Aqua Security is a cloud native security company founded in 2015 that helps enterprises protect containerized and cloud native applications from development to production. Its Aqua Platform is a Cloud Native Application Protection Platform (CNAPP) that combines agent and agentless technology to scan code and images, enforce policies, manage cloud posture, and stop attacks at runtime. Aqua is also the creator of Trivy, the widely adopted open source vulnerability and misconfiguration scanner. Headquartered in Boston and Ramat Gan, Israel, the company protects more than 500 large enterprises and has raised $325M in total funding at a valuation above $1 billion.
Business Technology Integrators (BTI) is a Washington, DC-based Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering secure IT solutions to U.S. federal agencies. BTI focuses on cybersecurity, cloud migration, digital transformation, and data modernization, backed by ISO certifications, CMMI Level 3, and CMMC Level 2, and delivers work through vehicles such as GSA MAS, OASIS+ SDVOSB, and NASA SEWP VI.

Cloudsmith is a Belfast-founded, cloud-native artifact management platform that gives engineering teams a single place to store, secure, and distribute software packages and containers across 30+ formats. It acts as a private, fully managed registry with built-in supply chain controls - vulnerability and malware scanning, policy enforcement, quarantine, and global distribution - increasingly positioned around governing the flood of code produced by AI coding agents.
Legit Security is an AI-native Application Security Posture Management (ASPM) company that gives security teams a single platform to discover, prioritize, and remediate risk across the entire software development lifecycle - from a developer's IDE and AI coding assistant to production. Founded in 2020 by three veterans of Israel's elite cyber units, the company consolidates fragmented AppSec findings, cuts false positives with context and reachability analysis, scans for exposed secrets, and now governs AI-generated code before it ships. Legit serves large enterprises including Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, and ZoomInfo.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
Onapsis is a Boston-based cybersecurity company that secures business-critical applications - the SAP, Oracle and SaaS ERP systems that run the world's largest enterprises. Founded in 2009 by a team of ethical hackers, Onapsis combines a platform for assessing, defending and controlling ERP application-layer security with the threat research of Onapsis Research Labs, which regularly discovers SAP zero-day vulnerabilities and works directly with SAP and CISA. It is the only SAP security and compliance platform certified as a Premium Certified SAP Endorsed App.
OX Security is an application security company that built an Active Application Security Posture Management (ASPM) platform to give development and security teams a single, code-to-cloud view of software risk. Founded in 2021 by Check Point veterans Neatsun Ziv and Lior Arzi, OX consolidates scanning across the software development lifecycle - from source code and open-source dependencies to CI/CD pipelines and cloud - then uses context and attack-path analysis to surface the roughly 5% of vulnerabilities that are actually exploitable and reachable, so teams stop drowning in alerts. The company raised a $60M Series B in May 2025 (total funding around $94-101M) with backing from DTCP, IBM, Microsoft's M12, Evolution Equity, Team8 and others.
Glenn Weinstein is the CEO of Cloudsmith, the cloud-native software supply chain platform headquartered in Belfast, Northern Ireland. A U.S. Naval Academy graduate and former naval flight officer who learned to code on a Commodore 64, he co-founded the cloud consultancy Appirio (sold to Wipro for $500M) and spent four years as Chief Customer Officer at Twilio before relocating from New York to Belfast in 2023 to lead Cloudsmith. Under his leadership Cloudsmith raised a $72M Series C in April 2026, positioning the company to secure software supply chains in the age of AI coding agents.
On July 9, 2026, IBM unveiled major enhancements to IBM Bob, its agentic software development platform. The updates introduce multi-agent coordination across the full software development lifecycle, model-native parallel tool calling, subagents for context management, cost-and-productivity visibility via Bobalytics, and pre-built premium modernization workflows for IBM Z (COBOL/PL/I), IBM i (RPG), and Java (migration to Java 25). The release responds to a shift in enterprise bottlenecks from code generation to code review and validation, aiming to help teams ship production-ready software faster while optimizing the total cost of AI-driven development.
CivicActions is a fully remote digital services firm that helps U.S. federal, state, and local government agencies modernize the technology behind public services. Founded in 2004 by Henry Poole and Aaron Pava, the company pairs free and open-source software - especially Drupal - with agile delivery, DevSecOps, human-centered design, and accessibility expertise to rebuild legacy government websites and platforms. Guided by the values of Balance, Openness, and Care, CivicActions has served agencies including Veterans Affairs, the FCC, the National Science Foundation, and the State of Georgia while contributing heavily back to the open-source communities its work depends on.
Contrast Security is a Pleasanton, California-based cybersecurity company that secures software from the inside out. Founded in 2014 by OWASP veterans Jeff Williams and Arshan Dabirsiaghi, it pioneered an instrumentation-based approach that embeds security sensors directly into running applications to detect vulnerabilities and block live attacks in real time. Its runtime security platform spans Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), static analysis (SAST), software composition analysis (SCA), and Application Detection and Response (ADR), serving Fortune 500 enterprises and government agencies.
FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.
AutoRABIT is an enterprise DevSecOps and release-management platform built for the Salesforce ecosystem. It combines CI/CD automation (ARM), static code and security analysis (CodeScan), data and metadata backup and recovery (Vault), and security posture management (Guard) so teams in regulated industries - banking, financial services, healthcare, and government - can ship Salesforce changes quickly while keeping security and compliance intact. Founded in 2015 and bootstrapped for its first five years, the company is headquartered in San Francisco and serves customers including ABN AMRO, Cigna, and CyberArk.
BlueFlag Security is a Sunnyvale, California cybersecurity company building an identity-centric security and governance platform for the software development lifecycle (SDLC). Rather than scanning code for vulnerabilities, BlueFlag watches the identities and tools behind the code - developers, service accounts, bots, and increasingly the AI coding assistants and autonomous agents that now write, test, and deploy software. Founded in 2024 by former CloudKnox and Symantec operators Raj Mallempati and Ken Schneider, the company applies AI/ML-based 'Identity Intelligence' to detect risky behavior, enforce least privilege, and govern AI agents across CI/CD pipelines. In March 2026 it announced a $28 million Series A and 300% year-over-year revenue growth.
depthfirst is a San Francisco applied AI lab building an AI-native security platform that detects, triages and remediates software vulnerabilities before attackers can exploit them. Its 'General Security Intelligence' uses custom AI agents and purpose-trained security models to read a company's code, business logic and infrastructure, surfacing more true-positive vulnerabilities while cutting false positives and delivering developer-ready fixes. Founded in 2024 by leaders from Databricks, Google DeepMind and Faire, the company raised $120M across Series A and B within a few months of leaving stealth.
EverOps is a San Francisco-based IT and cloud managed services provider that embeds small teams of senior engineers - called TechPods - directly inside client organizations to run DevOps, SRE, ITOps, and security work. Founded in 2012 and re-capitalized in 2022, the firm pitches itself as an alternative to advice-only consulting and staffing shops: pods sit in the client's toolchain, attend standups, and take ownership of outcomes across cloud infrastructure, platform engineering, observability, and cloud cost reduction.
Mattermost is an open-source, self-hostable collaboration platform built for organizations that cannot put their conversations in someone else's cloud. Started as a game studio's internal chat tool and open-sourced in 2015, it grew into the leading self-hosted alternative to Slack and Microsoft Teams, combining channel messaging, voice and screen sharing, incident-response Playbooks, and integrated AI agents. Its customers skew toward defense, government, financial services, and technology organizations - from the U.S. Air Force to Uber - that need data sovereignty, air-gapped deployment, and government-grade security.
RAD Security is a San Francisco cloud-native security company that pairs runtime telemetry with agentic AI to help teams detect, investigate, and respond to threats across Kubernetes and cloud environments. Founded in 2021 as KSOC and rebranded RAD Security in 2024, it builds behavioral, eBPF-driven detection and a roster of AI 'RADBots' that triage alerts, generate compliance evidence, and automate security workflows. The company raised a $14M Series A in February 2025, bringing total funding to about $20M.
SEWORKS is a San Francisco cybersecurity company founded in 2013 by white-hat hackers that turns offensive-security expertise into AI-powered products. Its platform helps organizations see their software the way an attacker does, combining AI-driven penetration testing (Pentoma), mobile app hardening (AppSolid), breached-credential defense (LeakJar), and SOC 2 / ISO 27001 compliance support. SEWORKS serves 100+ enterprise clients including Sendbird and Mercari.
Neatsun Ziv is the co-founder and CEO of OX Security, an application security posture management company he started in 2021 with fellow Check Point veteran Lior Arzi after the SolarWinds breach. OX raised a $60M Series B in May 2025, bringing total funding to about $101.5M, and pitches a platform that culls the roughly 5% of code and pipeline risks that developers actually need to fix. Before OX, Ziv ran Threat Prevention & Intelligence at Check Point, where his team helped coordinate responses to NotPetya, SolarWinds and other campaigns with Interpol and national CERTs.
Roni Fuchs is the co-founder and CEO of Legit Security, an application security posture management (ASPM) company protecting software supply chains for customers including Google, NYSE, Kraft Heinz and Palo Alto Networks. A Unit 8200 veteran who grew up in Jaffa, he founded Legit in 2020 with two IDF comrades after stints at Microsoft (via Aorato) and Checkmarx (via his prior startup Lumobit). Legit has raised roughly $80.5M through Series B.
Arganteal Corporation is an Austin, Texas software company that helps enterprise and government IT teams design, deploy, and manage complex infrastructure across hybrid cloud environments. Its patented tools - ADepT for workflow automation and ASCOT for discovering and classifying operational scripts - turn scattered scripting knowledge into reusable, platform-agnostic automation libraries. The company pairs that technology with professional services, claiming to cut deployment time by as much as 90%, and counts the U.S. Air Force among its longstanding partners.
Resourcely was a San Francisco cybersecurity startup that made cloud infrastructure secure and compliant by design. Its platform paired Blueprints - self-service templates that generate golden-path Terraform and OpenTofu - with Guardrails, a policy engine written in a human-friendly language called Really that catches misconfigurations before deployment. Founded in 2022 by Travis McPeak and Aladdin Almubayed and backed by $8M in seed funding, Resourcely was acquired by Anysphere (maker of the AI code editor Cursor) in July 2025, with McPeak joining to lead Cursor's security efforts.
Corridor is a San Francisco security company building an AI-native platform that embeds protection directly into AI coding workflows. Its Agentic Coding Security Management (ACSM) platform reviews every file edit and pull request in real time, catching vulnerabilities as code is generated by tools like Cursor and Claude Code rather than after it ships. Founded in 2025 by former CISA staffers Jack Cable and Ashwin Ramaswami with security veteran Alex Stamos, Corridor has raised $30.4M, including a $25M Series A at a $200M valuation in March 2026.
David Bild is a technical co-founder and engineering leader at Resourcely, the cloud-security startup acquired by Anysphere (maker of Cursor) in July 2025. A Ph.D. computer engineer who once designed censorship-resistant networks, he has spent his career turning gnarly security problems into guardrails developers actually want to use - from overlay networking for IoT at Xaptum to secure-by-design Terraform blueprints at Resourcely. Post-acquisition he works on Fraim, an open-source, genAI-based application- and cloud-security tool. He builds from a cabin-adjacent base in Southwest Harbor, Maine, on the doorstep of Acadia.
TAO Digital Solutions is a Santa Clara, California-based IT services and consulting firm founded in 2022 by serial entrepreneur Rajkumar (Raj) Velagapudi. It helps enterprises with product engineering, managed services, cybersecurity, payment solutions, cloud, data and AI-driven transformation. Backed by a 2024 growth investment from Vesper Company, TAO has scaled to roughly 3,000-3,650 professionals across offices in the Americas, Europe, Asia and Africa, and has pursued aggressive M&A to deepen capabilities in medtech, automotive and life sciences.
ThinkSys Inc is a global technology services, software engineering, and consulting company founded in 2012 and headquartered in Sunnyvale, California, with delivery operations in Noida, India. It specializes in quality assurance and software testing, QA automation, custom software development, DevOps, and cloud (AWS) consulting, serving 300+ clients across SaaS, FinTech, healthcare, retail, e-commerce, and education. Fully CMMI Level-3 and ISO 27001 certified, the firm pairs an engineering-first culture with a reputation for top-rated client reviews on G2 and Clutch.
VentureSoft is a Silicon Valley IT services and consulting firm that helps enterprises modernize through AI, secure cloud infrastructure, and data solutions. Founded in 1996 and headquartered in Pleasanton, California, with offices in Dubai and Bengaluru, the company has delivered 1,000+ projects to more than 300 clients ranging from venture-backed startups to Fortune 500 names like Nike, Tesla, Intuit and Gap. Its work spans data analytics and AI, security and GRC, cloud and DevSecOps, ERP/CRM, application development, and 24/7 managed services.
Copado is the leading AI-powered DevOps platform built natively for Salesforce and other low-code business applications. Founded in Madrid in 2013 by two Salesforce release engineers tired of brittle, manual deployments, Copado unifies planning, building, testing, and releasing with built-in automation, governance, and trust. More than 1,750 global brands - including Coca-Cola, T-Mobile, Medtronic, and Volkswagen - use Copado to ship Salesforce changes faster and more safely, and the company reached unicorn status after a $140M Series C in 2021.

Jad Boutros is the co-founder and CEO of TerraTrue, a San Francisco privacy-and-security automation company he started in 2018 with former Snap general counsel Chris Handman. Before building software to make privacy reviews painless, Boutros spent nine years on Google's information security team leading security for its social products, then became Snap's first Chief Security Officer, where he and Handman ran thousands of privacy reviews a year out of a Google spreadsheet that ballooned past 100 tabs. TerraTrue is the product that spreadsheet should have been: a single source of truth that bakes privacy-by-design into the software development lifecycle.