What Codex Security does, and what a pull request security review adds
Codex Security is OpenAI's application security agent: it helps teams find, confirm and fix vulnerabilities, from the Codex app, a CLI and SDK, or Codex cloud for connected GitHub repositories.[1] It builds a threat model of the repository, ranks likely issues, then tries to reproduce each one in a clean container. It never applies a patch for you: you review it before creating a draft pull request.[2]
IonWarp's Security Review works on the pull request. The planner adds it when a change needs it, and its findings land on the pull request before merge. On 13 benchmark pull requests with 18 known security issues, DeepSeek v4.1 Flash, the model it runs, scored an F1 of 62.5% for about 6 cents a review, ahead of CodeRabbit (54.1%), Greptile (53.8%) and Cursor Bugbot (50.0%). The Qodo app scored 73.3%.[3]
IonWarp and Codex Security
OpenAI facts are from its Codex Security documentation, read on 2026-10-04; numbered notes link to each page.
IonWarp and Codex Security| Criterion | IonWarp | Codex Security |
|---|
| What it is | A security reviewer in a GitHub app; the planner adds it to the pull requests that need it | An application security agent that helps teams find, confirm and fix vulnerabilities[1] |
|---|
| What it reads | A pull request's changes and the code around them | A repository or a folder, a pull request or branch before merge, or the new commits it monitors[1][2] |
|---|
| What it returns | Findings on the pull request with a severity, the attack path, a suggested fix and an AI fix prompt | Ranked findings with criticality, validation evidence, remediation guidance and a proposed patch when one is available[2] |
|---|
| Changes to your code | None: the GitHub app reads code and never pushes | No patch is applied for you; you review it before creating a draft pull request[2] |
|---|
| Where it runs | IonWarp's hosted service | The Codex app, the open-source CLI and SDK, or Codex cloud for connected GitHub repositories[1][8] |
|---|