A library can sit quietly in an application for years. Oligo watches what happens when it starts working - and gives security teams a better reason to interrupt an engineer.

A brisket photo became a startup text. Years of building container tools had prepared Matt Moore for a larger argument: the safest software should be the easiest software to use.

Dan Lorenc became uneasy when strangers ran the first Minikube release without asking who built it. A decade later, the Chainguard co-founder is still trying to make that question impossible to ignore.

Kim Lewandowski helped turn the hidden plumbing of open source into a product people could trust. After building Chainguard, she is starting again - this time with developers in the new AI world on her mind.
Endor Labs built a business around a costly question: does the vulnerable code ever run? As AI agents start writing and installing software, that question has moved from the backlog to the developer’s desk.
Lineaje began with a small heresy: finding vulnerable code is the easy part. Its larger bet is to trace every ingredient, judge the real risk, and send back a repair that does not wreck the build.

A punishing due-diligence exercise showed a computer scientist that open-source security was working against developers. His answer became WhiteSource, now Mend.io - and the clearest expression of a career spent turning technical friction into companies.
Most security tools ask whether a dependency is already notorious. Socket asks a ruder, more useful question: what will this code do after you invite it inside?
ProjectDiscovery made vulnerability checks readable, remixable and free. Then it discovered the harder problem: somebody still had to run the machinery, judge the evidence and carry the fix across the company.

She learned marketing on the job, helped take Yext public, and still insists the discipline cannot live by dashboards alone. At Chainguard, Liz Egan is putting a company builder’s instinct behind the quiet machinery of secure open source.
When open-source support expires but the application still runs the business, HeroDevs patches the old code in place. The bet is simple: a clean security scan today is worth more than a panicked rewrite tomorrow.

A computer-science graduate became cybersecurity's translator-in-chief - building brands through acquisitions, making the case for secure software, and learning when the market is finally ready to hear an old warning.
The open source scanner sold for $565 million, disappeared inside Synopsys, then returned as the name of a $2.1 billion security business. Its next test is harder: checking code that machines can write faster than humans can review.
Most security tools tell engineers what is broken. Chainguard sells them a cleaner starting point - rebuilt from source, stripped of baggage, signed, and continuously patched before the scanner queue becomes the week's agenda.

The Mend.io co-founder built companies around neglected security chores. Now, back in the CEO seat, he is betting that AI will make the old habit of fixing risk at the end of development impossible to defend.

After years spent watching security teams produce longer lists of vulnerabilities, the Root co-founder made a different bet: patch the software, preserve the workflow, and give developers their time back.

A weekend security tool escaped its creator's laptop, found a global community, and became Truffle Security. Ayrey's real trick was learning that the history developers delete can be more revealing than the code they keep.
TruffleHog started as a weekend bug-bounty tool and grew into an enterprise security platform by attacking the least glamorous part of a credential leak: separating live danger from a pile of convincing-looking junk.
ARMO gave away a Kubernetes scanner, watched 40,000 companies download it, then built a runtime-security business on top. This is the story of the open-source Trojan horse - and the eBPF sensor that made it work.
The Boston startup began by trimming Docker images. Its sharper insight was that security teams did not need another list of vulnerabilities - they needed tested fixes that could arrive without an upgrade, a rebuild marathon or a ruined sprint.
SubImage is a San Francisco security startup building an open-core security graph that maps a company's cloud and SaaS infrastructure so teams can see who can access what, and why. Built by the original team behind Cartography, the open-source graph tool created at Lyft and now a CNCF project, SubImage sells a managed, agentless platform for attack path analysis, asset inventory, and misconfiguration detection. Backed by a $4.2M seed round, it positions itself as an open-core alternative to Wiz.
Aqua Security is a cloud native security company founded in 2015 that helps enterprises protect containerized and cloud native applications from development to production. Its Aqua Platform is a Cloud Native Application Protection Platform (CNAPP) that combines agent and agentless technology to scan code and images, enforce policies, manage cloud posture, and stop attacks at runtime. Aqua is also the creator of Trivy, the widely adopted open source vulnerability and misconfiguration scanner. Headquartered in Boston and Ramat Gan, Israel, the company protects more than 500 large enterprises and has raised $325M in total funding at a valuation above $1 billion.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
On July 8, 2026, IBM and Red Hat announced the commercial launch of Lightwell, a platform delivering automated open source vulnerability remediation at enterprise scale. The launch, which builds on a $5 billion open source security commitment made in May 2026, introduces two offerings: Lightwell Network, a generally available catalog of 6,500+ remediated, digitally signed and certified application-layer dependencies across ecosystems like Java and Python, and Lightwell Clearinghouse Premier, a limited-availability trusted intermediary for secured patch embargoes and vertical threat coordination, starting with financial services. The initiative aims to build the 'trust infrastructure' for open source as AI accelerates both software creation and cheap, automated exploits.
FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.
Manifest is a software and AI supply chain security platform built to answer a deceptively simple question: what is actually inside the software and AI you build and buy? Founded by national security veterans from Palantir and the Pentagon, the company turns Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) from compliance paperwork into a living risk inventory - generating, importing, enriching and monitoring component data so security teams can find vulnerabilities, track open-source and vendor risk, and prove compliance. Manifest serves mission-critical organizations across defense, government, automotive, medical devices, financial services and healthcare, and counts customers such as the U.S. Air Force and the Department of Homeland Security.
Sonatype is the software supply chain management company behind Nexus Repository and the maintainer of Maven Central, the world's largest repository of open source Java components. Founded in 2008 by core contributors to Apache Maven, it helps developers and enterprises find, manage, and secure the open source code that powers modern software - blocking malicious packages, enforcing policy, and generating software bills of materials (SBOMs) across the development lifecycle.
Bhagwat Swaroop is the CEO of Sonatype, the software supply chain security company behind the Nexus platform and the world's largest repository of open source component intelligence. Appointed in July 2025, he brings nearly 30 years of cybersecurity and enterprise software leadership from Entrust, One Identity, Proofpoint, Symantec, NetApp, McKinsey, and Intel. Armed with an MBA from Wharton and an MS in Electrical Engineering from Arizona State, Swaroop is betting that developers - not perimeter firewalls - are the new front line of cybersecurity, and he's building Sonatype's AI-powered platform to prove it.

Brian Dye is the CEO of Corelight, the network detection and response (NDR) company behind the enterprise deployment of Zeek, the open-source network security monitor trusted by the U.S. military, major banks, and critical infrastructure operators worldwide. After a 20-year career spanning Symantec, McAfee, Citrix, and Intel, Dye joined Corelight as CPO in 2018 and was elevated to CEO in August 2020. Under his leadership the company has grown 40% annually, expanded its cloud/SaaS business by 300%, secured a $150M Series E at a $900M valuation in April 2024, and positioned itself at the intersection of AI-driven automation and high-fidelity network evidence.