How Endor Labs, Chainguard, Snyk, Semgrep, Socket, Aikido, Legit Security, Cycode, Apiiro, Ox Security, Backslash, Arnica, Jit.
AI-native AppSec, DevSecOps, software supply-chain security is one of the fastest-growing security categories — 2024 saw record supply-chain attacks (XZ Utils backdoor CVE-2024-3094, PyPI/npm typosquatting waves, Polyfill.io compromise, Sisense breach, Snowflake Ticketmaster, AT&T, Santander via stolen tokens), forcing every F500 CISO to procure reachability, SBOM, secrets, IaC, container, runtime, AI-code-review coverage. Startups, product — Endor Labs ($163M+ total incl. $70M A extension Aug-2024 DFJ Growth-Coatue-Lightspeed-Dell Technologies Capital, reachability-based SCA, AI code-review, secrets, CI-CD, SBOM), Chainguard ($256M+ total incl. $140M C Nov-2024 Redpoint-Amplify-IVP-Kleiner-Sequoia-Spark, minimal, zero-CVE container images, Wolfi, Sigstore, FIPS, FedRAMP), Snyk ($1.05B+ total, IPO track $8.6B post-money Jan-2023 down-round from $9.9B, developer-security platform), Semgrep ($200M+ total incl. $100M D Sep-2024 Menlo-Redpoint-Sequoia-Felicis, static-analysis, Semgrep Assistant AI, Semgrep Supply Chain, Semgrep Secrets), Socket ($60M+ total incl. $40M B Aug-2024 Andreessen-a16z-Abstract-Elad Gil, AI-first open-source dependency, typosquat, malicious-package detection), Aikido Security ($67M+ total incl. $50M B Nov-2024 Singular-Notion-Datadog Ventures, all-in-one AppSec for SMB, mid-market), Legit Security ($75M+ total incl. $40M B Feb-2024 CRV-Cyberstarts-Bessemer, ASPM, CI/CD, secrets, SBOM), Cycode ($136M+ total incl. $54M B Nov-2022 Insight Partners-YL Ventures, ASPM, supply-chain), Apiiro ($135M+ total incl. $100M B May-2024 General Catalyst-Kleiner-Greylock-Fictiv-Elad Gil, ASPM, code-to-runtime), Ox Security ($134M+ total incl. $60M A May-2024 IVP-Team8-Rain Capital, ASPM, supply-chain), Backslash Security ($26M+ total incl. $8M seed Sep-2023 StageOne-Team8, reachability-based SCA), Arnica ($10M+ Draper-Kmehin, ASPM, code-to-cloud), Jit ($38M+ total incl. $12M A Boldstart-Insight, DevSecOps orchestration), Bit Discovery-Tenable (acq $44M Sep-2022, ASM), StackHawk ($20M+ B, DAST for CI/CD), Nuclei-ProjectDiscovery ($25M+ CRV-Point72-Lightspeed), Root Security-Descope-adj, Kondukto, Escape (API-security). Runtime, eBPF, container, AI-code layers — Wiz ($32B Google acquisition Mar-2025 pending, CNAPP, supply-chain, container scanning — see AI Cybersecurity page), Sysdig, Aqua Security ($1B+ Insight-CapitalG-Evolution, container, runtime, SBOM), Anchore ($40M+ Foundry-Storm), JFrog Xray, JFrog Curation $FROG, Sonatype (Vista Equity), Mend.io (ex-WhiteSource, M12, Susquehanna), Checkmarx (Hellman & Friedman $1.15B+ Apr-2020), Veracode (Bregal Sagemount, TA Associates, take-private 2022), Black Duck-Synopsys (spin from Synopsys Software Integrity Sep-2024 for $2.1B to Clearlake, Francisco), HackerOne, Bugcrowd, Synack (bug-bounty), YesWeHack, Intigriti (EU bug-bounty), Semgrep, Snyk Open Source competitors GitLab Ultimate SAST/DAST/SCA, GitHub Advanced Security, Copilot Autofix, Dependabot, CodeQL, Amazon CodeGuru Security, Amazon Inspector, Google Cloud Assured Open Source Software, Software Delivery Shield, Microsoft Defender for Cloud, GitHub Advanced Security. Sigstore, supply-chain infrastructure — Sigstore (Linux Foundation, cosign, fulcio, rekor), SLSA (Google, OSSF), in-toto (CNCF), TUF (CNCF), OSSF Scorecard, Allstar, Package Analysis, GUAC (Kusari, Google, IBM), Kusari ($8M+ Glasswing-Front Porch), TestifySec, Rekor, Chainguard Enforce, Chainguard Cluster, Chainguard Libraries. Regulation, framework — EO 14028 (May-2021), NIST SSDF SP 800-218, SP 800-218A, M-22-18, M-23-16, SBOM attestations to CISA (Aug-2023 form deadline), EU Cyber Resilience Act (CRA, in force Dec-2024, most obligations Dec-2027 with 21-day vulnerability reporting from Sep-2026), EU NIS2 (Oct-2024), UK PSTI (Apr-2024), FDA Refuse-to-Accept, PMA cyber for medical devices (Section 524B FD&C Act, Mar-2023), DORA (EU financial-services, Jan-2025), ISO/IEC 27001, 27034, 5230 (OpenChain), CVE, CWE, SARIF, SPDX, CycloneDX SBOM formats, VEX (Vulnerability Exploitability eXchange), OSV.dev (Google, OSSF), OpenSSF Scorecard, plus post-XZ, Sisense, Polyfill, Snowflake-token 2024 wave forcing board-level supply-chain security procurement.
Four unlocks: (1) The 2024 supply-chain attack wave — XZ Utils backdoor (CVE-2024-3094 Andres Freund Mar-2024 catch), PyPI, npm typosquatting waves, Polyfill.io compromise (Jun-2024), Sisense breach (Apr-2024), Snowflake stolen-token wave (Ticketmaster, AT&T, Santander, LendingTree, Advance Auto Parts May-Jul-2024) — collapsed the 'is supply-chain a real risk?' debate and forced every F500 CISO to procure reachability, SBOM, secrets, attestation coverage. (2) Frontier reasoning models (GPT-5, Claude Opus 4.5, Sonnet 4.5, Gemini 2.5 Pro) reached the accuracy floor where AI code-review, auto-fix, PR-comment now clears the developer-acceptance bar — Semgrep Assistant, Snyk Code, Copilot Autofix, Corgea, Mobb, Pixee published 40-60% auto-fix-acceptance case-studies in 2024-2025. (3) EU Cyber Resilience Act (in force Dec-2024, Sep-2026 21-day vuln-reporting to ENISA, Dec-2027 CE-marking), EO 14028, M-22-18, M-23-16 CISA SBOM attestation (Aug-2023 form), FDA Section 524B (Mar-2023), DORA (Jan-2025) created hard regulatory deadlines that force SBOM, VEX, SLSA, Sigstore adoption and unlock a new $10B+ procurement line-item. (4) Wiz-Google $32B (pending Mar-2025), Noname-Akamai $500M, Ermetic-Tenable $265M, Talon, Dig, Cider, Bionic, Bit Discovery M&A wave validated AppSec, supply-chain, CNAPP as top-tier acquirer category and priced strategic exits at 15-30x ARR.
Seed $3-15M for founding-team, first published reachability, adoption benchmark, 3-5 F500 or top-100-tech design-partner logos (Backslash $8M seed Sep-2023, Kusari $8M+, Jit $12M A Boldstart-Insight, Socket $22M A pre-Series B pattern). Series A $20-80M for 15-40 F500, top-100-tech logos, $2-8M ACV proof, FedRAMP, SOC 2 Type II, ISO 27001 (Ox Security $60M A May-2024 IVP-Team8-Rain, Legit $40M B CRV-Cyberstarts-Bessemer, Apiiro $100M B May-2024 General Catalyst-Kleiner-Greylock, Socket $40M B Aug-2024 Andreessen-Abstract, Aikido $50M B Nov-2024 Singular-Notion-Datadog Ventures, Endor Labs $70M A extension Aug-2024 DFJ-Coatue-Lightspeed). Series B $80-200M for $20-75M+ ARR, NDR 130%+, FedRAMP-Moderate/High, IL4/5, EU CRA, FDA 524B, Sigstore, SLSA, GitHub, GitLab, Palo Alto, CrowdStrike, Datadog Marketplace listings (Semgrep $100M D Sep-2024 Menlo-Redpoint-Sequoia-Felicis $500M+ post-money, Chainguard $140M C Nov-2024 Redpoint-Amplify-IVP-Kleiner-Sequoia-Spark $3.5B+ post-money). Series C+ $150M-$500M for $75M-$300M+ ARR, platform, M&A, late-stage growth (Snyk $1.05B+ total $8.6B Jan-2023 down-round from $9.9B pattern, JFrog $2B+ market-cap public $FROG, GitLab $10B+ market-cap public $GTLB, Palo Alto $130B+ market-cap public $PANW). Non-dilutive, credits: NSF SBIR-STTR, DARPA V-SPELLS, DARPA AISS, DoD SBIR, DIU, AFWERX, IARPA, CISA JCDC, CISA JSC, CISA Secure by Design, NSA Cybersecurity Directorate, UK NCSC, Innovate UK, EU Horizon-EIC, ENISA, plus AWS, Azure, Google, GitHub, Nvidia, Snowflake, Databricks partner-credits ($100k-$500k per startup).
Building traditional SCA or SAST without reachability, call-graph, taint-analysis — F500 CISOs bin any AppSec pitch that produces 10,000+ noisy CVEs instead of the 100-500 reachable, exploitable subset (Endor, Socket, Semgrep, Backslash, Snyk Code benchmarks). Ignoring GitHub Advanced Security, Copilot Autofix, Dependabot, CodeQL, GitLab Ultimate, Amazon CodeGuru, Google Duet, Microsoft Defender for Cloud as the reference bundled competition — bundled security inside GitHub, GitLab, Azure DevOps, AWS CodePipeline, GCP Cloud Build is 40-60% of the F500 baseline. Ignoring Sigstore, SLSA, in-toto, GUAC, OSSF Scorecard, CycloneDX, SPDX, VEX, OpenVEX, CSAF, OSV.dev as the reference supply-chain, attestation stack — bespoke SBOM formats are a losing tax and CISA, EU CRA, FDA 524B require standardized attestation. Depending on frontier-only models without an open-weights, fine-tune, cache path — F500, gov, defense procurement requires VPC, BYOK, on-prem, air-gapped, and inference-cost per PR kills gross-margin below 60% without Llama 3.3 70B, Qwen 2.5 Coder, DeepSeek V3, StarCoder2, CodeGemma offload. Ignoring FedRAMP-Moderate/High, IL4/5, SOC 2 Type II, ISO 27001, ISO 42001, FIPS 140-3, StateRAMP, TX-RAMP, HIPAA, PCI-DSS — these are gating for gov, defense, finance, healthcare procurement, not nice-to-have. Building AI auto-fix without human-in-loop review, audit-log, rollback, explainable-fix-diffs — a single bad auto-fix that breaks prod erases developer trust and kills adoption. Ignoring the GitHub-Microsoft, GitLab, Palo Alto, CrowdStrike, Cisco, Datadog, Snowflake, Google-Wiz strategic acquirer pattern — most exits will be strategic, not IPO.
Investor directory · Fundraising library · Articles A–Z · Company funding database