42Crunch
Dublin, Ireland
OpenAPI-first API security that audits the contract, tests it, then wraps a micro-firewall around the live endpoint.
Released OAS 3.1 support for API Protection in the 42Crunch platform, February 2026
API security, runtime application protection, and service-mesh startups watching production, not just pull requests.
8 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.
This is the live catalog slice for the API and runtime category. A company appears here only when its primary category matches, and every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link. A full page-unique intro for this category ships in a later polish pass.
How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Dublin, Ireland
OpenAPI-first API security that audits the contract, tests it, then wraps a micro-firewall around the live endpoint.
Released OAS 3.1 support for API Protection in the 42Crunch platform, February 2026
Los Altos, United States
IAST, RASP, and ADR that instrument the running app so exploits are seen in the code path, not the packet.
Published the Software Under Siege 2025 report on application-layer attacks, August 2025
Paris, France
AI pentesting for APIs and web apps that proves exploitability, including IDOR and business logic, not just crawler noise.
Raised $18M to expand agentic pentesting for APIs and business logic, March 2026
San Francisco, United States
Runtime API and AI security with eBPF visibility, agentless discovery, and inline protection that stays off the data path for privacy.
Shipped Launch Week 2026 with AI Firewall, AI Gateway, and MCP discovery and testing, February 2026
Tel Aviv, Israel
Application detection and response that watches live code execution and blocks exploits as they run.
Raised $60M, crossing $140M in total funding, August 2026
Palo Alto, United States
Runtime API security that discovers shadow and zombie APIs, then spots business-logic abuse in live traffic.
Published a year of monthly API and AI security releases, December 2025
Denver, United States
Developer-first API DAST that runs in CI so AI-generated endpoints get tested before they ship.
Raised $12M strategic round from Sapphire and Costanoa, total $47.3M, May 2025
San Francisco, United States
Inline API and agent security that blocks abuse in real time instead of paging after the request lands.
Raised $55M Series C led by Toba Capital, July 2025