DARPA Selects Xint to Secure Military Messaging Apps with AI
Following its success in a major multi-year competition, Xint has been chosen by the Defense Advanced Research Projects Agency to research autonomous AI application security for military messaging platforms.

DARPA Selects Xint for Military Messaging Security
The Defense Advanced Research Projects Agency (DARPA) has selected Xint to research the use of autonomous AI application security. The initiative focuses on performing deep analyses of internally and externally developed messaging applications utilized throughout the Department of War. According to details shared with SecurityWeek, the collaboration aims to ensure that military communications remain secure against external and foreign eavesdropping.
DARPA was originally established in 1958 in the wake of the USSR’s launch of Sputnik in 1957. Its overarching purpose is to ensure that the United States is never surprised by the technological achievements of foreign countries. Throughout its history, the agency has partnered with private industry to develop cutting-edge technologies that keep the nation ahead of rivals, famously leading to foundational innovations such as the internet via ARPANET, GPS, and Siri.
Roots in the AIxCC Competition and Emergence from Theori
Xint emerged within Theori and secured its selection following its strong performance in DARPA’s Artificial Intelligence Cyber Challenge (AIxCC). The competition was a two-year, $29.5 million event that ultimately named three winners. Building on this achievement, Xint is now tasked with analyzing source code from various projects, whether they are internally developed messaging apps like Signal or open-source software.
In addition to source code analysis, the company will analyze compiled binaries using a service launched in September 2026. This newly introduced service is designed to assess software supply chain risk across compiled code running in diverse environments, including on-premises software, network daemons, agents, appliances, and other critical services.
Unique Risks in Messaging and Communication Applications
"Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app," said Andrew Wesie, CTO and co-founder at Xint, during an explanation of the company's operations.
Wesie further noted that third-party software development kits (SDKs) and libraries embedded within messaging apps can introduce hidden data risks. Seemingly minor leaks can inadvertently expose a user’s physical location or other personally identifiable information during sensitive communications, often happening without the knowledge of the user or even the application developer.
How Xint’s AI-Driven Vulnerability Analysis Operates
Xint technology leverages the latest frontier large language model (LLM) models. Wesie describes Xint as essentially operating as a harness and workflow built around frontier elements. The system can examine all source code involved in target applications and reverse engineer binaries whenever necessary.
For instance, when analyzing messaging data originating from Android, Xint evaluates the application itself alongside the Linux kernel and other Android ecosystem components sitting between the app and the kernel. By gaining access to every aspect of the targeted system, the platform can detect and investigate vulnerabilities across the entire attack surface.
Once vulnerabilities are identified, the technology automatically triages them based on their accessibility to potential attackers. It then generates patches for any security flaws that could be exploited. This capability grants DARPA a robust method for securing War Department communications, while simultaneously allowing Xint to refine technology applicable to broader commercial markets.
Commercial Expansion and Future Outlook
Beyond its work with defense authorities, Xint offers its software security capabilities as a SaaS solution to commercial customers. Developers can run their custom code through Xint prior to release to ensure it is vulnerability-free, followed by regular secondary scans to detect any new issues introduced post-release.
"Right now, we’re talking to customers that have written their own code, such as a web app. We want to help them secure that code," Wesie explained. While the startup continues to evolve its service offerings, it is also exploring options for enterprises that prefer keeping everything inside local data centers, though utilizing top-tier external LLM models locally remains an ongoing technical challenge.
Sources
- SecurityWeekDARPA Selects Xint to Use AI in Securing Military Messaging Apps
Continue chronologically



