A security alert is easy to produce and surprisingly hard to act on. Cycode has built its business around the missing connections between vulnerable code, the people who own it, and the software that actually runs.
A security scanner can find a flaw. Getting someone to fix it is another business entirely. Invicti has built its application security platform around the evidence that travels between the two.
Security tools are excellent at finding trouble. ArmorCode has built a business around the awkward next question: who is going to fix it?
The scanner found the flaw. The hard part was finding the person, the production path and the reason to act. Apiiro built its business around that missing context.
The 20-year-old AppSec company made its name finding vulnerable code. Its harder second act is making the findings useful before AI-assisted development turns every security queue into a landfill.
Legit Security is an AI-native Application Security Posture Management (ASPM) company that gives security teams a single platform to discover, prioritize, and remediate risk across the entire software development lifecycle - from a developer's IDE and AI coding assistant to production. Founded in 2020 by three veterans of Israel's elite cyber units, the company consolidates fragmented AppSec findings, cuts false positives with context and reachability analysis, scans for exposed secrets, and now governs AI-generated code before it ships. Legit serves large enterprises including Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, and ZoomInfo.
OX Security is an application security company that built an Active Application Security Posture Management (ASPM) platform to give development and security teams a single, code-to-cloud view of software risk. Founded in 2021 by Check Point veterans Neatsun Ziv and Lior Arzi, OX consolidates scanning across the software development lifecycle - from source code and open-source dependencies to CI/CD pipelines and cloud - then uses context and attack-path analysis to surface the roughly 5% of vulnerabilities that are actually exploitable and reachable, so teams stop drowning in alerts. The company raised a $60M Series B in May 2025 (total funding around $94-101M) with backing from DTCP, IBM, Microsoft's M12, Evolution Equity, Team8 and others.
Neatsun Ziv is the co-founder and CEO of OX Security, an application security posture management company he started in 2021 with fellow Check Point veteran Lior Arzi after the SolarWinds breach. OX raised a $60M Series B in May 2025, bringing total funding to about $101.5M, and pitches a platform that culls the roughly 5% of code and pipeline risks that developers actually need to fix. Before OX, Ziv ran Threat Prevention & Intelligence at Check Point, where his team helped coordinate responses to NotPetya, SolarWinds and other campaigns with Interpol and national CERTs.
Roni Fuchs is the co-founder and CEO of Legit Security, an application security posture management (ASPM) company protecting software supply chains for customers including Google, NYSE, Kraft Heinz and Palo Alto Networks. A Unit 8200 veteran who grew up in Jaffa, he founded Legit in 2020 with two IDF comrades after stints at Microsoft (via Aorato) and Checkmarx (via his prior startup Lumobit). Legit has raised roughly $80.5M through Series B.