ARMO gave away a Kubernetes scanner, watched 40,000 companies download it, then built a runtime-security business on top. This is the story of the open-source Trojan horse - and the eBPF sensor that made it work.
The Boston startup began by trimming Docker images. Its sharper insight was that security teams did not need another list of vulnerabilities - they needed tested fixes that could arrive without an upgrade, a rebuild marathon or a ruined sprint.
BellSoft built a business around the part of Java most companies would rather not think about. Its pitch is simple: one engineering team for the runtime, the Linux layer and the container - with fewer licensing surprises and fewer vulnerabilities to chase.
Aqua Security is a cloud native security company founded in 2015 that helps enterprises protect containerized and cloud native applications from development to production. Its Aqua Platform is a Cloud Native Application Protection Platform (CNAPP) that combines agent and agentless technology to scan code and images, enforce policies, manage cloud posture, and stop attacks at runtime. Aqua is also the creator of Trivy, the widely adopted open source vulnerability and misconfiguration scanner. Headquartered in Boston and Ramat Gan, Israel, the company protects more than 500 large enterprises and has raised $325M in total funding at a valuation above $1 billion.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
OX Security is an application security company that built an Active Application Security Posture Management (ASPM) platform to give development and security teams a single, code-to-cloud view of software risk. Founded in 2021 by Check Point veterans Neatsun Ziv and Lior Arzi, OX consolidates scanning across the software development lifecycle - from source code and open-source dependencies to CI/CD pipelines and cloud - then uses context and attack-path analysis to surface the roughly 5% of vulnerabilities that are actually exploitable and reachable, so teams stop drowning in alerts. The company raised a $60M Series B in May 2025 (total funding around $94-101M) with backing from DTCP, IBM, Microsoft's M12, Evolution Equity, Team8 and others.
FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.
Sonatype is the software supply chain management company behind Nexus Repository and the maintainer of Maven Central, the world's largest repository of open source Java components. Founded in 2008 by core contributors to Apache Maven, it helps developers and enterprises find, manage, and secure the open source code that powers modern software - blocking malicious packages, enforcing policy, and generating software bills of materials (SBOMs) across the development lifecycle.
RapidFort is a Sunnyvale-based software supply chain security company that automatically hardens container images, strips unused components, and ships a library of curated near-zero-CVE images so engineering teams can ship secure software without rewriting it.
Tigera is the creator of Calico, the open-source standard for Kubernetes networking and security that powers more than a million clusters every day. From its San Jose headquarters, the company sells Calico Cloud and Calico Enterprise - SaaS and on-prem platforms that bolt active runtime security, zero-trust microsegmentation, and observability onto container environments at any scale.