Somewhere in a large company, a scanner has found a dangerous line of code. That should be good news. Instead, it starts a small bureaucratic comedy: the repository has changed hands, the service may or may not run in production, a firewall may already blunt the threat, and the person assigned the ticket has never seen the application. The flaw is real. The route from finding it to fixing it is missing.
Apiiro, founded in 2019 by Idan Plotnik and Yonatan Eldar, makes software for that gap. Its application security platform connects source code to the architecture around it: packages, APIs, deployment context, business policies and the people responsible. The company calls this a Context Graph. To a security team, it is a way to distinguish a noisy list from a useful decision. To a developer, it can turn a vague alarm into a specific piece of work.
The short version
- Apiiro sells application security software to enterprise development and security teams.
- Its graph links code findings to runtime exposure, ownership and policy.
- Public customer stories from SoFi and Paddle report sharply shorter review and remediation work.
- Its newer Guardian Agent aims to steer AI coding tools before risky code reaches a repository.
A map is more useful than a pile
Conventional security tools inspect one thing at a time. A static analyzer examines code. A software composition tool watches dependencies. A cloud product observes running infrastructure. Each can be right and still leave the central question unanswered: which finding can hurt this business now? Apiiro’s answer is to connect these signals to the actual application and its owner. A library issue in an isolated experiment does not deserve the same response as a reachable vulnerability in a public payments endpoint.
This is the heart of its difference in a crowded market. Snyk, GitHub Advanced Security, Checkmarx and Veracode can find classes of software flaws. Other application security posture management vendors aggregate findings. Apiiro also performs its own deep code analysis, then ties that analysis to runtime and organizational context. Its pitch is less about producing one more alert and more about giving an existing alert a place in the story of the system.

The cost of finding the wrong person
The strongest evidence for the approach comes from customer workflows, not from a claim that all vulnerabilities disappear. SoFi says it used Apiiro to inventory its applications and trigger security reviews when material code changes met its risk policies. Its AppSec team reports that design reviews once taking hours fell to five to fifteen minutes. The average remediation ticket, it says, went from eight days to ten minutes after critical risks were tied to relevant code owners. Those are SoFi’s reported results, and their mechanism matters: less time locating the application, the reason for concern and the person who can act.
Paddle, the payments company, offers a second view. Its security team used Apiiro’s GitHub integration to map nearly 500 repositories. It says the platform now monitors more than 100 pull requests a week, flags the high-risk ones for further assessment and returns roughly two days of work each week to the team. The platform also gives developers the context to repair a change while they are still working on it. That is a better moment to ask for a fix than six weeks later, when everyone has moved on.
“The unique value that Apiiro provides Paddle is as a force multiplier.”Jonny Herd / VP of Information Security & Enterprise Technology, Paddle
These cases suggest a practical playbook a reader can borrow without buying anything: inventory the repositories; identify owners; define what counts as a material change; route only the changes that meet a risk policy to human review; and measure the time from finding to accepted fix. The method depends on trustworthy ownership data, useful integrations and policies narrow enough that teams do not learn to ignore them.

The coding agent enters the room
In 2025 Apiiro introduced AutoFix, an agent designed to propose changes using its code and runtime map. In 2026 it introduced Guardian Agent, which pushes the intervention earlier. The idea is to put a company’s security rules and architecture into the workflow of AI coding assistants, including through MCP and developer tools, so an unsafe pattern can be corrected before it is committed. Apiiro calls one part of this “Secure Prompt”: it enriches the instruction going to a coding agent with relevant constraints. AutoGovern handles policy guardrails; AutoManage follows risk through assignment, acceptance and evidence.
That move followed a change in the company’s own thesis. Its initial graph helped teams see and prioritize risks after a change. Apiiro says work with design partners showed that an AI fix needed a map of the actual software. From there, prevention became a plausible next step. The sequence is revealing: first learn what the software is, then make the agent useful. A generic code suggestion cannot know that a particular API handles regulated data or that an upstream control already resolves a scanner finding.
In a company-run proof of concept with a Fortune 500 healthcare codebase, Apiiro says Guardian’s prompt intervention prevented 80% of the identified risks in a ten-task comparison. It kept the model, repository and tasks the same, changing whether Guardian sat in the loop. That is a specific test on a specific codebase, useful as a demonstration rather than a promise for every team. The transferable lesson is to test any coding guardrail against your own architecture and count what it prevents, what it misses and what it slows.
The business of the handoff
Apiiro’s buyers are enterprises with many developers, many repositories and too few application security specialists. Public customer stories include SoFi, Paddle, Cloudera and Navan; its site also names large companies such as BlackRock, CVS and Walmart. It sells enterprise software through demos and contracts, with integrations and marketplace distribution. A buyer has to judge the platform against the labor it saves, the tooling it might consolidate and the risks it helps address. Its total reported funding reached $135 million after a $100 million Series B led by General Catalyst in 2022.
Partners extend the map. With Akamai, Apiiro connects runtime API findings to their source code, repository and owner. In August 2026 it joined Chainguard’s Athena coalition and offered AutoFix free to open-source maintainers. These moves fit the same theory: a vulnerability is not a useful unit of work until it reaches someone able to repair the code. Open-source maintainers and enterprise developers sit at different desks, but both can be buried by context-free reports.
Apiiro is hardly alone in selling security for software built at AI speed. Its case rests on whether its map stays current and whether its automation earns developer trust. The customer reports are promising because they measure work, not just detections. A security system should have something better to show for itself than a longer list of things to worry about. The best outcome is quieter: the right person gets a comprehensible change at the moment it can still be made.