Security Startups
← All categories

Application security

Startups that find and fix weaknesses in application code: SAST, ASPM, authz and business-logic scanners, not the PR-comment bots.

16 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.

Application security is the code-and-logic layer of this directory, not a second vendor floor. This index maps every company whose primary product finds or fixes weaknesses in application code: SAST, ASPM, authz and business-logic scanners. Pull-request comment bots belong on aicodereviewers.com. Mega-cap SAST suites belong on the vendor map if they belong anywhere. Every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link, and membership is taxonomy from the research pass.

What they build. The products here include static analysis, application security posture, authorization and IDOR scanners, and tools that look at business logic rather than only XSS or SQLi signatures. Some sell a scanner plus a console; others sell a GitHub App or CI check on an owned SHA. PR-diff review bots that comment on style or generic bugs live elsewhere.

Who this is for. AppSec leads comparing scanners that actually look at authz and business logic, founders mapping the independent ASPM field, and investors who need companies rather than Black Hat booth labels.

How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.

Aevral

Listed by Better ISMS (same rules as everyone) · Coming soon

Seed

GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.

Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent

Aikido Security

Ghent, Belgium

Series B

One platform that scans code, cloud, and runtime, then triages and auto-fixes what is actually reachable.

Raised $60M Series B at a $1B valuation, January 2026

Application security$84M raisedFounded 2022

Apiiro

New York, USA

Series B

Code-to-runtime ASPM graph that ranks material application risk, not every scanner finding.

Joined Chainguard's Athena coalition and made AutoFix free for OSS maintainers, August 2026

Application security$135M raisedFounded 2019

ArmorCode

Palo Alto, USA

Series B

Scanner-agnostic ASPM that correlates hundreds of tools into the findings that actually matter.

Raised $16M strategic round, taking total funding to $81M, March 2026

Application security$81M raisedFounded 2020

Arnica

Alpharetta, USA

Seed

Pipelineless SAST, SCA, secrets, and IaC that scans every push and talks to the developer in Slack.

Shipped PR secrets scanning and secrets-in-HEAD detection, June 2026

Application security$7M raisedFounded 2021

Clover Security

New York, USA

Series A

Design-led product security agents that review PRDs, architecture, and specs before code exists.

Emerged from stealth with $36M seed and Series A, November 2025

Application security$36M raisedFounded 2023

Corgea

San Francisco, USA

Seed

AI SAST that hunts broken auth and business-logic bugs, then writes a patch developers can merge.

Raised $2.6M seed led by Shorooq, with Y Combinator participating, November 2024

Application security$2.6M raisedFounded 2023

Cycode

New York, USA

Series B

ASPM with its own SAST, SCA, and pipeline scanners, plus a graph for AI-written code.

Named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security, June 2026

Application security$81M raisedFounded 2019

Endor Labs

Palo Alto, USA

Series B

Reachability-first AppSec: SAST and SCA that only page you when the vulnerable function is actually called.

Raised $93M Series B led by DFJ Growth, April 2025

Application security$163M raisedFounded 2021

Kodem

Tel Aviv, Israel

Series A

Runtime-backed AppSec that proves a CVE is loaded in memory before it hits the backlog.

Published Rapyd case study showing runtime-led AppSec without extra headcount, July 2025

Application security$25M raisedFounded 2021

Legit Security

Tel Aviv, Israel

Series B

AI-native ASPM that discovers the software factory, then VibeGuard blocks bad AI code in the IDE.

Shipped VibeGuard to secure AI-generated code at the developer endpoint, 2026

Application security$70M raisedFounded 2020

OX Security

New York, USA

Series B

Prompt-to-runtime AppSec that tries to show only the 5 percent of findings that can actually breach you.

Raised $60M Series B led by DTCP, taking total funding to $94M, May 2025

Application security$94M raisedFounded 2021

Pixee

Baltimore, USA

Seed

Agentic AppSec that triages scanner noise and opens mergeable fix PRs in your house style.

Raised $15M seed led by Decibel and Wing VC, May 2025

Application security$15M raisedFounded 2022

Semgrep

San Francisco, USA

Series D

Rules-plus-AI SAST, SCA, and secrets that developers run in seconds and AppSec can actually tune.

Raised $100M Series D led by Menlo Ventures, February 2025

Application security$204M raisedFounded 2017

Snyk

Boston, USA

Series G

Developer-first SAST, SCA, container, and IaC platform now wrapping AI agents and models too.

Launched Evo Agentic Development Security to govern coding agents, June 2026

ZeroPath

San Francisco, USA

Seed

AI-native SAST for business logic, auth bypasses, and chained exploit paths, with generated patches.

Named an RSAC 2026 Innovation Sandbox Top 10 finalist