open-source-security

(29)
Company
Oligo Security asks which vulnerabilities actually wake up
Enterprise · Saas · Developer Tools

Oligo Security asks which vulnerabilities actually wake up

A library can sit quietly in an application for years. Oligo watches what happens when it starts working - and gives security teams a better reason to interrupt an engineer.

runtime-security · application-securityRead →
Legend
Matt Moore and the Art of Fixing the Defaults
Founder · Engineer · Executive

Matt Moore and the Art of Fixing the Defaults

A brisket photo became a startup text. Years of building container tools had prepared Matt Moore for a larger argument: the safest software should be the easiest software to use.

matt-moore · chainguardRead →
Legend
Dan Lorenc and the Problem with a Trusted Download
Founder · Engineer · Executive

Dan Lorenc and the Problem with a Trusted Download

Dan Lorenc became uneasy when strangers ran the first Minikube release without asking who built it. A decade later, the Chainguard co-founder is still trying to make that question impossible to ignore.

dan-lorenc · chainguardRead →
Legend
The Founder Who Couldn’t Sit Still
Founder · Operator · Engineer

The Founder Who Couldn’t Sit Still

Kim Lewandowski helped turn the hidden plumbing of open source into a product people could trust. After building Chainguard, she is starting again - this time with developers in the new AI world on her mind.

kim-lewandowski · chainguardRead →
Company
The Security Alert That Never Needed Fixing
Saas · Enterprise · Developer Tools

The Security Alert That Never Needed Fixing

Endor Labs built a business around a costly question: does the vulnerable code ever run? As AI agents start writing and installing software, that question has moved from the backlog to the developer’s desk.

application-security · software-supply-chain-securityRead →
Company
The Security Scanner That Wants to Finish the Job
Enterprise · Saas · Developer Tools

The Security Scanner That Wants to Finish the Job

Lineaje began with a small heresy: finding vulnerable code is the easy part. Its larger bet is to trace every ingredient, judge the real risk, and send back a repair that does not wreck the build.

software-supply-chain-security · sbom-managementRead →
Legend
Ron Rymon Turned One Miserable Code Audit Into a Company
Founder · Investor · Engineer

Ron Rymon Turned One Miserable Code Audit Into a Company

A punishing due-diligence exercise showed a computer scientist that open-source security was working against developers. His answer became WhiteSource, now Mend.io - and the clearest expression of a career spent turning technical friction into companies.

ron-rymon · mend-ioRead →
Company
The Package Was Fine Six Minutes Ago
Saas · Enterprise · Developer Tools

The Package Was Fine Six Minutes Ago

Most security tools ask whether a dependency is already notorious. Socket asks a ruder, more useful question: what will this code do after you invite it inside?

software-supply-chain-security · open-source-securityRead →
Company
The Security Scanner That Let Everyone Write the Alarm
Enterprise · Developer Tools · Saas

The Security Scanner That Let Everyone Write the Alarm

ProjectDiscovery made vulnerability checks readable, remixable and free. Then it discovered the harder problem: somebody still had to run the machinery, judge the evidence and carry the fix across the company.

cybersecurity · vulnerability-managementRead →
Legend
Liz Egan Builds Companies by Making Marketing Feel Like Something
Executive · Operator

Liz Egan Builds Companies by Making Marketing Feel Like Something

She learned marketing on the job, helped take Yext public, and still insists the discipline cannot live by dashboards alone. At Chainguard, Liz Egan is putting a company builder’s instinct behind the quiet machinery of secure open source.

liz-egan · elizabeth-walton-eganRead →
Company
HeroDevs Sells Enterprises the One Thing a Rushed Rewrite Can’t: More Time
Enterprise · Developer Tools · Saas

HeroDevs Sells Enterprises the One Thing a Rushed Rewrite Can’t: More Time

When open-source support expires but the application still runs the business, HeroDevs patches the old code in place. The bet is simple: a clean security scan today is worth more than a panicked rewrite tomorrow.

open-source-security · end-of-life-softwareRead →
Legend
Jim Ivers Has Spent 20 Years Making Invisible Risk Impossible to Ignore
Executive · Operator · Author

Jim Ivers Has Spent 20 Years Making Invisible Risk Impossible to Ignore

A computer-science graduate became cybersecurity's translator-in-chief - building brands through acquisitions, making the case for secure software, and learning when the market is finally ready to hear an old warning.

jim-ivers · black-duckRead →
Company
Black Duck Came Back From a $2.1 Billion Detour - Now It Wants to Police the AI Code Rush
Enterprise · Developer Tools · Saas

Black Duck Came Back From a $2.1 Billion Detour - Now It Wants to Police the AI Code Rush

The open source scanner sold for $565 million, disappeared inside Synopsys, then returned as the name of a $2.1 billion security business. Its next test is harder: checking code that machines can write faster than humans can review.

application-security · software-composition-analysisRead →
Company
Chainguard Put Open Source on a Factory Line - and Made Patching Someone Else's Problem
Enterprise · Developer Tools · Saas

Chainguard Put Open Source on a Factory Line - and Made Patching Someone Else's Problem

Most security tools tell engineers what is broken. Chainguard sells them a cleaner starting point - rebuilt from source, stripped of baggage, signed, and continuously patched before the scanner queue becomes the week's agenda.

software-supply-chain-security · container-securityRead →
Legend
Azi Cohen Has Spent 25 Years Finding the Risk Everyone Else Left for Later
Founder · Operator · Executive

Azi Cohen Has Spent 25 Years Finding the Risk Everyone Else Left for Later

The Mend.io co-founder built companies around neglected security chores. Now, back in the CEO seat, he is betting that AI will make the old habit of fixing risk at the end of development impossible to defend.

azi-cohen · mend-ioRead →
Legend
Ian Riopel Wants Software Security to Fix the Problem, Not Forward the Ticket
Founder · Operator · Executive

Ian Riopel Wants Software Security to Fix the Problem, Not Forward the Ticket

After years spent watching security teams produce longer lists of vulnerabilities, the Root co-founder made a different bet: patch the software, preserve the workflow, and give developers their time back.

ian-riopel · root-ioRead →
Legend
Dylan Ayrey Went Looking for Bug Bounties. He Found a Company in the Commit History.
Founder · Engineer · Executive

Dylan Ayrey Went Looking for Bug Bounties. He Found a Company in the Commit History.

A weekend security tool escaped its creator's laptop, found a global community, and became Truffle Security. Ayrey's real trick was learning that the history developers delete can be more revealing than the code they keep.

dylan-ayrey · truffle-securityRead →
Company
The Free Security Tool That Became a $40 Million Bet on One Annoying Question: Is That Key Still Live?
Saas · Enterprise · Developer Tools

The Free Security Tool That Became a $40 Million Bet on One Annoying Question: Is That Key Still Live?

TruffleHog started as a weekend bug-bounty tool and grew into an enterprise security platform by attacking the least glamorous part of a credential leak: separating live danger from a pile of convincing-looking junk.

truffle-security · trufflehogRead →
Company
The Open-Source Trojan Horse: How ARMO Turned 11,000 GitHub Stars Into a Cloud-Security Business
Saas · Enterprise · Developer Tools

The Open-Source Trojan Horse: How ARMO Turned 11,000 GitHub Stars Into a Cloud-Security Business

ARMO gave away a Kubernetes scanner, watched 40,000 companies download it, then built a runtime-security business on top. This is the story of the open-source Trojan horse - and the eBPF sensor that made it work.

kubernetes-security · cloud-runtime-securityRead →
Company
Root Raised $37.6 Million to Shrink Containers - Then Found the Bigger Business Was Fixing Them
Ai · Saas · Enterprise

Root Raised $37.6 Million to Shrink Containers - Then Found the Bigger Business Was Fixing Them

The Boston startup began by trimming Docker images. Its sharper insight was that security teams did not need another list of vulnerabilities - they needed tested fixes that could arrive without an upgrade, a rebuild marathon or a ruined sprint.

container-security · open-source-securityRead →
Company
SubImage
Saas · Enterprise · Developer Tools

SubImage

SubImage is a San Francisco security startup building an open-core security graph that maps a company's cloud and SaaS infrastructure so teams can see who can access what, and why. Built by the original team behind Cartography, the open-source graph tool created at Lyft and now a CNCF project, SubImage sells a managed, agentless platform for attack path analysis, asset inventory, and misconfiguration detection. Backed by a $4.2M seed round, it positions itself as an open-core alternative to Wiz.

cloud-security · security-graphRead →
Company
Aqua Security
Enterprise · Developer Tools · Saas

Aqua Security

Aqua Security is a cloud native security company founded in 2015 that helps enterprises protect containerized and cloud native applications from development to production. Its Aqua Platform is a Cloud Native Application Protection Platform (CNAPP) that combines agent and agentless technology to scan code and images, enforce policies, manage cloud posture, and stop attacks at runtime. Aqua is also the creator of Trivy, the widely adopted open source vulnerability and misconfiguration scanner. Headquartered in Boston and Ramat Gan, Israel, the company protects more than 500 large enterprises and has raised $325M in total funding at a valuation above $1 billion.

cloud-native-security · container-securityRead →
Company
Mend.io
Saas · Developer Tools · Enterprise

Mend.io

Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.

application-security · appsecRead →
Story
The $5 Billion Patch: IBM and Red Hat Try to Fix Open Source Before AI Breaks It
Ibm · Red Hat · Lightwell

The $5 Billion Patch: IBM and Red Hat Try to Fix Open Source Before AI Breaks It

On July 8, 2026, IBM and Red Hat announced the commercial launch of Lightwell, a platform delivering automated open source vulnerability remediation at enterprise scale. The launch, which builds on a $5 billion open source security commitment made in May 2026, introduces two offerings: Lightwell Network, a generally available catalog of 6,500+ remediated, digitally signed and certified application-layer dependencies across ecosystems like Java and Python, and Lightwell Clearinghouse Premier, a limited-availability trusted intermediary for secured patch embargoes and vertical threat coordination, starting with financial services. The initiative aims to build the 'trust infrastructure' for open source as AI accelerates both software creation and cheap, automated exploits.

ibm · red-hatRead →
Company
FOSSA
Developer Tools · Saas · Enterprise

FOSSA

FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.

open-source-management · software-composition-analysisRead →
Company
Manifest
Enterprise · Saas · Ai

Manifest

Manifest is a software and AI supply chain security platform built to answer a deceptively simple question: what is actually inside the software and AI you build and buy? Founded by national security veterans from Palantir and the Pentagon, the company turns Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) from compliance paperwork into a living risk inventory - generating, importing, enriching and monitoring component data so security teams can find vulnerabilities, track open-source and vendor risk, and prove compliance. Manifest serves mission-critical organizations across defense, government, automotive, medical devices, financial services and healthcare, and counts customers such as the U.S. Air Force and the Department of Homeland Security.

sbom · aibomRead →
Company
Sonatype
Developer Tools · Enterprise · Saas

Sonatype

Sonatype is the software supply chain management company behind Nexus Repository and the maintainer of Maven Central, the world's largest repository of open source Java components. Founded in 2008 by core contributors to Apache Maven, it helps developers and enterprises find, manage, and secure the open source code that powers modern software - blocking malicious packages, enforcing policy, and generating software bills of materials (SBOMs) across the development lifecycle.

software-supply-chain · open-source-securityRead →
Legend
Bhagwat Swaroop
Executive · Operator · Advisor

Bhagwat Swaroop

Bhagwat Swaroop is the CEO of Sonatype, the software supply chain security company behind the Nexus platform and the world's largest repository of open source component intelligence. Appointed in July 2025, he brings nearly 30 years of cybersecurity and enterprise software leadership from Entrust, One Identity, Proofpoint, Symantec, NetApp, McKinsey, and Intel. Armed with an MBA from Wharton and an MS in Electrical Engineering from Arizona State, Swaroop is betting that developers - not perimeter firewalls - are the new front line of cybersecurity, and he's building Sonatype's AI-powered platform to prove it.

ceo · sonatypeRead →
Legend
Brian Dye
Executive · Operator · Founder

Brian Dye

Brian Dye is the CEO of Corelight, the network detection and response (NDR) company behind the enterprise deployment of Zeek, the open-source network security monitor trusted by the U.S. military, major banks, and critical infrastructure operators worldwide. After a 20-year career spanning Symantec, McAfee, Citrix, and Intel, Dye joined Corelight as CPO in 2018 and was elevated to CEO in August 2020. Under his leadership the company has grown 40% annually, expanded its cloud/SaaS business by 300%, secured a $150M Series E at a $900M valuation in April 2024, and positioned itself at the intersection of AI-driven automation and high-fidelity network evidence.

ceo · cybersecurityRead →