
Wait for the initial scan to finish. Codex Security first builds a threat model for the project and scans repository history for existing vulnerabilities. This can take longer for large projects. Scans of new code are faster.
Review findings, validation details, and proposed patches.
Role-based access controls (RBAC)
For Enterprise and Edu workspaces, admins can manage Codex Security access in workspace permissions. Codex Security requires both Codex Cloud and Codex Security access to be enabled for the workspace. Access can also be limited to specific roles or groups through RBAC, including SCIM-synced groups. To let members manage Codex Security scan configurations, also enable the Codex Security admin permission for the appropriate role or group.
To update your workspace’s permissions:
In ChatGPT, select your profile icon, then select Workspace Settings > Permissions to open workspace permissions.
Scroll down to Codex Cloud.
Make sure Codex Cloud access is enabled.
Enable or disable access by toggling Allow members to use Codex Security.
If the role or group should manage scan configurations, also enable Allow members to administer Codex Security.
Learn more about role-based access controls in your ChatGPT workspace.
Best practices
Start with a small set of repositories and a dedicated group of reviewers. We recommend a focused rollout at first, especially while onboarding and vulnerability sharing are still relatively manual.
Refine the threat model as you learn. Small updates to the model can improve context and make findings more precise over time.
If you do not use GitHub Cloud today, consider starting with lower-risk or non-production repositories for evaluation. That can help teams build confidence in the workflow before wider adoption.
Review generated patch PRs with your normal review process. We also recommend using Codex Code Review on Codex Security PRs so remediation does not introduce regressions.
FAQ
Does Codex Security automatically change my code?
No. Codex Security proposes a patch for human review. That proposal can be turned into a pull request, but it does not automatically modify your code.
Does Codex Security rely on fuzzing or signature-based scanning?
No. Codex Security is using language-model reasoning, test-time compute, tool use, and large context, rather than fuzzing or signature-based scanning.
Can I inspect or edit the threat model?
Yes. The threat model is visible and editable, so teams can inspect how Codex Security understands the application and update assumptions to match their environment.
What does validation mean?
Validation is the step where Codex Security tries to reproduce a potential vulnerability in an isolated environment before surfacing it. This is meant to reduce false positives and keep findings high-signal.
What happens after a finding is validated?
After validation, Codex Security proposes a patch that addresses the root cause and can be turned into a pull request for review.
