Cycode extends ADLC Security to developer workstations
1st article in the last 90 days, one of 4 articles referencing Cycode. Previous coverage: Cycode named a Leader in Gartner’s 2026 Magic Quadrant for Software Supply Chain Security (Jun 2026).
Companies mentioned
Best suited for
- Seniority
- C Level / Executive Team
- Job function
- Chief Information Security Officer
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Adopters
- Technology maturity
- Market Correction
- Industry
- Information Technology / Software & Services / Cybersecurity / Application Security & DevSecOps (SAST/DAST/SCA/Supply Chain)
Our classification, not the publisher's statement. Best suited for, not only for.
Cycode said it extended its ADLC Security capabilities with Workstation Protection, a feature for developer workstations. The change targets the point where malicious packages are installed during the agentic development lifecycle.
The company described the move in the context of increasing software supply chain attack activity that installs malicious packages on workstations. Cycode said it focused on scenarios where agents and developers install packages before security checks run, and where risk can enter the agentic development lifecycle.
Workstation Protection was described as part of Cycode ADLC Protection, which intercepts package installs in real time and evaluates packages before they reach the machine. Cycode said it applies two controls: enforcing cooldown policies through release-age gating, and blocking known-malicious packages by checking installs against a continuously updated threat intelligence feed.
Cycode said Workstation Protection deploys through Mobile Device Management and adds no console or infrastructure while changing nothing about how developers install packages. Seth Robbins, President of Cycode, said, “Risk enters the agentic development lifecycle (ADLC) for our customers before a single line of code is generated. Developers connect AI tools nobody approved, agents install packages nobody reviewed, and secrets leak into prompts and file reads nobody sees,” and, “ This launch extends Cycode’s platform to the workstation, the earliest control point in the software supply chain where malicious packages are installed and must be stopped.”
Cycode added that Security teams define and manage cooldown policies centrally and that the protection works for every developer workstation running a coding agent as quickly as software can be pushed to it. Dor Atias, Co-Founder and Chief Product and Engineering Officer at Cycode, said, “Security has to start where risk enters the development lifecycle, not after,” and, “Blocking malicious packages is the earliest control point in a complete agentic development and software supply chain security solution. Protect every workstation. Control every input. Secure every output. That is what unlocks secure AI development.” The company said Cycode ADLC with Workstation Protection is available in early access.
Press release, provided by Globe Newswire on behalf of Cycode. Read the original.