Tenable One adds application security data to exposure platform

Tenable has expanded its One platform to unify static code vulnerability data with runtime exposure, giving security teams code-to-production risk visibility.

A grey network switch with numerous active Ethernet and SFP ports displays glowing yellow and green status LEDs while mounted in a server rack with visible blue cabling.

Tenable Holdings has expanded its One Exposure Management Platform to incorporate application security data, bringing static code vulnerability analysis into a single view alongside cloud, identity, endpoint and operational technology risk. The NASDAQ-listed vendor says the update, available immediately to all Tenable One customers, is designed to close a long-standing gap between developer tooling and the infrastructure-level context needed to assess whether a code flaw represents a genuine business risk.

The integration ingests data from application development and security sources, including AI-assisted code security tools. Tenable One then normalises that data against its existing telemetry and third-party feeds from endpoint protection, cloud security and vulnerability management platforms, as well as configuration management databases. The result, according to the company, is a unified attack-surface view that connects a code flaw to the runtime systems, cloud workloads and identity paths it threatens.

The problem Tenable is targeting

Tenable cites a Cloud Security Alliance report from April 2026 which found that generative AI tooling enables developers to ship code three to four times faster, while potentially introducing vulnerabilities at ten times the rate. That dynamic means insecure code reaches production before application security teams can review it, creating what the company describes as an exploitable blind spot.

Eric Doerr, Chief Product Officer at Tenable, said the platform now gives customers "the context they've been missing." He added: "Security teams don't need to wade through a sea of vulnerabilities. With Tenable One, security teams know exactly where they are exposed the moment an exposure is created."

Market context and competitive positioning

Tenable operates in a maturing exposure management market that is consolidating around unified platforms. Competitors including Palo Alto Networks, Qualys and Rapid7 have each moved to integrate application security scanning with broader vulnerability and cloud posture management capabilities. The pressure to unify comes partly from enterprise buyers who have grown frustrated with the operational overhead of managing distinct AppSec, cloud security posture management and vulnerability management tools in parallel.

The specific challenge of AI-generated code risk is attracting increasing attention from the wider security community. Several startups are pursuing dedicated AI code security tooling, while established software composition analysis vendors are extending their scope to cover AI-generated dependencies. Tenable's approach of absorbing those signals into an exposure management layer, rather than competing directly at the scanning level, reflects a platform-over-point-tool strategy that its investor base will be watching for revenue impact.

Standards and regulatory read-across

Enterprise buyers in regulated sectors will note that unifying code and runtime risk data supports compliance workflows under frameworks including SOC 2, ISO 27001 and the NIST Cybersecurity Framework's Identify and Protect functions. The EU's NIS2 Directive, which extended mandatory incident reporting to a broader set of critical-sector organisations from late 2024, also increases the cost of undetected application-layer vulnerabilities for European customers.

Tenable did not disclose the number of integrations available at launch beyond naming Claude Security as one AI application security source, nor did it provide pricing details for the expanded capability. The company reports more than 40,000 customers globally. Analysts and investors will look for concrete customer adoption figures and evidence of uplift in average contract value as the next meaningful datapoints.