Most security tools inspect the code developers write. Appknox follows the app that users actually touch - from compiled binary and real-device behavior to the moment a counterfeit copy appears in an app store.
MindFort is a San Francisco AI security lab building autonomous agents that continuously find, validate, and patch vulnerabilities in web applications and APIs. Founded out of Y Combinator's X25 batch by offensive-security veterans, it runs like a 24/7 AI red team - proving exploits in isolated runtime environments before it reports them, then opening pull requests with the fix. The company raised a $3M+ seed led by Soma Capital in April 2026.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
Cobalt is the pioneer of Pentest as a Service (PtaaS), pairing a curated community of vetted offensive-security experts (the Cobalt Core) with a SaaS platform that turns penetration testing from a months-long procurement exercise into an on-demand, continuous program. Founded in 2013, the company now serves 1,500+ customers and is leaning hard into AI-augmented offensive security.