Aevral
Listed by Better ISMS (same rules as everyone) · Coming soon
GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.
Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent
Startups that find and fix weaknesses in application code: SAST, ASPM, authz and business-logic scanners, not the PR-comment bots.
16 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.
Application security is the code-and-logic layer of this directory, not a second vendor floor. This index maps every company whose primary product finds or fixes weaknesses in application code: SAST, ASPM, authz and business-logic scanners. Pull-request comment bots belong on aicodereviewers.com. Mega-cap SAST suites belong on the vendor map if they belong anywhere. Every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link, and membership is taxonomy from the research pass.
What they build. The products here include static analysis, application security posture, authorization and IDOR scanners, and tools that look at business logic rather than only XSS or SQLi signatures. Some sell a scanner plus a console; others sell a GitHub App or CI check on an owned SHA. PR-diff review bots that comment on style or generic bugs live elsewhere.
Who this is for. AppSec leads comparing scanners that actually look at authz and business logic, founders mapping the independent ASPM field, and investors who need companies rather than Black Hat booth labels.
How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Listed by Better ISMS (same rules as everyone) · Coming soon
GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.
Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent
Ghent, Belgium
One platform that scans code, cloud, and runtime, then triages and auto-fixes what is actually reachable.
Raised $60M Series B at a $1B valuation, January 2026
New York, USA
Code-to-runtime ASPM graph that ranks material application risk, not every scanner finding.
Joined Chainguard's Athena coalition and made AutoFix free for OSS maintainers, August 2026
Palo Alto, USA
Scanner-agnostic ASPM that correlates hundreds of tools into the findings that actually matter.
Raised $16M strategic round, taking total funding to $81M, March 2026
Alpharetta, USA
Pipelineless SAST, SCA, secrets, and IaC that scans every push and talks to the developer in Slack.
Shipped PR secrets scanning and secrets-in-HEAD detection, June 2026
New York, USA
Design-led product security agents that review PRDs, architecture, and specs before code exists.
Emerged from stealth with $36M seed and Series A, November 2025
San Francisco, USA
AI SAST that hunts broken auth and business-logic bugs, then writes a patch developers can merge.
Raised $2.6M seed led by Shorooq, with Y Combinator participating, November 2024
New York, USA
ASPM with its own SAST, SCA, and pipeline scanners, plus a graph for AI-written code.
Named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security, June 2026
Palo Alto, USA
Reachability-first AppSec: SAST and SCA that only page you when the vulnerable function is actually called.
Raised $93M Series B led by DFJ Growth, April 2025
Tel Aviv, Israel
Runtime-backed AppSec that proves a CVE is loaded in memory before it hits the backlog.
Published Rapyd case study showing runtime-led AppSec without extra headcount, July 2025
Tel Aviv, Israel
AI-native ASPM that discovers the software factory, then VibeGuard blocks bad AI code in the IDE.
Shipped VibeGuard to secure AI-generated code at the developer endpoint, 2026
New York, USA
Prompt-to-runtime AppSec that tries to show only the 5 percent of findings that can actually breach you.
Raised $60M Series B led by DTCP, taking total funding to $94M, May 2025
Baltimore, USA
Agentic AppSec that triages scanner noise and opens mergeable fix PRs in your house style.
Raised $15M seed led by Decibel and Wing VC, May 2025
San Francisco, USA
Rules-plus-AI SAST, SCA, and secrets that developers run in seconds and AppSec can actually tune.
Raised $100M Series D led by Menlo Ventures, February 2025
Boston, USA
Developer-first SAST, SCA, container, and IaC platform now wrapping AI agents and models too.
Launched Evo Agentic Development Security to govern coding agents, June 2026
San Francisco, USA
AI-native SAST for business logic, auth bypasses, and chained exploit paths, with generated patches.
Named an RSAC 2026 Innovation Sandbox Top 10 finalist