42Crunch
Dublin, Ireland
OpenAPI-first API security that audits the contract, tests it, then wraps a micro-firewall around the live endpoint.
Released OAS 3.1 support for API Protection in the 42Crunch platform, February 2026
Directory
148 companies. Sorted by name. No paid boost.
Dublin, Ireland
OpenAPI-first API security that audits the contract, tests it, then wraps a micro-firewall around the live endpoint.
Released OAS 3.1 support for API Protection in the 42Crunch platform, February 2026
Boston, USA
Swarming AI agents that take over the investigation work human SOCs cannot staff.
Raised $130M Series A led by Index Ventures, December 2025
San Francisco, United States
API-native email and SaaS defense that baselines human behavior to catch BEC and account takeover.
Raised $250M Series D at a $5.1B valuation, August 2024
Houston, USA
Cloud-native patch management that remediates endpoints without a VPN or on-prem console.
H1 2026 ARR from six-figure deals grew 275% year over year
Silver Spring, United States
Workload IAM that issues short-lived, secretless credentials for services, scripts, and AI agents.
Raised $25M Series A led by Acrew Capital, September 2024
Listed by Better ISMS (same rules as everyone) · Coming soon
GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.
Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent
Ghent, Belgium
One platform that scans code, cloud, and runtime, then triages and auto-fixes what is actually reachable.
Raised $60M Series B at a $1B valuation, January 2026
Ramat Gan, Israel
SaaS vault for secrets, keys, and certificates that never stores the master key in the customer's cloud.
Took a strategic investment from Deutsche Bank Ventures, October 2024
Santa Barbara, USA
Open-source Syft/Grype plus enterprise SBOM management for containers and the pipeline that builds them.
Published the 2025 Anchore supply-chain blog series, December 2025
New York, USA
Code-to-runtime ASPM graph that ranks material application risk, not every scanner finding.
Joined Chainguard's Athena coalition and made AutoFix free for OSS maintainers, August 2026
Tel Aviv, Israel
Just-in-time cloud access that kills standing privileges for humans, machines, and agents.
Raised $34M Series B led by USVP, November 2025
San Mateo, United States
SaaS security posture for Salesforce, ServiceNow, Microsoft 365, and the agents now living inside them.
Reported 43% year-over-year revenue growth and five of the top 10 Fortune 500 as customers, February 2025
Burlington, United States
Code-to-runtime CNAPP that ranks CVEs by live workload behavior and can stop an exploit without waiting for a patch.
Raised $60M at a $1B-plus valuation, January 2024
Eden Prairie, USA
Concierge MDR on the Aurora platform, now with its own endpoint prevention.
Launched Aurora Endpoint Security and acquired Cylance from BlackBerry in 2025
Tel Aviv, Israel
Kubernetes-rooted CNAPP and CADR, built on CNCF Kubescape, that uses eBPF runtime to decide which CVEs and misconfigs matter.
Kubescape 4.0 released with runtime threat detection GA, March 2026
Palo Alto, USA
Scanner-agnostic ASPM that correlates hundreds of tools into the findings that actually matter.
Raised $16M strategic round, taking total funding to $81M, March 2026
Alpharetta, USA
Pipelineless SAST, SCA, secrets, and IaC that scans every push and talks to the developer in Slack.
Shipped PR secrets scanning and secrets-in-HEAD detection, June 2026
Tel Aviv, Israel
Cloud policy enforcement that blocks misconfigs and over-privilege at deploy time, before CSPM has anything to scan.
Raised $29M Series A, June 2026
Los Altos, USA
Security control validation platform built around MITRE ATT&CK and purple-team testing.
Named among 2026 CTEM and BAS alternatives in independent vendor comparisons
Tel Aviv, Israel
Reachability-aware AppSec now aimed at AI coding agents, IDEs, MCPs, and the packages they pull.
Raised $19M Series A led by KOMPAS VC, February 2026
Menlo Park, United States
Metadata lake DSPM that classifies petabyte estates in place, then governs AI access in plain language.
Raised $25M Series A led by Greylock, November 2025
New York, United States
Hybrid DSPM and data intelligence platform for discovery, privacy, and AI risk across cloud and on-prem.
First DSPM vendor to cross $100M in annual revenue, 2024
Montreal, Canada
Pipeline and package gates that block supply-chain junk before AI-written code swallows it.
Raised $4M and acquired SecureIQx and Korbit.ai, May 2026
Ann Arbor, USA
Internet-wide map of exposed infrastructure used for ASM, threat hunting, and exposure management.
Raised $40M Series D plus $30M debt led by Morgan Stanley Expansion Capital, March 2026
Kirkland, USA
Zero-to-low CVE container images and language libraries rebuilt from verified source.
Closed $280M growth round from General Catalyst at a $3.5B valuation, October 2025
Belfast, United Kingdom
Universal artifact control plane for what AI and humans actually put into production.
Raised $72M Series C led by TCV and Insight Partners, April 2026
New York, USA
Design-led product security agents that review PRDs, architecture, and specs before code exists.
Emerged from stealth with $36M seed and Series A, November 2025
Tel Aviv, Israel
Zero Trust for non-human identities: discover the secret, then make stolen static credentials useless.
Raised $20M Series A led by SignalFire, January 2025
Augusta, USA
Browser-native SSE that gives zero-trust access without a VPN, VDI, or backhauled proxy.
Raised $26M Series B led by Two Bear Capital, October 2025
San Mateo, United States
Semantic DSPM that labels unstructured data by meaning, then remediates oversharing on-prem and in the cloud.
Raised $45M Series B led by Top Tier Capital and HarbourVest, October 2024
San Francisco, United States
AI-native identity platform that folds IGA, IAM, and PAM into one access control plane.
Raised $79M Series B led by Greycroft, October 2025
Dallas, USA
MSSP-first agentic SOC that wires intel, hunting, detections, investigation, and response into one loop.
Raised $25M Series A led by SYN Ventures, January 2025
Los Altos, United States
IAST, RASP, and ADR that instrument the running app so exploits are seen in the code path, not the packet.
Published the Software Under Siege 2025 report on application-layer attacks, August 2025
San Francisco, USA
AI SAST that hunts broken auth and business-logic bugs, then writes a patch developers can merge.
Raised $2.6M seed led by Shorooq, with Y Combinator participating, November 2024
Washington, United States
Machine identity provider for operational technology, factories, and defense networks that still run API keys.
Raised $18M Series A-1 led by SineWave Ventures, April 2025
Palo Alto, United States
Data detection and response that traces lineage as files move, transform, and hit AI tools.
Raised $100M Series D at a $1B valuation, April 2025
New York, USA
ASPM with its own SAST, SCA, and pipeline scanners, plus a graph for AI-written code.
Named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security, June 2026
Palo Alto, United States
Seedless external attack-surface discovery that finds cloud, subsidiary, and third-party assets attackers can actually reach.
Named a Leader and Outperformer in the 2026 GigaOm Radar for Attack Surface Management
New York, United States
AI-native DSPM that classifies sensitive data, then governs what people and agents can do with it.
Raised $600M Series G at a $12B valuation, June 2026
Tel Aviv, Israel
BAS-born exposure validation that now pushes findings into automated control updates.
Shipped Vero AI for agentic cyber defense engineering on the live platform, 2026
Boston, USA
All-in-one XDR agent for teams that cannot staff a SOC or buy seven point products.
Named Leader and Outperformer in the 2026 GigaOm Radar for XDR
Palo Alto, United States
SPIFFE-based non-human IAM that replaces static secrets with short-lived workload identities.
Raised $30.75M Series B led by XYZ Ventures, October 2025
Los Altos, United States
Customer identity workflows that let product teams ship login, MFA, and agent auth without an IAM rebuild.
Closed $35M seed extension, $88M total, September 2025
Stockholm, Sweden
Hacker-powered surface monitoring for domains, apps, and APIs, now with an MCP server for AI workflows.
Launched a Detectify MCP server for AI security workflows, 2026
New York, United States
SaaS data security that watches sharing in Google Workspace, Slack, and Box, then revokes it automatically.
Launched Dot, an AI SaaS data security assistant, June 2025
San Francisco, United States
Developer-first secrets platform that syncs env vars, rotates them, and logs who changed what.
Launched Change Requests for approved secret edits, October 2024
Seattle, USA
Software-only AI SOC analyst that investigates alerts without a managed service attached.
Raised $37M Series B led by Theory Ventures, July 2025
Los Angeles, United States
Self-serve DMARC, SPF, and DKIM platform for teams that need enforcement without a mail consultant.
Raised $20M Series A led by Radian Capital, September 2024
Palo Alto, USA
Reachability-first AppSec: SAST and SCA that only page you when the vulnerable function is actually called.
Raised $93M Series B led by DFJ Growth, April 2025
Paris, France
AI pentesting for APIs and web apps that proves exploitability, including IDOR and business logic, not just crawler noise.
Raised $18M to expand agentic pentesting for APIs and business logic, March 2026
San Jose, USA
Real-time knowledge graph plus Exabot agents that investigate and stop attacks as they happen.
Raised $125M Series B at a $725M valuation, May 2026
Herndon, USA
Vendor-agnostic MDR that works on the SIEM and EDR you already bought.
Launched MDR coverage for the full AI attack surface, August 2026
Columbus, USA
Product and firmware SBOM platform for the devices you buy and the binaries you did not compile.
Won Cybersecurity Stars award for firmware security leadership, June 2026
San Francisco, USA
Open-source osquery control plane for Mac, Windows, Linux, and phones, cloud or self-hosted.
Raised $27M Series B led by Ten Eleven Ventures, June 2025
Santa Clara, United States
Confidential computing and key management so data stays encrypted while AI and apps use it.
Joined Cisco Secure AI Factory with NVIDIA for Confidential AI inference, June 2026
Paris, France
Secrets detection plus NHI lifecycle, from leaked keys in git to the agents still using them.
Raised $50M Series C led by Insight Partners, February 2026
Pittsburgh, USA
Frontier-lab red teaming (Shade) and runtime defense (Cygnal) trained on unpublished attacks.
Raised $40M Series A co-led by Wing and Madrona, May 2026
Tel Aviv, Israel
Consumer browser protection that treats everyday users like they deserve an enterprise SOC.
Raised $80M Series B led by ION Crossover Partners, November 2025
Amsterdam, Netherlands
Outside-in autonomous hacker that discovers, exploits, and validates external exposure continuously.
Shipped Sense, Plan, Attack AI agents to operationalize CTEM, November 2025
Paris, France
ANSSI-certified French EDR for buyers who cannot put a US cloud agent on sensitive endpoints.
Added Attack Surface Management to its endpoint platform, September 2025
Austin, USA
Model scanner, attack simulation, and runtime firewall for agentic, generative, and predictive AI.
Selected to support the US DOE Prometheus initiative under the Genesis Mission, August 2026
San Francisco, USA
NodeZero autonomous pentest that exploits live networks the way an attacker would, continuously.
Raised $250M Series E at a $2B-plus valuation, August 2026
Columbia, USA
Managed EDR, identity, and SIEM for businesses that do not run a 24/7 SOC.
Surpassed $250M ARR and 270,000 businesses protected, July 2026
San Francisco, United States
Open-source secrets manager you can self-host or run as SaaS, now adding agent-safe credential proxying.
Raised $16M Series A led by Elad Gil, June 2025
New York, USA
Forensic-grade AI SOC that investigates 100% of alerts, including the low-severity ones MDR skips.
Expanded AI SOC platform for teams outgrowing MDR, March 2026
Tel Aviv, Israel
External attack-surface platform that discovers cloud, subsidiary, and supply-chain assets, then validates which exposures are actually exploitable.
Added $15M to Series A, bringing total funding to $50.3M, February 2024
Atlanta, United States
AI email security that mixes automated remediation with a network of admin-reported phishing.
Launched Winter 2026 agentic release with Red Teaming, Phishing SOC, and Simulation agents, March 2026
Dallas, United States
Enterprise browser that embeds DLP, ZTNA, and last-mile control into Chromium instead of another VDI farm.
Raised $250M Series E at a $4.8B valuation, March 2025
Louisville, United States
Cloud directory that binds workforce identity, devices, and access without living on Active Directory.
Acquired Breez to add identity threat detection, October 2025
Austin, USA
Browser detection and response that watches behavior inside existing Chrome and Edge sessions.
Published The State of Browser Security Report 2026 from production telemetry
Tel Aviv, Israel
Need-to-know access control so Copilots, coding agents, and MCP tools stop oversharing.
Raised $11M to ship need-to-know controls for enterprise AI, March 2025
Tel Aviv, Israel
Runtime-backed AppSec that proves a CVE is loaded in memory before it hits the backlog.
Published Rapyd case study showing runtime-led AppSec without extra headcount, July 2025
Tel Aviv, Israel
Discovery, posture, automated red team, and gateway runtime for models and agents.
Published Securing Agentic AI: The Intent Security Framework, March 2026
Tel Aviv, Israel
AI-native ASPM that discovers the software factory, then VibeGuard blocks bad AI code in the IDE.
Shipped VibeGuard to secure AI-generated code at the developer endpoint, 2026
San Francisco, United States
Runtime API and AI security with eBPF visibility, agentless discovery, and inline protection that stays off the data path for privacy.
Shipped Launch Week 2026 with AI Firewall, AI Gateway, and MCP discovery and testing, February 2026
Santa Clara, USA
AI-driven lineage of every component, including the ones hiding in firmware and public-sector stacks.
Raised $20M Series A co-led by Prosperity7, Neotribe, and Hitachi, July 2024
San Francisco, United States
Autonomous IGA that reviews, provisions, and rightsizes access for people, NHIs, and AI agents.
Launched Identity Agent Force to govern human, NHI, and AI access, June 2026
Washington, USA
SBOM and AIBOM intelligence so you can actually use the bills of materials you generate.
Raised $15M Series A led by Ensemble VC, April 2025
San Francisco, United States
Workspace security for Google and Microsoft 365 that assumes the mailbox will get owned and limits the blast.
Published original analysis of the May 2026 Composio Gmail OAuth token breach, June 2026
Seattle, United States
AI-native DLP and insider risk that classifies, then blocks exfil at the endpoint without a policy farm.
Raised $30M Series A seven months after stealth, June 2025
London, United Kingdom
Attacker-style recon and automated red team for models, agents, IDEs, and the systems around them.
Raised $30M Series A led by Album VC, August 2026
New York, United States
Cloud, SaaS, identity, and AI detection and response with a forensic lake built for attacks that never touch an endpoint agent.
Raised $30M Series B led by SYN Ventures, January 2025
Austin, USA
Firmware and binary SBOM that unpacks what vendors actually shipped, not what the datasheet claimed.
Raised $10M Series A, taking total funding to about $25M, April 2025
San Francisco, United States
AI-native DLP for SaaS, endpoints, browsers, and GenAI prompts that learns from investigations.
Launched Nyx, an autonomous DLP copilot, July 2025
New York, USA
AI-SPM, agent access control, red team, and AI-DR in one control plane for homegrown and SaaS agents.
Raised $100M Series B led by Evolution Equity Partners, July 2025
Palo Alto, United States
SaaS identity and agent governance inside the third-party apps where work actually happens.
Raised $85M Series D at $1.1B valuation, August 2026
Tel Aviv, Israel
Application detection and response that watches live code execution and blocks exploits as they run.
Raised $60M, crossing $140M in total funding, August 2026
New York, United States
Policy-as-code access control plane for employees, service accounts, and AI agents.
Raised $23M and hired a new product bench, June 2026
Portland, United States
Agentless CNAPP that SideScans cloud disks and APIs for the full estate without installing a workload agent.
Named a Strong Performer in The Forrester Wave: Cloud Native Application Protection Solutions, Q1 2026
New York, USA
Prompt-to-runtime AppSec that tries to show only the 5 percent of findings that can actually breach you.
Raised $60M Series B led by DTCP, taking total funding to $94M, May 2025
San Francisco, United States
Cloud IGA and PAM that answers who or what can touch production, then enforces it at runtime.
Closed $15M Series A led by SYN Ventures, September 2024
Burlington, USA
Automated security validation that actually exploits attack paths inside the customer's network.
Raised $60M Series D led by Evolution Equity Partners, March 2025
San Francisco, USA
Breach-and-attack simulation plus autonomous pentest that scores whether controls actually stop the attack.
Raised $45M Series C to lead adversarial exposure validation, September 2024
Miami, USA
Inventory, agentic red team, and self-improving runtime guardrails for the agent lifecycle.
Named a 2026 Gartner Cool Vendor in AI Software Security
Baltimore, USA
Agentic AppSec that triages scanner noise and opens mergeable fix PRs in your house style.
Raised $15M seed led by Decibel and Wing VC, May 2025
Newark, United States
Fine-grained data access and AI governance from the team that built Apache Ranger.
Shipped major PAIG updates aligned to the NIST AI RMF, February 2025
Menlo Park, USA
Agentic SOC platform covering investigation, hunting, and detection engineering in one mesh.
Raised $30M Series A led by Accel, July 2025
Boston, United States
Browser-native ITDR that stops phishing, token theft, and account takeover where the session lives.
Raised $30M Series B led by Redpoint Ventures, April 2025
Paris, France
European agentic SOC that turns every alert investigation into posture insight.
Raised $30M co-led by Partech and Forgepoint Capital International, March 2026
San Francisco, United States
Behavioral runtime CDR for Kubernetes and AI workloads, fingerprinting what a cluster should do so zero-days show up as drift.
Raised $14M Series A, February 2025
New York, United States
SaaS and agent security that maps every app, identity, and AI connector, then remediates the risky ones.
Raised $30M Series B, total funding $85M, February 2026
London, United Kingdom
Email authentication and brand protection that gets domains to DMARC enforcement without a DNS circus.
Won a 2025 Cybersecurity Excellence Award for OnDMARC, March 2025
San Francisco, United States
Data-flow DSPM that shows how customer data actually moves through products, vendors, and AI features.
Raised $32.1M Series B led by Thomvest Ventures, October 2024
New York, USA
MCP gateway plus identity, observability, and threat detection for enterprise agents.
Emerged from stealth with $11M seed from Khosla (Keith Rabois) and Felicis, November 2025
Palo Alto, USA
Cyber risk quantification platform that added an agentic CTEM loop on top of CRQ and TPRM.
Raised $70M Series C and launched a fully autonomous CTEM offering, July 2025
Palo Alto, United States
Runtime API security that discovers shadow and zombie APIs, then spots business-logic abuse in live traffic.
Published a year of monthly API and AI security releases, December 2025
Tel Aviv, Israel
Backports security patches onto the exact open-source versions you already run, including EOL.
Raised $13M Series A led by Vertex Israel, July 2025
San Francisco, USA
Rules-plus-AI SAST, SCA, and secrets that developers run in seconds and AppSec can actually tune.
Raised $100M Series D led by Menlo Ventures, February 2025
Hoboken, United States
Identity threat detection and forest recovery for Active Directory, Entra ID, and Okta.
Secured $125M growth financing at a $1B+ valuation, June 2024
New York, United States
Cloud-native DSPM that discovers, classifies, and readies enterprise data for AI without agents.
Closed $50M Series B, bringing total funding over $100M, April 2025
Plano, United States
Runtime identity protection that puts MFA and least privilege on systems IAM vendors leave naked.
Acquired Fabrix Security for autonomous runtime identity security, April 2026
Mountain View, USA
Self-improving AI SOC that unifies defense, hunting, and offense on one agent family.
Named to the CB Insights AI 100, May 2026, after 15x customer growth in 2025
Columbia, USA
Internet-scale IPv4/IPv6 discovery that maps what an attacker can actually see of you.
Launched new product capabilities for AI-driven attack-surface change, December 2025
Tel Aviv, Israel
AI purple team that replays CNAPP and SIEM findings against a digital twin to prove which cloud CVEs are actually weaponizable.
Named a CRN 2025 Stellar Startup for the third consecutive year, November 2025
San Francisco, United States
Private CA and device identity so internal TLS, SSH, and laptops get short-lived certificates instead of passwords.
Published hardware-bound device identity essay, May 2026
Boston, USA
Developer-first SAST, SCA, container, and IaC platform now wrapping AI agents and models too.
Launched Evo Agentic Development Security to govern coding agents, June 2026
San Francisco, USA
Behavioral SCA that blocks malicious packages at install time, before a CVE exists.
Raised $60M Series C at a $1B valuation led by Thrive Capital, May 2026
New York, United States
Cloud permissions firewall that enforces least privilege on humans, machines, and AI identities using native AWS, Azure, and GCP controls.
Reported 4x ARR growth as Cloud Permissions Firewall adoption surged, January 2026
Denver, United States
Developer-first API DAST that runs in CI so AI-generated endpoints get tested before they ship.
Raised $12M strategic round from Sapphire and Costanoa, total $47.3M, May 2025
Mountain View, USA
Discover, adversarially test, and kill-switch AI agents and MCP connections in production.
Raised $64M Series A, taking total funding to $85M, June 2026
Tel Aviv, Israel
Cloud detection and response on a live CloudTwin of every workload, identity, and network path.
Raised $30M Series B, October 2024
Washington, United States
Agentic email security with open detection rules and AI that writes new coverage in hours.
Raised $150M Series C led by Georgian, October 2025
Tel Aviv, Israel
Runtime CNAPP that watches cloud and AI agents as they act, then turns the finding into a guardrail.
Raised $75M Series B, November 2025
San Francisco, United States
Runtime CNAPP built on kernel-level system calls, Falco detections, and AI agents that act inside the tools you already run.
Named a Leader in The Forrester Wave: Cloud Native Application Protection Solutions, Q1 2026
Sammamish, United States
Human-plus-AI cloud remediation that closes CNAPP findings without breaking the workload that owns them.
Raised $12M Series A, September 2024
Oakland, United States
Infrastructure identity for SSH, Kubernetes, databases, and MCP servers without standing secrets.
Launched Beams trusted runtimes for AI agents, March 2026
New York, United States
Agentic data security that classifies with business context and remediates without a ticket queue.
Raised $25M Series A led by M13, total funding $32.2M, November 2025
Sarasota, USA
AI-native MDR that triages every alert in under a minute, with humans on the loop.
Raised $250M Series B led by Crosspoint, March 2026
Tel Aviv, Israel
Agentic pentest platform with a human in the loop across web, API, network, and AI surfaces.
Raised $8M (Q2 2025) to scale agentic continuous pentesting
Orlando, USA
Default-deny allowlisting that stops unapproved software and AI agents from running at all.
Raised $190M Series F led by Elephant, July 2026
San Francisco, United States
Calico-powered Kubernetes network security and microsegmentation, plus Lynx for governing AI agent calls on the cluster.
Shipped the Winter 2026 Calico Cloud release with an AI assistant and multi-cluster traffic observability, March 2026
Dublin, Ireland
Workflow automation that security teams actually own, now with agentic AI on top.
Raised $125M Series C at a $1.13B valuation, February 2025
Tel Aviv, Israel
Machine-first identity security that finds every NHI, names an owner, and cuts leftover privilege.
Named to Rising in Cyber 2026 after a $20M Series A, May 2026
Tel Aviv, Israel
Hyperautomation platform turning SOAR playbooks into an agentic SOC.
Raised $140M Series D at a $1.2B valuation, January 2026
San Francisco, United States
Verified secret scanning that proves a leaked key still works, then helps you kill it.
Raised $25M Series B led by Intel Capital and a16z, November 2025
Berlin, Germany
Agentless identity fabric for human, machine, and AI identities across hybrid cloud and on-prem.
Raised $5M seed led by VentureFriends and DFF Ventures, April 2025
San Francisco, United States
Runtime-first CNAPP that ranks cloud risk from what is actually running, not from a static CVE dump.
Raised $250M Series B at a $1.5B valuation, January 2026
Los Gatos, United States
Access graph that shows what every identity can actually do, not just which group it sits in.
Raised $108M Series D at $808M valuation, April 2025
New York, USA
Vulnerability remediation that actually patches, not another scanner that files tickets.
Named in Forrester's Q1 2026 Proactive Security Platforms Landscape
Menlo Park, USA
Continuous trust tests so enterprise agents stay reliable after they leave the lab.
Raised $17M Series A led by BrightMind Partners, November 2025
San Francisco, United States
Inline API and agent security that blocks abuse in real time instead of paging after the request lands.
Raised $55M Series C led by Toba Capital, July 2025
Mountain View, USA
Observe, control, and protect employees, models, apps, and agents from one AI security plane.
Raised $58M led by Sound Ventures, January 2026
San Francisco, United States
Enterprise identity APIs so product companies can ship SSO, SCIM, and audit without becoming an IAM vendor.
Raised $100M Series C at $2B valuation, March 2026
Tel Aviv, Israel
Hybrid attack-path graph that shows how an identity, cloud, or on-prem foothold becomes a breach.
Named a Challenger in the first Gartner Magic Quadrant for Exposure Assessment Platforms, 2025
Pamplona, Spain
SCA plus malware and pipeline security for teams whose code is increasingly written by agents.
Won Global Infosec awards for ASPM and GenAI application security, 2026
New York, USA
CTEM that proves which CVEs are exploitable, then mitigates with the controls you already own.
Raised $60M Series C led by Menlo Ventures, December 2025
New York, USA
Agent security that watches the decision, not just the prompt, across SaaS, cloud, and endpoint.
Raised $125M Series C led by Norwest, August 2026
San Francisco, USA
AI-native SAST for business logic, auth bypasses, and chained exploit paths, with generated patches.
Named an RSAC 2026 Innovation Sandbox Top 10 finalist