A library can sit quietly in an application for years. Oligo watches what happens when it starts working - and gives security teams a better reason to interrupt an engineer.
Endor Labs built a business around a costly question: does the vulnerable code ever run? As AI agents start writing and installing software, that question has moved from the backlog to the developer’s desk.
Lineaje began with a small heresy: finding vulnerable code is the easy part. Its larger bet is to trace every ingredient, judge the real risk, and send back a repair that does not wreck the build.
Most security tools ask whether a dependency is already notorious. Socket asks a ruder, more useful question: what will this code do after you invite it inside?
ProjectDiscovery made vulnerability checks readable, remixable and free. Then it discovered the harder problem: somebody still had to run the machinery, judge the evidence and carry the fix across the company.
When open-source support expires but the application still runs the business, HeroDevs patches the old code in place. The bet is simple: a clean security scan today is worth more than a panicked rewrite tomorrow.
The open source scanner sold for $565 million, disappeared inside Synopsys, then returned as the name of a $2.1 billion security business. Its next test is harder: checking code that machines can write faster than humans can review.
Most security tools tell engineers what is broken. Chainguard sells them a cleaner starting point - rebuilt from source, stripped of baggage, signed, and continuously patched before the scanner queue becomes the week's agenda.
TruffleHog started as a weekend bug-bounty tool and grew into an enterprise security platform by attacking the least glamorous part of a credential leak: separating live danger from a pile of convincing-looking junk.
ARMO gave away a Kubernetes scanner, watched 40,000 companies download it, then built a runtime-security business on top. This is the story of the open-source Trojan horse - and the eBPF sensor that made it work.
The Boston startup began by trimming Docker images. Its sharper insight was that security teams did not need another list of vulnerabilities - they needed tested fixes that could arrive without an upgrade, a rebuild marathon or a ruined sprint.
SubImage is a San Francisco security startup building an open-core security graph that maps a company's cloud and SaaS infrastructure so teams can see who can access what, and why. Built by the original team behind Cartography, the open-source graph tool created at Lyft and now a CNCF project, SubImage sells a managed, agentless platform for attack path analysis, asset inventory, and misconfiguration detection. Backed by a $4.2M seed round, it positions itself as an open-core alternative to Wiz.
Aqua Security is a cloud native security company founded in 2015 that helps enterprises protect containerized and cloud native applications from development to production. Its Aqua Platform is a Cloud Native Application Protection Platform (CNAPP) that combines agent and agentless technology to scan code and images, enforce policies, manage cloud posture, and stop attacks at runtime. Aqua is also the creator of Trivy, the widely adopted open source vulnerability and misconfiguration scanner. Headquartered in Boston and Ramat Gan, Israel, the company protects more than 500 large enterprises and has raised $325M in total funding at a valuation above $1 billion.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.
Manifest is a software and AI supply chain security platform built to answer a deceptively simple question: what is actually inside the software and AI you build and buy? Founded by national security veterans from Palantir and the Pentagon, the company turns Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) from compliance paperwork into a living risk inventory - generating, importing, enriching and monitoring component data so security teams can find vulnerabilities, track open-source and vendor risk, and prove compliance. Manifest serves mission-critical organizations across defense, government, automotive, medical devices, financial services and healthcare, and counts customers such as the U.S. Air Force and the Department of Homeland Security.
Sonatype is the software supply chain management company behind Nexus Repository and the maintainer of Maven Central, the world's largest repository of open source Java components. Founded in 2008 by core contributors to Apache Maven, it helps developers and enterprises find, manage, and secure the open source code that powers modern software - blocking malicious packages, enforcing policy, and generating software bills of materials (SBOMs) across the development lifecycle.