A modern application is less a manuscript than a potluck. The company writes some of it. Open-source maintainers bring quite a lot. Vendors arrive with casseroles whose ingredients are politely described as proprietary. By the time the meal reaches production, everyone remembers inviting the database and nobody can say precisely which version of a tiny compression library came in through a friend of a friend.
Lineaje was founded to answer that impolite question. Javed Hasan and Anand Revashetti, two cybersecurity veterans who met at McAfee, started the company in 2021 and launched it publicly the following year. Their premise was that software security had become strangely satisfied with detection. A scanner found a weakness, generated a ticket and congratulated itself. The awkward business of locating the dependency, choosing a compatible upgrade, rebuilding the application and proving that nothing else broke belonged to someone downstream.
The short version
- Lineaje maps what software contains, where each component came from and whether it changed along the way.
- It sells to enterprise security, engineering, procurement and compliance teams, with particular attention to finance, technology and government.
- Its distinction is the loop: discover, contextualize, repair, verify and preserve the evidence.
- The useful bit to copy is human-gated automation - prepare the fix and the proof, then ask a person to approve it.
First came the list. Then came the argument.
The basic artifact is an SBOM, a software bill of materials. Think of it as an ingredient label for code: packages, versions and dependencies, ideally in a machine-readable format. SBOMs became a matter of procurement rather than taste after the United States government pushed software vendors toward stronger attestations. Lineaje's first product, SBOM360, did not merely print the label. It assessed what the label meant - vulnerabilities, license problems, dependency depth, provenance, maintainability and signs of tampering.
That distinction matters because the first thing that failed was the scanner-first workflow, not necessarily the scanner. A technically correct alert can still be operationally useless. A critical vulnerability may sit in unreachable code. A supposedly safe upgrade may break an application. A package bearing the right name may not match the source from which it claims to descend. Hasan and Revashetti's change of mind was to treat composition as lineage: what was sourced, what was built, what was shipped and what was deployed should form one chain of evidence.
“A bill of materials can name the ingredients. The consequential question is whether the kitchen can still serve dinner after one is replaced.”
The product became a small municipal government
Once Lineaje knew what was in the software, it found itself governing the traffic around it. SBOM360 Hub lets a producer publish an SBOM once, control who sees it and attach VEX, CSAF and attestation documents to the proper product version. The Third-Party Risk Manager sits on the buyer's side and evaluates vendor software. SCA360 scans source, build artifacts and containers, including inside a customer's own environment when the code cannot leave. Gold Open Source tries prevention: supply vetted packages and container images before a dubious component enters the factory.
Then came the BOMbots. The name sounds like a Saturday-morning repair crew, which is not entirely misleading. Lineaje AI uses specialized agents to search large SBOMs, score risks, check upgrade compatibility, generate a fix plan, create a branch, update a dependency file, open a Jira ticket and prepare a pull request. The company says the system can rebuild and validate a proposed change before asking a human to merge it. This is “self-healing” with an important asterisk: the human is still at the gate.
Catalog figures are company-reported. The Air Force award also appears in the federal SBIR award record.
Who pays for fewer tickets?
Lineaje is enterprise software, sold by quote rather than by a cheerful public price card. Its natural buyers sit where risk becomes paperwork: the CISO who needs a portfolio view, the developer who needs a change that passes tests, the procurement team evaluating a vendor, and the software producer answering a customer or federal agency's attestation request. Its disclosed financing is clearer than its pricing. A $7 million seed round led by Tenable Ventures was followed by a $20 million Series A in July 2024, bringing total funding to $27 million.
The investors help explain the go-to-market machinery. Carahsoft distributes Lineaje into the U.S. public sector. Wipro Ventures invested, and Wipro combines the platform with consulting and engineering services for global enterprises. Opsera connects Lineaje's security work to delivery pipelines. In 2025, an Air Force AFWERX Phase II award supplied up to $1.8 million for work on enriched SBOMs, vulnerability discovery, tamper detection and self-healing software. It is a customer-shaped laboratory with unusually little patience for unverifiable provenance.


A crowded market, with one useful obsession
Lineaje does not lack rivals. Endor Labs, OX Security, Chainguard, Sonatype, JFrog, Black Duck, Mend.io, Checkmarx, Kusari and others approach parts of the same territory. Some excel at developer-friendly composition analysis. Some provide hardened images. Some manage posture across an application estate. Gartner's first 2026 Magic Quadrant devoted to software supply-chain security listed Lineaje among 18 vendors and placed it in the Visionaries quadrant.
Its differentiator is breadth arranged around a single obsession: close the loop. Plenty of tools can find a CVE; Lineaje wants to tell whether it is reachable, whether the component is authentic, what replacement will remain compatible, whether the rebuild passes and what evidence should follow the software to its buyer. That makes the platform potentially attractive to a large, regulated organization and potentially excessive for a small team whose dependencies are few and whose build already has reliable automated updates.
Where Lineaje places its weight
The copyable idea is a modest one
A company need not buy Lineaje to borrow its best operating principle. Do not automate judgment and execution as one opaque gesture. Separate them. First build a trustworthy inventory. Then rank findings with context. Generate the smallest compatible change. Run the real build and tests. Preserve the before-and-after evidence. Put a person at the merge point. This pattern is useful well beyond cybersecurity because it makes automation inspectable.
The conditions matter. Automated repair weakens when tests are thin, build systems are irreproducible, internal packages have no provenance or application owners cannot agree on policy. A curated dependency can reduce one class of risk while adding dependence on the curator. Private, air-gapped and legacy systems demand careful deployment. And no platform can promise that “zero vulnerabilities” means zero unknown flaws. The practical goal is narrower and better: fewer exploitable weaknesses, shorter exposure and an evidence trail that survives an audit.
Now the ingredients can think
In March 2026, Lineaje extended the same model to agentic AI with UnifAI. Instead of stopping at packages and containers, it inventories models, agents, MCP servers, skills, tools and data connections. It can turn governance documents into policies and place guardrails into an AI workflow. The move is coherent: an autonomous agent is another opaque dependency, except this one can take actions. Software lineage becomes behavioral lineage.
That expansion also sharpens the test for Lineaje. The company began by arguing that partial visibility made old tools half-blind. It now has to avoid making the same mistake about AI systems whose behavior changes with context. Its answer remains the one it started with: know the ingredients, track the handoffs, make the repair reviewable. Security, in this telling, is not an alarm. It is custody.