Security Startups

Categories

Security categories

One primary category per company, assigned by what it actually builds rather than marketing language. Sorted by field size.

Application security

16

Startups that find and fix weaknesses in application code: SAST, ASPM, authz and business-logic scanners, not the PR-comment bots.

Cloud security

16

CNAPP, CSPM, and workload startups that map cloud attack surface for companies that do not want another console from a network-security incumbent.

Identity and access

15

Workforce, customer, and ITDR startups. Identity is the control plane; these companies treat it as the product.

Detection and response

14

Independent XDR, MDR, and detection-engineering startups. Not the public mega-cap EDR floor.

Offensive and exposure

13

CTEM, attack-surface, pentest-platform, and continuous-exposure startups. Not a services firm with a PDF report.

Data security

12

DSPM, data detection, and data-access startups that tell you where sensitive data actually lives.

AI security

12

Startups securing models, agents, and LLM applications: red teaming, runtime guards, and agent identity.

Software supply chain

12

SCA, SBOM, package, and pipeline-security startups that treat dependencies as the product surface.

Secrets and non-human identity

11

Secrets, certificates, machine identity, and NHI startups. The credentials humans did not mean to ship.

Email and collaboration

10

Email security, browser isolation, and collaboration-security startups built after the last generation of secure email gateways.

Endpoint and browser

9

Independent endpoint, browser-security, and device startups. Not CrowdStrike-class public mega-caps.

API and runtime

8

API security, runtime application protection, and service-mesh startups watching production, not just pull requests.