Categories
Security categories
One primary category per company, assigned by what it actually builds rather than marketing language. Sorted by field size.
Application security
16Startups that find and fix weaknesses in application code: SAST, ASPM, authz and business-logic scanners, not the PR-comment bots.
Cloud security
16CNAPP, CSPM, and workload startups that map cloud attack surface for companies that do not want another console from a network-security incumbent.
Identity and access
15Workforce, customer, and ITDR startups. Identity is the control plane; these companies treat it as the product.
Detection and response
14Independent XDR, MDR, and detection-engineering startups. Not the public mega-cap EDR floor.
Offensive and exposure
13CTEM, attack-surface, pentest-platform, and continuous-exposure startups. Not a services firm with a PDF report.
Data security
12DSPM, data detection, and data-access startups that tell you where sensitive data actually lives.
AI security
12Startups securing models, agents, and LLM applications: red teaming, runtime guards, and agent identity.
Software supply chain
12SCA, SBOM, package, and pipeline-security startups that treat dependencies as the product surface.
Secrets and non-human identity
11Secrets, certificates, machine identity, and NHI startups. The credentials humans did not mean to ship.
Email and collaboration
10Email security, browser isolation, and collaboration-security startups built after the last generation of secure email gateways.
Endpoint and browser
9Independent endpoint, browser-security, and device startups. Not CrowdStrike-class public mega-caps.
API and runtime
8API security, runtime application protection, and service-mesh startups watching production, not just pull requests.