AI Trust Index
What's New:
The AI Trust Index is a publicly available benchmark that scores 16 large language models on the security of the code they produce, broken down by programming language and vulnerability type. The index is backed by SCW and RMIT research methodology. In-product, Trust Agent: AI now displays an AI Trust Score column per model in the dashboard, and the policy page surfaces the most and least secure models per language to support governance decisions.
Key Benefits:
- Answer "which large language models should we allow?" with evidence rather than opinion — scores are based on real code security analysis, not vendor claims
- The Trust Agent: AI dashboard and policy page now show model-level trust scores in context, alongside existing usage and compliance data
- Deep-linkable model and language views on the public microsite make it easy to share findings with stakeholders
How to Access:
The public microsite is live at aitrustindex.securecodewarrior.com. In-product trust scores are available now for Trust Agent: AI customers.
Improved Language Mode Selection
What's New:
The two language mode options in the platform have been renamed to make it easier for learners to choose the right one. "Secure coding" is now labelled "I write or review code" and "Security Awareness" is now labelled "I don't work directly with code." The updated wording appears both when a learner selects their language mode for the first time and when they switch it later.
Key Benefits:
- Learners can immediately identify which mode applies to them without needing to understand product terminology
- Fewer incorrect mode selections means learners start with content better matched to their role
- The clearer labels apply at both initial setup and later when changing preferences
How to Access:
The updated labels appear automatically in the language mode selector. No admin action is required.
Trust Agent: AI — Onboarding and Upsell Experience
What's New:
Navigating to Trust Agent: AI no longer leads to an empty screen if the feature is not yet configured. All customers now land on a redesigned page with an overview of what Trust Agent: AI provides and an interactive dashboard preview using sample data, so the value is visible before any setup takes place. Enterprise customers who are entitled but not yet configured are guided through activation; Business and Legacy customers are directed to learn more or book a demonstration.
Key Benefits:
- Enterprise customers can see what Trust Agent: AI reveals before committing to setup, lowering the barrier to activation
- The in-page activation path — from token generation through endpoint installation — reduces the steps needed to get data flowing into the dashboard
- Every customer sees a cohort-appropriate experience rather than a blank screen
How to Access:
Available now for all customers. Navigate to Trust Agent: AI in the main navigation to see the updated experience.
Manual SARIF File Upload for Vulnerability Data
What's New:
You can now upload SARIF files directly into Trust Agent to import vulnerability data from any security scanning tool, even those without a direct platform integration. SARIF (Static Analysis Results Interchange Format) is the industry-standard export format supported by most scanners. Once uploaded, the data populates the Vulnerability Report and feeds Adaptive Learning with Vulnerabilities, so identified gaps are automatically turned into targeted training assignments.
Key Benefits:
- Bring vulnerability data into the platform from any scanner that supports SARIF export, without waiting for a dedicated integration
- Uploaded data immediately populates the Vulnerability Report and triggers Adaptive Learning assignments where applicable
- Repository-level adaptive training is supported when the uploaded SARIF file includes version control provenance information
How to Access:
Available now for all customers. Go to Trust Agent > Vulnerabilities to upload a SARIF file.
New Vulnerability Connector: SonarQube Cloud
What's New:
Trust Agent now connects directly to SonarQube Cloud, so vulnerability data flows in automatically without requiring a manual export. Customers can authenticate using a personal access token or a scoped organisation token. Imported data populates the Vulnerability Report and feeds Adaptive Learning with Vulnerabilities alongside existing connector sources.
Key Benefits:
- Vulnerability data from SonarQube Cloud stays current automatically — no manual exports or uploads needed
- The connector sits alongside Fortify, Snyk, and GitHub Advanced Security in a single, unified setup location
- Imported findings flow directly into Adaptive Learning, turning scanner output into targeted developer training
How to Access:
Available now for all customers using SonarQube Cloud. Go to Trust Agent > Vulnerabilities to configure the connector. Note: this connector supports SonarQube Cloud only, not SonarQube Server (self-hosted).
Step-by-Step Quest Creation Flow
What's New:
The Quest creation page has been redesigned as a step-by-step stepper flow, replacing the previous single long scrolling form. A progress indicator across the top of the page shows where you are in the process, and you can jump to any step directly or move through using next and previous buttons.
Key Benefits:
- It is always clear how far through Quest creation you are and what remains to be configured
- Jumping directly to a specific step makes it faster to review or adjust a single setting without scrolling
- The structured flow reduces the chance of missing a configuration step before publishing
How to Access:
Available now for all customers. The updated flow appears automatically when creating a new Quest.
"Using AI Coding Agents" Content Collection
What's New:
A new collection of 14 conceptual topics covering the safe and effective use of artificial intelligence coding agents is now available on the platform. These topics replace the previous single "Coding with AI" topic, breaking the subject into smaller, focused pieces that can be assigned individually. Topics include Prompt Engineering, Context Engineering, MCP Servers, Sandboxing, Slopsquatting, Spec-Driven Development, and more, with several featuring new interactive walkthrough activities. The existing "Coding with AI" topic has been gracefully deprecated: it remains available to learners currently assigned to it but can no longer be added to new Quests.
Key Benefits:
- Admins can assign specific AI agent topics that match their organisation's current tools and priorities, rather than a single all-in-one module
- Most topics take under 30 minutes to complete, making them easier to fit into learner schedules
- New interactive walkthrough activities are included at launch, with more planned throughout the year
How to Access:
Available now for all customers. Find the topics in Quests under the Security Concepts objective ("Using AI Coding Agents" section), in Learn by filtering for "Using AI Coding Agents", in Explore as individual activities, and in Legacy Courses as the "Using AI Coding Agents" course.
AI Content Filters and "New Content" Toggle in Explore and Learn
What's New:
Explore and Learn now include a dedicated AI-related content filter section with three categories — AI-assisted development, Building AI Applications, and AI for Non-Developers — making it straightforward for learners to find content matched to how they work with artificial intelligence. A "Surface only new content" toggle and "New" badges on activity cards let learners quickly identify what has been recently added.
Key Benefits:
- Learners can navigate directly to AI content relevant to their role without browsing the full catalogue
- The "New Content" toggle surfaces only recently added activities, so engaged learners can easily keep up with what's arrived
- "New" badges on cards provide an at-a-glance signal of fresh content without requiring any additional navigation
How to Access:
Available now for all customers. The AI content filter section and "New Content" toggle appear in the filter panel in Explore and Learn.
Comments
0 comments
Please sign in to leave a comment.