Security Startups
← All categories

Software supply chain

SCA, SBOM, package, and pipeline-security startups that treat dependencies as the product surface.

12 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.

This is the live catalog slice for the Software supply chain category. A company appears here only when its primary category matches, and every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link. A full page-unique intro for this category ships in a later polish pass.

How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.

Anchore

Santa Barbara, USA

Series B

Open-source Syft/Grype plus enterprise SBOM management for containers and the pipeline that builds them.

Published the 2025 Anchore supply-chain blog series, December 2025

Backslash Security

Tel Aviv, Israel

Series A

Reachability-aware AppSec now aimed at AI coding agents, IDEs, MCPs, and the packages they pull.

Raised $19M Series A led by KOMPAS VC, February 2026

Software supply chain$27M raisedFounded 2022

Boost Security

Montreal, Canada

Seed

Pipeline and package gates that block supply-chain junk before AI-written code swallows it.

Raised $4M and acquired SecureIQx and Korbit.ai, May 2026

Software supply chain$16M raisedFounded 2020

Chainguard

Kirkland, USA

Series D

Zero-to-low CVE container images and language libraries rebuilt from verified source.

Closed $280M growth round from General Catalyst at a $3.5B valuation, October 2025

Software supply chain$892M raisedFounded 2021

Cloudsmith

Belfast, United Kingdom

Series C

Universal artifact control plane for what AI and humans actually put into production.

Raised $72M Series C led by TCV and Insight Partners, April 2026

Software supply chain$124M raisedFounded 2016

Finite State

Columbus, USA

Series B

Product and firmware SBOM platform for the devices you buy and the binaries you did not compile.

Won Cybersecurity Stars award for firmware security leadership, June 2026

Lineaje

Santa Clara, USA

Series A

AI-driven lineage of every component, including the ones hiding in firmware and public-sector stacks.

Raised $20M Series A co-led by Prosperity7, Neotribe, and Hitachi, July 2024

Software supply chain$27M raisedFounded 2021

Manifest

Washington, USA

Series A

SBOM and AIBOM intelligence so you can actually use the bills of materials you generate.

Raised $15M Series A led by Ensemble VC, April 2025

Software supply chain$23M raisedFounded 2022

NetRise

Austin, USA

Series A

Firmware and binary SBOM that unpacks what vendors actually shipped, not what the datasheet claimed.

Raised $10M Series A, taking total funding to about $25M, April 2025

Software supply chain$25M raisedFounded 2020

Seal Security

Tel Aviv, Israel

Series A

Backports security patches onto the exact open-source versions you already run, including EOL.

Raised $13M Series A led by Vertex Israel, July 2025

Software supply chain$20M raisedFounded 2022

Socket

San Francisco, USA

Series C

Behavioral SCA that blocks malicious packages at install time, before a CVE exists.

Raised $60M Series C at a $1B valuation led by Thrive Capital, May 2026

Software supply chain$125M raisedFounded 2022

Xygeni

Pamplona, Spain

Seed

SCA plus malware and pipeline security for teams whose code is increasingly written by agents.

Won Global Infosec awards for ASPM and GenAI application security, 2026

Software supply chain$4M raisedFounded 2021