Anchore
Santa Barbara, USA
Open-source Syft/Grype plus enterprise SBOM management for containers and the pipeline that builds them.
Published the 2025 Anchore supply-chain blog series, December 2025
SCA, SBOM, package, and pipeline-security startups that treat dependencies as the product surface.
Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-10. Next editorial review by 2026-09-10. Alphabetical order, no paid placement. 12 matched live listings.
This shortlist is the live catalog slice for the Software supply chain category. Listings appear here only when their primary category matches. Full page-unique intros for remaining categories ship in a later polish pass.
How order works. Matched companies are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking. When listing fees open, they are intended to affect publish timing or review-queue position only, not alphabetical order or praise on this page (payments are currently closed). Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Category index: /categories/supply-chain. Parent hub: /best. Full catalog: /directory.
Santa Barbara, USA
Open-source Syft/Grype plus enterprise SBOM management for containers and the pipeline that builds them.
Published the 2025 Anchore supply-chain blog series, December 2025
Tel Aviv, Israel
Reachability-aware AppSec now aimed at AI coding agents, IDEs, MCPs, and the packages they pull.
Raised $19M Series A led by KOMPAS VC, February 2026
Montreal, Canada
Pipeline and package gates that block supply-chain junk before AI-written code swallows it.
Raised $4M and acquired SecureIQx and Korbit.ai, May 2026
Kirkland, USA
Zero-to-low CVE container images and language libraries rebuilt from verified source.
Closed $280M growth round from General Catalyst at a $3.5B valuation, October 2025
Belfast, United Kingdom
Universal artifact control plane for what AI and humans actually put into production.
Raised $72M Series C led by TCV and Insight Partners, April 2026
Columbus, USA
Product and firmware SBOM platform for the devices you buy and the binaries you did not compile.
Won Cybersecurity Stars award for firmware security leadership, June 2026
Santa Clara, USA
AI-driven lineage of every component, including the ones hiding in firmware and public-sector stacks.
Raised $20M Series A co-led by Prosperity7, Neotribe, and Hitachi, July 2024
Washington, USA
SBOM and AIBOM intelligence so you can actually use the bills of materials you generate.
Raised $15M Series A led by Ensemble VC, April 2025
Austin, USA
Firmware and binary SBOM that unpacks what vendors actually shipped, not what the datasheet claimed.
Raised $10M Series A, taking total funding to about $25M, April 2025
Tel Aviv, Israel
Backports security patches onto the exact open-source versions you already run, including EOL.
Raised $13M Series A led by Vertex Israel, July 2025
San Francisco, USA
Behavioral SCA that blocks malicious packages at install time, before a CVE exists.
Raised $60M Series C at a $1B valuation led by Thrive Capital, May 2026
Pamplona, Spain
SCA plus malware and pipeline security for teams whose code is increasingly written by agents.
Won Global Infosec awards for ASPM and GenAI application security, 2026