Imagine a smoke alarm that rings every time somebody makes toast. At first, everyone investigates. Eventually, someone removes the battery. A software security scanner can acquire the same reputation: technically vigilant, socially irrelevant. Cycode’s business begins in that uncomfortable space between a finding that exists and a finding somebody believes enough to fix.
- Cycode connects code scanning, supply chain protection and security priorities.
- Its graph adds ownership and deployment context to individual findings.
- AI agents investigate and propose repairs; useful results still depend on trustworthy inputs and review.
The company sells to enterprises whose software crosses repositories, build systems and cloud environments. For a security team, the appeal is practical: see where a risky component lives, identify its owner, and decide what deserves attention. For developers, the attraction is less ceremony between receiving a warning and understanding what to change. A beautiful dashboard has limited charm when its next instruction is “please investigate.”
The code was only the beginning
Cycode’s first problem was narrower. In 2019, its seed investor YL Ventures described a business protecting proprietary source code against theft, leakage and tampering. Distributed development had scattered valuable code across people and repositories. The company connected to source control systems to make that estate visible. A $4.6 million seed round financed the opening move.
By May 2021, the perimeter had expanded to development pipelines. Cycode announced a knowledge graph connecting assets and activity across software delivery, alongside a $20 million Series A. A $56 million Series B followed that November. The three disclosed rounds add up to $80.6 million, commonly rounded to $81 million. Insight Partners and YL Ventures backed the expansion.

“With each new integration, our knowledge graph becomes smarter,” CEO Lior Levy said in the Series B announcement. That sentence explains the product’s direction better than the category acronyms. A repository alone tells one story. Connect it to the build, the deployed application and the person responsible, and the same weakness acquires a different meaning.
A map with consequences
Today the company combines application security testing, software supply chain protection and Application Security Posture Management, or ASPM. The testing suite covers application code, third-party dependencies, secrets, containers and infrastructure definitions. Supply chain controls look at the machinery that builds and ships software. Posture management organizes the findings into priorities and workflows. Buyers can purchase separate plans or the Complete bundle.
The distinguishing proposition is the shared map underneath. In January 2026, Cycode introduced its Context Intelligence Graph, evolving the earlier Risk Intelligence Graph. It adds records of decisions and outcomes to relationships across the development estate. IDC’s analysis describes five dimensions: time, causation, meaning, attribution and outcome. The ambition is institutional memory: preserve why an exception was approved, who approved it and what followed.
That matters because a vulnerability’s severity label cannot answer every operational question. Is the affected function used? Is the application exposed? Which team can change it? Cycode seeks to bring those questions into the same investigation. Its native scanners can also sit alongside findings from existing tools, giving enterprises a route to consolidation that can start before every old contract expires.
The scanner nobody trusted
Solaris, the German embedded finance company, supplies a revealing example. Its homegrown MetaScan combined commercial and open-source scanners. Coverage gaps, maintenance demands and unreliable alerts eroded developer trust. Blanket security policies sent teams chasing low-risk issues while more consequential findings waited.
Solaris chose Cycode for broad coverage, integration and deployment flexibility. Adoption still required infrastructure troubleshooting and developer education. After two years on-premises, it moved to SaaS, a change the customer case study attributes partly to accumulated trust. Reported results include a 61% reduction in repair time for high-risk issues and triage falling from 3.1 days to under an hour. These are one customer’s results, achieved alongside changes to people and process.
The machines join the meeting
Cycode’s March 2024 acquisition of Bearer added static code analysis, API discovery and data leak protection technology. The move broadened what the company could detect itself. The acquisition announcement tied those capabilities to contextual remediation and developer workflows. It was a concrete purchase in service of a larger platform, rather than another name for the same dashboard.
In March 2026, Cycode introduced Maestro in early access after a closed beta. Maestro coordinates agents that query the graph, analyze exploitability and generate fixes. A question about exposure can become a sequence of tasks, rather than a hunt through separate screens. Cycode’s demonstration shows orchestration around the vulnerability lifecycle; generated changes still deserve the scrutiny of ordinary code changes.
“Cycode is my cheat sheet for security”Matt Domko, Head of Security, on Cycode’s customer page
May brought generally available Agentic Development Lifecycle Security, covering the AI tools and agents participating in development. Visibility, governance and guardrails extend the perimeter to prompts and AI-generated outputs. July’s bulk exploitability analysis addressed another practical bottleneck: investigating many findings without opening a separate inquiry for each one.
Buy the connection, test the repair
Cycode competes for budgets also pursued by Snyk, Checkmarx, Veracode and GitHub Advanced Security. Its case rests on combining native detection, third-party ingestion and development context. A buyer should test that combination against real repositories and existing workflows. The relevant comparison is how many consequential issues reach a responsible developer with a usable repair.
Commercially, current quotes depend on active developer count and AI usage. That makes the evaluation partly an exercise in workload planning: how often will agents analyze findings, and which jobs need them? Teams with simpler estates may find less value in a broad platform. Incomplete integrations, stale ownership and unreviewed automated fixes weaken the very connections Cycode sells.
The copyable lesson is modest: attach findings to owners, examine production exposure, and measure the time to a reviewed repair. Cycode’s partnerships with HackerOne and Immersive add validated bug reports and targeted training to that loop. Security becomes more useful when the warning arrives with enough context to earn a response. Even the finest alarm needs somebody willing to leave the kitchen.