CodeMender no longer needs the rest of the platform around it. Google Cloud put the agent into preview on July 21, reachable through Gemini Enterprise Agent Platform, two months after it launched wrapped inside AI Threat Defense alongside the cloud security firm Wiz and Mandiant's threat intelligence (Google Cloud, 2026).
The Bundle Comes Apart
In May, Google positioned CodeMender only as a piece of a larger architecture, alongside Wiz's exposure mapping and Mandiant's frontline intelligence. That framing suited the goal at the time, which was proving that reasoning models, cloud context, and threat data could work as one system. It also meant a customer who wanted the remediation loop had to buy the whole architecture to get it.
That requirement is gone.
Preview access now runs through Gemini Enterprise Agent Platform, where CodeMender operates without the Wiz Security Graph enrichment or the Mandiant feeds that framed the May launch. Customers select the model themselves, weighing cost against how deep a scan needs to run (Google Cloud, 2026). Third-party frontier models join the option list later this year, without a named date.
Two Tiers, Not One
Generally available Gemini models come with the standalone preview. A separate tier does not. CodeMender running on Gemini 3.5 Flash Cyber stays reserved for a small set of governments and trusted partners, and Google says it will expand that circle over time (Google Cloud, 2026). It has not said on what schedule, or what qualifies an organization to join the list.
Neither detail is trivial for a security buyer comparing scanning depth across model tiers before a procurement decision.
The Track Record Predates the Preview
Google DeepMind's original research release, published in October 2025, put a number on CodeMender's early output: 72 security patches submitted to open source projects over six months, in codebases as large as 4.5 million lines of code (Google DeepMind, 2025). That evidence predates this week's preview by nine months. The business model changed on July 21. The research behind it did not.
Three named enterprise customers backed the standalone launch. Salesforce's chief information security officer, Iain Mulholland, credited the tool with accelerating validated fixes. Robinhood's head of security operations, Scott Ponte, said it caught risks other AI-enabled tools missed. Palo Alto Networks' Ashwin Kannan called it genuinely ambitious about closing the loop from detection to fix (Google Cloud, 2026).
What Standalone Access Commits You To
Unbundling from AI Threat Defense does not mean unbundling from Google. Reaching CodeMender still requires standing up Gemini Enterprise Agent Platform, and Google's own post notes that Wiz will soon call CodeMender to scan code inside AI Threat Defense (Google Cloud, 2026). A buyer who adopts the standalone product to avoid the full security platform is still adopting the platform underneath it.
Salesforce, Robinhood, and Palo Alto Networks already answered whether CodeMender finds real vulnerabilities. The open question for a security team weighing this against a multi-vendor scanning setup is whether preview adoption on Agent Platform becomes the reference account a sales team cites when the AI Threat Defense conversation starts.
Gerstenhaber, Michael, and Clemens Viernickel. "Now in Preview: Find and Fix Software Vulnerabilities with CodeMender." Google Cloud Blog, 21 July 2026. cloud.google.com
Popa, Raluca Ada, and Fionn Flynn. "Introducing CodeMender: An AI Agent for Code Security." Google DeepMind Blog, 2025. deepmind.google
