Securing code from the keyboard to the cloud - and now the AI writing the code in between.
Every company today ships software, and every line of that software is potential attack surface. Legit Security was founded in 2020 on a blunt premise: the tools meant to secure that software had become part of the problem. Security teams were drowning in a dozen disconnected scanners, each firing alerts with no shared context - a game of whack-a-mole where fixing one issue surfaced three more. The three founders, Roni Fuchs, Liav Caspi, and Lior Barak, had lived that frustration from the inside, having led product and engineering at Checkmarx after serving together in the cyber-warfare division of the Israel Defense Forces.
Their answer was Application Security Posture Management, or ASPM: instead of another scanner, a platform that sits above them all - discovering every asset from a developer's laptop to production, unifying findings into a single view, and ranking risk by what is actually reachable and exploitable. The goal is not more alerts. It is fewer, better ones, with a clear path to remediation. Today that platform guards software at Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, and the New York Stock Exchange.
"When AI writes the code, Legit secures it."
The core AI-native platform: discovers assets, unifies findings across tools, prioritizes by risk and reachability, and orchestrates remediation across the SDLC.
Enterprise-grade, AI-powered scanning that detects, remediates, and prevents exposed secrets across Git history, build logs, and shared developer workspaces.
A dedicated dashboard for discovering and governing AI usage in development, including detection of risky or unsafe AI models in the pipeline.
Security governance for AI-generated code. Links into developers' AI IDEs to monitor coding agents, enforce secure-coding guardrails, and block vulnerabilities before they leave the IDE.
Surfaces AI-native security intelligence directly to developers and AI agents through the Model Context Protocol.
Legit has raised roughly $80.5M across three rounds, backed by Cyberstarts, Bessemer Venture Partners, TCV, and CRV.
Led product and business units at Checkmarx and Microsoft before co-founding Legit. Sets company strategy and vision.
Held product-management and engineering leadership roles; drives the technical architecture of the platform.
Engineering leadership veteran of Unit 8200 and Checkmarx; runs operations and delivery.
Legit sells B2B SaaS subscriptions to security and engineering teams at large, often regulated, enterprises. Named customers include:
Roni Fuchs, Liav Caspi, and Lior Barak found the company and raise a $3.5M seed round led by Cyberstarts.
Fresh capital to expand the code-to-cloud application security platform.
Total funding reaches $80.5M; the company lands on the Fortune Cyber 60 list.
Launches AI-powered secrets scanning, risky-AI-model detection, and the AI Security Command Center.
Releases VibeGuard to secure AI-generated code inside the IDE, and returns to the Fortune Cyber 60.
It provides an AI-native Application Security Posture Management (ASPM) platform that discovers, prioritizes, and remediates security risks across the whole software development lifecycle - from a developer's IDE to production.
It was founded in 2020 by Roni Fuchs (CEO), Liav Caspi (CTO), and Lior Barak (COO), who served together in Israel's military cyber units and previously led teams at Checkmarx.
About $80.5 million total: a $3.5M seed (2020), a $30M Series A (2022), and a $40M Series B led by CRV (2023).
Large enterprises including Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, ZoomInfo, and the New York Stock Exchange.
VibeGuard is Legit's 2025 product that secures AI-generated code at the moment of creation, monitoring AI coding agents inside the IDE and enforcing secure-coding guardrails before code ships.