...

As AI Risk Expands and Vulnerabilities Compound, Evo by Snyk Reaches 60% of New Deal Volume

Snyk

Snyk today announced that Evo by Snyk accounts for 60% of new deal volume. This agent-native layer drives a 30% increase in average contract value. Furthermore, Snyk has sustained an 81.5% month-over-month growth rate for Evo since March 2026. Enterprises are moving AI security rapidly into production.

Modern enterprises uncover more security risks than developers can resolve. Newly introduced issues grew 108% across Snyk’s 4,800 customers. Coding agents expand this gap significantly today. They pull in unvetted MCP servers and execute actions without human approval. Consequently, traditional security tools fail to keep pace with these fast runtime changes.

“Vulnerabilities are compounding faster than teams can clear them, and on top of that, agents add a whole new layer of exposure,” said Ken MacAskill, chief executive officer of Snyk. “We are in exactly the right place at the right time. We built Evo long before enterprises knew to ask for it, because the answer was never more AI grading its own homework it has to be independent validation. Not only is Evo growing rapidly, but more than three-quarters of enterprises who bought Evo deployed it in production within the same quarter. It is clear evidence that enterprises are urgently implementing solutions to address growing agentic AI security risks.”

Scaling AI Security Operations Across Enterprise Workflows

Snyk processes 2.4 million agent supply-chain scans each month. Additionally, Snyk handles 4.2 million agent behavior checks daily across 417,000 machines.

Typical enterprise software requires multiple quarters to deploy fully. However, 76% of Q2 customers deployed Evo within the same quarter. The software installs smoothly into existing workflows. For instance, a major US bank centralizes 1,000 internal agent skills for 50,000 developers. Snyk runs continuous risk assessments across this entire registry.

“The sequence is predictable,” said Manoj Nair, Snyk’s chief technology officer. “An enterprise introduces coding agents. Then it ships its own AI applications. Then it finds that attackers are probing both at machine speed, chaining the low-severity issues the old model told teams to ignore. Each step adds a surface the previous generation of tooling was never built to see. Evo covers the development loop, the production loop and the adversarial loop, because a loop with a missing segment is not a loop. It is a gap an autonomous attacker will occupy.”

Independent Validation Layer Closes Critical Security Gaps

Snyk builds its architecture on independent validation. Code generators should not validate their own output safety. Open-source fixes via Snyk merge at a 94% higher rate. Snyk places a deterministic security layer right beneath the AI model. Furthermore, Snyk works across multiple leading model providers seamlessly.

“Security teams do not need another system that simply adds findings to an already unmanageable backlog,” said Nair. “They need a trusted way to turn those findings into fixes and to govern the AI agents increasingly responsible for building and operating software. Evo combines AI-driven action with the application context and deterministic validation required to deliver outcomes enterprises can trust.”

“We’re seeing supply-chain attacks, malicious skills and compromised MCP servers enter through the agent’s own toolchain, alongside agents taking actions with no guardrails between intent and execution,” said Brendan Putek, director of DevOps at Relay Network, a provider of secure customer engagement technology for regulated industries. “Working with Snyk, we landed on what I believe is the right architecture for agentic development security: controls embedded directly into the agent workflow that govern what an agent uses, executes and generates.”

Unified Protection Across Three Enterprise AI Challenges

Evo solves three primary AI risks through one platform. First, Evo Agentic AppSec addresses the security backlog directly. Secrets Detection identifies exposed credentials instantly. Meanwhile, the Remediation Agent fixes issues automatically.

Second, Evo Agentic Development Security governs developer coding tools. It validates external tools before agents execute code. Third, Evo AI-SPM delivers a live inventory of models and applications. Finally, Evo Continuous Offensive Security tests these guardrails against active adversarial attacks.

For related updates on digital trust and cybersecurity, explore our SOC News.

News Source: Businesswire