Aevral
Listed by Better ISMS (same rules as everyone) · Coming soon
GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.
Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent
Live directory shortlist for primary category application-security. Full category slice, alphabetical, not quality-ranked. No paid order.
Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next editorial review by 2026-09-23. Alphabetical order, no paid placement. 16 matched live listings.
This page is a live catalog slice: every company whose primary category is application security. Readers often land here when comparing SAST, ASPM, and authz or business-logic scanners, not PR-comment bots. Depth and maturity vary widely. Some companies ship GitHub Apps on an owned SHA; others sell a console. Category membership is taxonomy from the directory research pass, and every entry carries a 2024 to 2026 proof-of-life signal. It is not a verified audit of every product claim, and the word Best in the shortlist title is the hub name, not a scored ranking.
Who this is for. AppSec leads, founders, and investors shortlisting companies whose main focus is finding or fixing weaknesses in application code rather than cloud posture, identity, or PR review comments.
Eligibility. Included only when a live company has primary category application-security. Pure AI code reviewers, GRC agents, and mega-cap SAST suites live elsewhere. Inclusion is category-based and verification-gated, not paid placement and not an endorsement of outcomes.
How order works. Matched companies are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking. When listing fees open, they are intended to affect publish timing or review-queue position only, not alphabetical order or praise on this page (payments are currently closed). Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Target query: best application security companies. Category index: /categories/application-security. Parent hub: /best. Full catalog: /directory.
Listed by Better ISMS (same rules as everyone) · Coming soon
GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.
Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent
Ghent, Belgium
One platform that scans code, cloud, and runtime, then triages and auto-fixes what is actually reachable.
Raised $60M Series B at a $1B valuation, January 2026
New York, USA
Code-to-runtime ASPM graph that ranks material application risk, not every scanner finding.
Joined Chainguard's Athena coalition and made AutoFix free for OSS maintainers, August 2026
Palo Alto, USA
Scanner-agnostic ASPM that correlates hundreds of tools into the findings that actually matter.
Raised $16M strategic round, taking total funding to $81M, March 2026
Alpharetta, USA
Pipelineless SAST, SCA, secrets, and IaC that scans every push and talks to the developer in Slack.
Shipped PR secrets scanning and secrets-in-HEAD detection, June 2026
New York, USA
Design-led product security agents that review PRDs, architecture, and specs before code exists.
Emerged from stealth with $36M seed and Series A, November 2025
San Francisco, USA
AI SAST that hunts broken auth and business-logic bugs, then writes a patch developers can merge.
Raised $2.6M seed led by Shorooq, with Y Combinator participating, November 2024
New York, USA
ASPM with its own SAST, SCA, and pipeline scanners, plus a graph for AI-written code.
Named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security, June 2026
Palo Alto, USA
Reachability-first AppSec: SAST and SCA that only page you when the vulnerable function is actually called.
Raised $93M Series B led by DFJ Growth, April 2025
Tel Aviv, Israel
Runtime-backed AppSec that proves a CVE is loaded in memory before it hits the backlog.
Published Rapyd case study showing runtime-led AppSec without extra headcount, July 2025
Tel Aviv, Israel
AI-native ASPM that discovers the software factory, then VibeGuard blocks bad AI code in the IDE.
Shipped VibeGuard to secure AI-generated code at the developer endpoint, 2026
New York, USA
Prompt-to-runtime AppSec that tries to show only the 5 percent of findings that can actually breach you.
Raised $60M Series B led by DTCP, taking total funding to $94M, May 2025
Baltimore, USA
Agentic AppSec that triages scanner noise and opens mergeable fix PRs in your house style.
Raised $15M seed led by Decibel and Wing VC, May 2025
San Francisco, USA
Rules-plus-AI SAST, SCA, and secrets that developers run in seconds and AppSec can actually tune.
Raised $100M Series D led by Menlo Ventures, February 2025
Boston, USA
Developer-first SAST, SCA, container, and IaC platform now wrapping AI agents and models too.
Launched Evo Agentic Development Security to govern coding agents, June 2026
San Francisco, USA
AI-native SAST for business logic, auth bypasses, and chained exploit paths, with generated patches.
Named an RSAC 2026 Innovation Sandbox Top 10 finalist