Security Startups
← All shortlists

Best Application security companies

Live directory shortlist for primary category application-security. Full category slice, alphabetical, not quality-ranked. No paid order.

Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next editorial review by 2026-09-23. Alphabetical order, no paid placement. 16 matched live listings.

This page is a live catalog slice: every company whose primary category is application security. Readers often land here when comparing SAST, ASPM, and authz or business-logic scanners, not PR-comment bots. Depth and maturity vary widely. Some companies ship GitHub Apps on an owned SHA; others sell a console. Category membership is taxonomy from the directory research pass, and every entry carries a 2024 to 2026 proof-of-life signal. It is not a verified audit of every product claim, and the word Best in the shortlist title is the hub name, not a scored ranking.

Who this is for. AppSec leads, founders, and investors shortlisting companies whose main focus is finding or fixing weaknesses in application code rather than cloud posture, identity, or PR review comments.

Eligibility. Included only when a live company has primary category application-security. Pure AI code reviewers, GRC agents, and mega-cap SAST suites live elsewhere. Inclusion is category-based and verification-gated, not paid placement and not an endorsement of outcomes.

How order works. Matched companies are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking. When listing fees open, they are intended to affect publish timing or review-queue position only, not alphabetical order or praise on this page (payments are currently closed). Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.

Target query: best application security companies. Category index: /categories/application-security. Parent hub: /best. Full catalog: /directory.

Aevral

Listed by Better ISMS (same rules as everyone) · Coming soon

Seed

GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.

Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent

Aikido Security

Ghent, Belgium

Series B

One platform that scans code, cloud, and runtime, then triages and auto-fixes what is actually reachable.

Raised $60M Series B at a $1B valuation, January 2026

Application security$84M raisedFounded 2022

Apiiro

New York, USA

Series B

Code-to-runtime ASPM graph that ranks material application risk, not every scanner finding.

Joined Chainguard's Athena coalition and made AutoFix free for OSS maintainers, August 2026

Application security$135M raisedFounded 2019

ArmorCode

Palo Alto, USA

Series B

Scanner-agnostic ASPM that correlates hundreds of tools into the findings that actually matter.

Raised $16M strategic round, taking total funding to $81M, March 2026

Application security$81M raisedFounded 2020

Arnica

Alpharetta, USA

Seed

Pipelineless SAST, SCA, secrets, and IaC that scans every push and talks to the developer in Slack.

Shipped PR secrets scanning and secrets-in-HEAD detection, June 2026

Application security$7M raisedFounded 2021

Clover Security

New York, USA

Series A

Design-led product security agents that review PRDs, architecture, and specs before code exists.

Emerged from stealth with $36M seed and Series A, November 2025

Application security$36M raisedFounded 2023

Corgea

San Francisco, USA

Seed

AI SAST that hunts broken auth and business-logic bugs, then writes a patch developers can merge.

Raised $2.6M seed led by Shorooq, with Y Combinator participating, November 2024

Application security$2.6M raisedFounded 2023

Cycode

New York, USA

Series B

ASPM with its own SAST, SCA, and pipeline scanners, plus a graph for AI-written code.

Named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security, June 2026

Application security$81M raisedFounded 2019

Endor Labs

Palo Alto, USA

Series B

Reachability-first AppSec: SAST and SCA that only page you when the vulnerable function is actually called.

Raised $93M Series B led by DFJ Growth, April 2025

Application security$163M raisedFounded 2021

Kodem

Tel Aviv, Israel

Series A

Runtime-backed AppSec that proves a CVE is loaded in memory before it hits the backlog.

Published Rapyd case study showing runtime-led AppSec without extra headcount, July 2025

Application security$25M raisedFounded 2021

Legit Security

Tel Aviv, Israel

Series B

AI-native ASPM that discovers the software factory, then VibeGuard blocks bad AI code in the IDE.

Shipped VibeGuard to secure AI-generated code at the developer endpoint, 2026

Application security$70M raisedFounded 2020

OX Security

New York, USA

Series B

Prompt-to-runtime AppSec that tries to show only the 5 percent of findings that can actually breach you.

Raised $60M Series B led by DTCP, taking total funding to $94M, May 2025

Application security$94M raisedFounded 2021

Pixee

Baltimore, USA

Seed

Agentic AppSec that triages scanner noise and opens mergeable fix PRs in your house style.

Raised $15M seed led by Decibel and Wing VC, May 2025

Application security$15M raisedFounded 2022

Semgrep

San Francisco, USA

Series D

Rules-plus-AI SAST, SCA, and secrets that developers run in seconds and AppSec can actually tune.

Raised $100M Series D led by Menlo Ventures, February 2025

Application security$204M raisedFounded 2017

Snyk

Boston, USA

Series G

Developer-first SAST, SCA, container, and IaC platform now wrapping AI agents and models too.

Launched Evo Agentic Development Security to govern coding agents, June 2026

ZeroPath

San Francisco, USA

Seed

AI-native SAST for business logic, auth bypasses, and chained exploit paths, with generated patches.

Named an RSAC 2026 Innovation Sandbox Top 10 finalist