> For the complete documentation index, see [llms.txt](https://docs.xygeni.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.xygeni.io/changelog/version-6.11-june-24-2026.md).

# Version 6.11 - June 24, 2026

With version 6.11, Xygeni ships a **fully redesigned interface**, brings **AI Triage and AI Explanation to general availability across every scanner**, and adds a **native DAST engine**.

This release also lets you **run AI on your own LLM**, introduces a **credit-based model for AI usage**, and rolls out **incremental scanning across all analyzers,** making security **faster, more transparent, and entirely on your terms**.

#### **🎨 A Redesigned Xygeni Experience**

We rebuilt the Xygeni interface from the ground up: a **modern, cleaner look and feel** with a **major performance boost** across every view. The platform now feels noticeably faster from list to detail, and a consistent design runs end to end.

**What's New**

* A **modern, redesigned interface** with refreshed navigation and dashboards, organized around risk and action rather than raw scanner output.
* **Significantly faster performance** across the platform: lists, detail views, and filtering all respond noticeably quicker.
* **Settings relocated** to the gear icon in the top-right corner, for a cleaner and more familiar layout.
* **A new filtering model.** Instead of expanding a list of every available filter, you now build your view by adding the filters you need from the available set — and changes to the table apply **immediately**.
* **A redesigned Subscription section** that reports your platform consumption in greater detail, so usage is transparent at a glance.

**Key Benefits**

* **Faster time to decision.** The gain comes from raw performance. The same workflow, markedly quicker end to end.
* **A consistent experience across the platform.** The same clear, modern patterns in every module reduce cognitive load and make the product easier to learn and trust.
* **Transparency into consumption.** The new Subscription view makes platform usage clear and predictable.
* **Filtering that matches how you work.** Build exactly the view you need and see results apply on the spot.

<figure><img src="/files/jOJupMveTEXQdUPmVzNw" alt=""><figcaption></figcaption></figure>

#### **✅ AI Triage. Now Generally Available**

AI Triage now goes well beyond true/false positive. For every finding you triage, it assesses **three dimensions**: the **verdict** (true vs false positive), the **remediation urgency** (based on impact and exploitability) and the **remediation complexity**. And **you stay in control**: Triage doesn't run automatically on every finding. You decide what to apply it to, one finding at a time or in **bulk**.

**What Xygeni Does**

* Classifies each triaged finding across three axes:
  * **Verdict:** true positive vs false positive, to cut noise.
  * **Remediation urgency**, driven by impact and exploitability: **Immediate**, **ASAP**, **Planned**, **Backlog**.
  * **Remediation complexity**: **Automatic**, **Trivial**, **Medium**, **Hard**.
* **Gives you control over what gets triaged.** Apply it to a single finding or in bulk, on your terms.
* In our **ASPM**, applies to **your own Xygeni findings and to third-party findings ingested** from other scanners. The same intelligence, regardless of where the finding came from.
* **Pairs with AI Autofix**, available for **SAST, SCA, and Secrets.** From understanding the issue to fixing it, in one path.

**Key Benefits**

* **Plan what to remediate, not just what was found.** Urgency and complexity together tell you what to fix now, what to schedule, and what's a quick win versus a heavy lift.
* **Optimize how you spend resources.** Direct effort to the highest-impact, most-exploitable issues and sequence the rest deliberately.
* **One layer of intelligence across all your tools.** In ASPM, Xygeni's AI applies to your findings and to ingested third-party findings alike. No rip-and-replace required.

<figure><img src="/files/H4BniI5fuFADEj4dNzdG" alt=""><figcaption></figcaption></figure>

#### **💬 AI Explanation. Understand the Attack Path, End to End**

AI Explanation helps the developer **understand the attack path** of a finding — and act on it. It explains how the vulnerability works, **how to reproduce it, how to remediate it, and how to validate that it's resolved**. It reasons over the full **code flow**, tracing every source through to the sink rather than looking at the finding in isolation.

**What Xygeni Does**

* Explains the **attack vector** behind each finding in the context of your code.
* Walks the developer through **how to replicate, how to remediate, and how to confirm the fix**.
* Reasons over the **complete code flow** — all sources to the sink — so the explanation reflects the real path, not just the symptom.
* Once generated, the explanation is **reused across the ASPM context** to power remediation, triage, and related workflows.

**Key Benefits**

* **Developers fix with confidence.** Understanding the path from source to sink — and how to validate the fix — turns a finding into a clear course of action.
* **Faster, more reliable remediation.** Reproduce, fix, and verify without leaving the workflow or guessing at root cause.
* **One explanation, reused everywhere.** The same analysis feeds triage, remediation, and the broader ASPM context — no duplicated effort.

<figure><img src="/files/8YfPwFlhUIL1Ia9PhRYo" alt=""><figcaption></figcaption></figure>

#### **🔌 Bring Your Own LLM**

You can now connect **your own LLM** to power Xygeni's AI capabilities. Triage, Explanation, and remediation guidance run on the model you choose, and apply to both your native Xygeni findings and the third-party findings you ingest through ASPM.

**What Xygeni Does**

* Lets you configure your own LLM provider to drive Xygeni's AI features.
* Keeps the full AI capability set. Triage, Explanation, remediation guidance... intact regardless of which model you run.
* Applies that intelligence across native and ingested third-party findings.

**Key Benefits**

* **Control over data and model choice.** Run AI within your own boundaries and provider relationships.
* **No rip-and-replace.** Add Xygeni's AI layer on top of the scanners and findings you already have.
* **Flexibility as you scale.** Adapt the AI backend to your security, compliance, and cost requirements.

👉 Learn how to configure it in [AI Agents Configuration](/xygeni-products/scan-management/ai-agents-configuration.md)

#### **💳 A New Credit-Based Model for AI**

We're moving AI usage from a per-fix model to a **credit-based model**. This makes AI consumption transparent and predictable across all AI capabilities — not just fixes. **This doesn't change what you pay:** existing customers receive an equivalent set of credits. **Credits are only consumed when you use the Xygeni-hosted model**; if you bring your own LLM, you run on your own provider and your own terms.

**What Changes**

* AI usage is now metered in **credits**, replacing the previous count-of-fixes model.
* Credits cover AI capabilities broadly, giving a single, consistent unit for AI consumption.
* **No change to pricing.** Current customers are issued an equivalent set of credits.
* **Bring-your-own-LLM usage does not consume Xygeni credits.**

**Key Benefits**

* **Transparent, predictable AI usage.** One clear unit across all AI features.
* **No cost impact.** The move is a change in how usage is measured, not in what you pay.
* **Full control with your own model.** Run on your LLM with no credit consumption.

#### **🌐 Native DAST (xy-dast)**

Xygeni moves from **DAST ingestion to a native DAST engine, xy-dast**. Where v5.36 ingested results from external DAST tools, v6.11 runs dynamic analysis natively. A scanner that behaves like the rest of the toolchain: one command, CI/CD-native, and integrated into the platform.

**What Xygeni Does**

* **Runs entirely in your own infrastructure.** No need to expose anything to the internet — xy-dast reaches your applications from inside your environment.
* **Scales with unlimited parallel runs.** Launch as many concurrent scans as you need; throughput is yours to set.
* **One command, any app.** Docker-based, with sensible defaults and no Java or plugins to install; `xy-dast scan -u <url>` gets you to a scan in minutes.
* **Profiles, not wizards.** Built-in profiles for traditional web, SPA, OpenAPI, GraphQL, SOAP, Quick, and Deep, with auto-detection picking the right one. Custom profiles live in Git, next to your code.
* **CI/CD-native gating.** Fail builds on a severity threshold, get clean exit codes for gating, and quiet logs for sane CI output.
* **Operates in on-premise and air-gapped environments.**
* **Findings flow into ASPM**, correlated with SAST, SCA, Secrets, API Security, and supply-chain signals. One inbox for AppSec.

**Key Benefits**

* **No new attack surface.** Running inside your infrastructure means no inbound exposure and no firewall changes to scan.
* **Throughput on your terms.** Unlimited parallel scans keep dynamic testing from becoming a bottleneck as you add services.
* **Real-world exposure, confirmed.** Native DAST validates whether a vulnerability is actually reachable and exploitable at runtime.
* **One correlated view.** Static, dependency, runtime, and API findings prioritized together. Fewer blind spots, one source of truth.

<figure><img src="/files/YYLop6ECK6vjcNGYFXpb" alt=""><figcaption></figcaption></figure>

#### **🧑‍💻 AI Across Every IDE**

Security and AI now live inside the full IDE family. **AI Explanation** and **Code Flow** are available directly in the editor, with real-time scanning on save and expanded IDE coverage.

**What's New**

* **AI Explanation in the IDE:** code-aware explanations inline, next to the finding.
* **Code Flow:** visualize the path of a vulnerability from source to sink, directly in the editor, so the root cause is obvious.
* **Expanded IDE support:** VS Code, JetBrains/IntelliJ, Visual Studio, Eclipse, Cursor, and Windsurf.
* **Real-time on save:** findings surface as developers write code, not in a separate phase.

**Key Benefits**

* **Security where developers already work.** No context switching, no separate scanning step.
* **Faster root-cause understanding.** Code Flow makes the data path explicit instead of leaving developers to trace it manually.
* **Consistent coverage across tooling.** The same capabilities regardless of which IDE the team uses.

<figure><img src="/files/ybpXOZAwghSsm6Ye96Yw" alt=""><figcaption></figcaption></figure>

#### **⚡ Incremental Scanning Across All Analyzers**

Every analyzer now supports **incremental scanning.** Xygeni analyzes only what changed instead of re-scanning everything on each run.

**What Xygeni Does**

* Scans only the code and dependencies that changed since the last run, across all analyzers.
* Applies in CI/CD pipelines and in the IDE.

**Key Benefits**

* **Faster scans, faster feedback.** Shorter cycles in CI and near-instant feedback in the editor.
* **Lower pipeline cost and friction.** Less compute spent re-scanning unchanged code.
* **Security keeps pace with development.** Scanning no longer becomes the bottleneck as repositories grow.

#### **🚀 Free Developer Plan Now Available**

Xygeni now offers a **free Developer plan.** Get started at no cost, scan your repositories, and try the platform with no commitment.

👉 Sign up with GitHub, GitLab, or Google to get started.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.xygeni.io/changelog/version-6.11-june-24-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
