Loading market data...

Sherlock Launches Audit Engine to Coordinate AI Security Scans

Sherlock Launches Audit Engine to Coordinate AI Security Scans

Sherlock has publicly launched Sherlock Audit Engine, a platform that coordinates multiple AI-driven approaches to vulnerability discovery in a single security review. The engine combines frontier LLMs, purpose-built AI auditors, and AI-enabled security researchers, with Sherlock handling orchestration, validation, and deduplication of findings.

A proving ground on Polygon

In June, Sherlock tested the Audit Engine on Polygon's Heimdall V2 consensus client. That test appears to have served as an early proving ground for the platform. The results showed that no single AI system or researcher captured the full security picture, reinforcing the need for a multi-approach orchestration model.

That outcome wasn't a surprise to Sherlock. The whole point of the engine is to avoid relying on one tool or one researcher's eye. Instead, it pulls together several distinct AI systems and human researchers, then merges their findings into a single review.

Measuring what each approach adds

The Audit Engine measures differences in coverage and precision across various AI systems and researchers. That lets teams see which approaches contribute complementary security signal. Sherlock handles the orchestration, validation, and deduplication of findings, so the output is a consolidated view rather than a stack of overlapping reports.

The platform is built to incorporate new models, auditors, and researcher methodologies as they emerge. It provides a consistent environment for measuring performance against code, which means teams can compare how different AI tools perform on the same codebase.

The broader AI security shift

In July, Google DeepMind introduced Gemini 3.5 Flash Cyber, a cybersecurity-specific AI model designed to find, validate, and patch vulnerabilities. That release highlights rapid development in specialized AI security. The Audit Engine is designed to incorporate new models like this as they appear, giving teams a way to test them against existing approaches.

The engine is now publicly available. It hasn't yet been tested against Gemini 3.5 Flash Cyber, but its design allows for that integration. The question now is how quickly new models will be folded into the platform and whether they'll meaningfully improve coverage beyond what the Polygon test showed.