Home / Episodes / E13 Bonus: The AI …

E13 Bonus: The AI SAST Shift: Eliminating Vulnerability Backlogs with Santiago Castiñeira, Co-Founder & CTO of Maze

22:09 listen Bonus
E13 Bonus: The AI SAST Shift: Eliminating Vulnerability Backlogs with Santiago Castiñeira, Co-Founder & CTO of Maze
Code Story | Startup Podcast for Technical Founders — E13 Bonus: The AI SAST Shift: Eliminating Vulnerability Backlogs with Santiago Castiñeira, Co-Founder & CTO of Maze
Press Play to Listen While You Browse
E13 Bonus: The AI SAST Shift: Eliminating Vulnerability Backlogs with Santiago Castiñeira, Co-Founder & CTO of Maze
Code Story | Startup Podcast for Technical Founders
0:00 22:09

Santiago Castineira has quite the background in international living. He was born in Argentina, but grew up in Spain, then moved to Sweden, San Francisco, and now llives in Germany. He did his grade school and university in Spain, but his masters program across Sweden, San Francisco, and Germany. He's worked in startups, bigger companies, and eventually founding and is leading his own. Outside of tech, he is a Dad of 3 kids, so he stays quite busy when he isn't working. He loves endurance sports, running half marathons and long distance biking.

Santiago and his team were well aware of the fact that tens of thousands of new vulnerabilities are published every year. While security teams were drowning, the rise of automated coding agents were starting to ship code faster and faster. He and his team realized that there needed to be an agent driven platform, designed to evaluate and secure your system like a senior security engineer. 

This is the creation story of Maze. 

Links

https://mazehq.com/

https://www.linkedin.com/in/santiagocastineira/



Current Sponsors:

Checkout our Stacklist! https://stacks.codestory.co/

Hosted by Noah Labhart | Technical Founder & Startup Mentor.



Our Sponsors:
* Check out Granola and use my code granola.ai/CODESTORY for a great deal: https://granola.ai
* Check out Perplexity and use my code CODESTORY for a great deal: https://www.perplexity.ai


Advertising Inquiries: https://redcircle.com/brands

Privacy & Opt-Out: https://redcircle.com/privacy

Latest Season of the Podcast is Sponsored By

Key Takeaways

  • The Static Application Security Testing (SAST) Bottleneck: Traditional SAST tools flag massive lists of potential vulnerabilities without context, drowning engineering teams in endless backlogs of false positives and unprioritized security alerts.
  • Moving from Rule Scans to Senior Security Agents: Maze replaces passive, rule-based scanners with autonomous AI agents designed to evaluate, triage, and patch codebases with the nuanced context of a senior application security engineer.
  • Closing the Remediation Gap: High-velocity engineering teams struggle to remediate known vulnerabilities due to tight feature deadlines; agent-driven SAST automatically generates contextual pull requests to fix security flaws directly in developer workflows.
  • Global Perspective Driving Engineering Leadership: Castiñeira’s international background across Argentina, Spain, Sweden, San Francisco, and Germany helped shape an adaptable, remote-first engineering culture built for rapid iteration.
  • Context-Aware Application Security: Effective AI security tools must understand repository architecture, data flow, and runtime risk to prevent non-critical warnings from stalling production deployments.

Frequently Asked Questions

What is Maze, and what core problem does it solve for security and engineering teams?

Maze is an agent-driven AI security and Static Application Security Testing (SAST) platform. It solves the issue of overwhelming vulnerability backlogs by automatically triaging, verifying, and fixing security flaws in software repositories.

Who is Santiago Castiñeira, and what is his background prior to co-founding Maze?

Santiago Castiñeira is an engineer and technical founder originally from Argentina who grew up in Spain. He completed his Master’s degree across Sweden, San Francisco, and Germany, acquiring deep global tech experience before launching Maze as CTO.

How do traditional SAST tools compare to Maze’s AI agent approach?

Traditional SAST scanners rely on static syntax rules, producing high rates of false positives and leaving developers to manually parse through thousands of alerts. Maze uses AI agents to analyze systemic risk context and write automated code remediations.

How does Maze assist developers without disrupting existing deployment workflows?

Maze integrates directly into standard CI/CD pipelines and version control platforms. Rather than stopping builds for low-risk issues, it automatically crafts production-ready pull requests containing security fixes for developer review.

What is the benefit of automating vulnerability remediation in fast-paced engineering organizations?

Automating remediation clears technical debt and reduces security backlogs, allowing developers to maintain shipping speed while ensuring production code adheres to enterprise security standards.

Where can listeners connect with Santiago Castiñeira and learn more about Maze?

Listeners can visit Maze HQ or connect directly with Santiago Castiñeira on LinkedIn.