BitPatrol is an AI-powered code security company that scans source code on every commit to catch exposed secrets - API keys, database passwords, and auth tokens - the moment they are pushed. Founded by former Stripe engineer and top-2% HackerOne researcher Christopher Lambert, it replaces legacy regex scanners with a proprietary machine-learning model that reads code context and cross-references billions of public commits to cut false positives. Part of Y Combinator's Spring 2025 (X25) batch, the company was acquired in 2025.
Onapsis is a Boston-based cybersecurity company that secures business-critical applications - the SAP, Oracle and SaaS ERP systems that run the world's largest enterprises. Founded in 2009 by a team of ethical hackers, Onapsis combines a platform for assessing, defending and controlling ERP application-layer security with the threat research of Onapsis Research Labs, which regularly discovers SAP zero-day vulnerabilities and works directly with SAP and CISA. It is the only SAP security and compliance platform certified as a Premium Certified SAP Endorsed App.
Contrast Security is a Pleasanton, California-based cybersecurity company that secures software from the inside out. Founded in 2014 by OWASP veterans Jeff Williams and Arshan Dabirsiaghi, it pioneered an instrumentation-based approach that embeds security sensors directly into running applications to detect vulnerabilities and block live attacks in real time. Its runtime security platform spans Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), static analysis (SAST), software composition analysis (SCA), and Application Detection and Response (ADR), serving Fortune 500 enterprises and government agencies.
depthfirst is a San Francisco applied AI lab building an AI-native security platform that detects, triages and remediates software vulnerabilities before attackers can exploit them. Its 'General Security Intelligence' uses custom AI agents and purpose-trained security models to read a company's code, business logic and infrastructure, surfacing more true-positive vulnerabilities while cutting false positives and delivering developer-ready fixes. Founded in 2024 by leaders from Databricks, Google DeepMind and Faire, the company raised $120M across Series A and B within a few months of leaving stealth.
Semgrep is a San Francisco application-security company that builds a unified AppSec platform (Code/SAST, Supply Chain/SCA, and Secrets) used by engineering teams at Dropbox, Figma, Snowflake and others. Born out of an open-source tool originally written at Facebook, it lets security teams write code-like rules and ship them through CI - cutting false positives and pushing fixes back to developers.

Isaac Evans is the Founder and CEO of Semgrep, the developer-first application security platform that has redefined how modern engineering teams handle code security. An MIT-trained computer scientist with a background in U.S. Department of Defense security research, Evans co-founded Semgrep in 2017 with college roommates Drew Dennison and Luke O'Malley. Under his leadership, Semgrep grew from a niche static analysis tool into a platform scanning 75+ million code repositories annually, serving customers like Figma, Dropbox, Slack, and Snowflake. In February 2025, the company closed a $100M Series D led by Menlo Ventures, bringing total funding to $193M. Evans's core thesis - that security must serve developers, not obstruct them - has made Semgrep a defining force in the AppSec category.