Codenotary Uses Claude AI to Secure immudb Development

The News

Codenotary, the company behind the open source immutable database immudb, has been accepted into Anthropic’s Claude for OSS program. The partnership gives Codenotary access to Claude AI to accelerate development of immudb, which provides cryptographically verifiable, tamper-evident data records used in software supply chains, compliance systems, financial infrastructure, and AI workloads. Rather than deploying Claude as an autonomous developer, Codenotary is positioning it as an engineering assistant: detecting subtle bugs, analyzing concurrency issues, generating regression tests, reviewing pull requests, and improving documentation, with human engineers retaining review and approval authority over all code changes.

Analyst Take

The real story is what this says about AI-assisted development at the infrastructure layer

Most AI coding announcements cluster around application-layer productivity like faster feature shipping, reduced boilerplate, quicker onboarding. Codenotary is doing something structurally different. It’s applying AI assistance to security-critical infrastructure software where the cost of a subtle defect, a missed race condition, or a silent data integrity failure is not a degraded user experience but a compromised audit trail or a breached supply chain. That distinction matters enormously for how you evaluate the model.

The framing CTO Dennis Zimmer uses is deliberate and worth taking seriously. He states that AI is an “engineering assistant that augments developer productivity,” not an autonomous agent. Every proposed change still goes through human review, automated testing, and reproducible builds. For immudb specifically, that discipline is non-negotiable. The database’s value proposition rests on cryptographic verifiability. Any erosion of engineering rigor in producing it would be self-defeating.

The supply chain security angle raises the stakes

The timing of this announcement intersects directly with where enterprise security investment is heading. ECI Research’s 2026 Application Development survey found that 47.4% of respondents selected software supply chain security as one of their top investment priorities for the next 12 months, making it one of the most cited priorities in the entire dataset. That demand signal is exactly the market Codenotary is serving with immudb, and accelerating its development velocity through AI assistance is a credible way to capitalize on that momentum without compromising the product’s integrity guarantees.

There’s also a pointed irony here that Codenotary is navigating carefully. AI-generated code has itself become a supply chain security concern. ECI Research’s 2026 DevSecOps & AppSec survey found that 29.1% of respondents identified AI-generated package risk as their biggest open-source security concern in 2026. Codenotary is using AI to build the very infrastructure that enterprises would use to establish trust and verifiability in AI-assisted development outputs. The company’s insistence on human review of every AI-suggested change is not just good engineering practice; it’s a brand statement about the kind of vendor it wants to be in a market that’s increasingly anxious about exactly this problem.

What developers should actually pay attention to

For engineers evaluating AI coding tools in security-sensitive contexts, the Codenotary approach offers a practical blueprint. The use cases they’ve identified, detecting subtle defects static analysis misses, reasoning across multi-file execution paths, identifying potential race conditions, generating regression tests, are precisely the tasks where AI provides genuine leverage without requiring autonomous decision authority. These are augmentation use cases, not replacement use cases. The distinction is architecturally significant. In any system where correctness is a security property rather than just a quality property, the human review gate is not optional overhead; it’s the assurance mechanism.

Looking Ahead

Codenotary’s acceptance into the Claude for OSS program positions the company to ship faster and with higher test coverage at a moment when enterprise demand for tamper-proof data infrastructure is accelerating across regulated industries. The more interesting question over the next 12 to 18 months is whether the AI-assisted development workflow they’re building around immudb becomes a differentiator they can articulate to enterprise buyers, not just an internal productivity gain. If Codenotary can demonstrate measurable improvements in defect detection rates, regression coverage, and release cadence, that evidence becomes a sales asset in regulated sectors where software provenance and auditability are procurement requirements.

The broader market dynamic to watch is how other security-infrastructure vendors respond. Codenotary is not alone in recognizing that AI assistance and security-critical software development are not mutually exclusive, but the companies that will win are those that build governance frameworks around AI use that match the assurance requirements of their products. The ones that treat AI as a black-box productivity shortcut in domains where cryptographic integrity is the value proposition will eventually produce the kind of incident that validates their competitors’ more disciplined approach. Codenotary is betting on discipline. That’s the right bet.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts