
Cloudsmith is a Belfast-founded, cloud-native artifact management platform that gives engineering teams a single place to store, secure, and distribute software packages and containers across 30+ formats. It acts as a private, fully managed registry with built-in supply chain controls - vulnerability and malware scanning, policy enforcement, quarantine, and global distribution - increasingly positioned around governing the flood of code produced by AI coding agents.
Legit Security is an AI-native Application Security Posture Management (ASPM) company that gives security teams a single platform to discover, prioritize, and remediate risk across the entire software development lifecycle - from a developer's IDE and AI coding assistant to production. Founded in 2020 by three veterans of Israel's elite cyber units, the company consolidates fragmented AppSec findings, cuts false positives with context and reachability analysis, scans for exposed secrets, and now governs AI-generated code before it ships. Legit serves large enterprises including Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, and ZoomInfo.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
On July 8, 2026, IBM and Red Hat announced the commercial launch of Lightwell, a platform delivering automated open source vulnerability remediation at enterprise scale. The launch, which builds on a $5 billion open source security commitment made in May 2026, introduces two offerings: Lightwell Network, a generally available catalog of 6,500+ remediated, digitally signed and certified application-layer dependencies across ecosystems like Java and Python, and Lightwell Clearinghouse Premier, a limited-availability trusted intermediary for secured patch embargoes and vertical threat coordination, starting with financial services. The initiative aims to build the 'trust infrastructure' for open source as AI accelerates both software creation and cheap, automated exploits.
FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.
Binarly is a firmware and software supply chain security company that reads the code no one else looks at - the layer below the operating system. Its AI-powered Transparency Platform analyzes firmware binaries to surface known and unknown vulnerabilities, malicious implants, misconfigurations and cryptographic weaknesses, then builds a genuine software bill of materials by reconstructing dependencies from the binary itself rather than trusting a manifest. Founded in 2021 by veteran reverse engineers Alex Matrosov and Claudiu Teodorescu, the company has disclosed hundreds of high-impact firmware vulnerabilities, including the widely covered PKfail Secure Boot flaw.
Gwenyth Castro is the Chief Executive Officer of Binarly, the firmware and software supply-chain security company behind the Binarly Transparency Platform. Appointed in March 2026, she stepped into the CEO seat after founder Alex Matrosov moved to the board. Before Binarly she spent roughly 15 years helping build and scale the offensive security firm Bishop Fox, rising to Chief of Staff to the CEO, where she ran cross-functional strategy and global expansion. A Stanford Certified Project Manager, Castro is an operator's operator - the person who turns deep research and patented technology into enterprise revenue, partnerships, and trust with customers like Meta and Dell.
Manifest is a software and AI supply chain security platform built to answer a deceptively simple question: what is actually inside the software and AI you build and buy? Founded by national security veterans from Palantir and the Pentagon, the company turns Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) from compliance paperwork into a living risk inventory - generating, importing, enriching and monitoring component data so security teams can find vulnerabilities, track open-source and vendor risk, and prove compliance. Manifest serves mission-critical organizations across defense, government, automotive, medical devices, financial services and healthcare, and counts customers such as the U.S. Air Force and the Department of Homeland Security.
Daniel Bardenstein is the CEO and co-founder of Manifest, a cybersecurity company building the platform that tells organizations what is actually inside their software and AI systems. He started Manifest in the wake of the Log4Shell crisis, when the world's biggest institutions discovered they could not answer a simple question: what code are we running? Before Manifest, he was chief of technology strategy at CISA, ran cybersecurity programs at the Pentagon's Defense Digital Service including Hack the Pentagon, co-led cyber protection for Operation Warp Speed's COVID-19 vaccine effort, and built products at Palantir and Exabeam. He treats software like an ingredients list the public has a right to read.
Sonatype is the software supply chain management company behind Nexus Repository and the maintainer of Maven Central, the world's largest repository of open source Java components. Founded in 2008 by core contributors to Apache Maven, it helps developers and enterprises find, manage, and secure the open source code that powers modern software - blocking malicious packages, enforcing policy, and generating software bills of materials (SBOMs) across the development lifecycle.
Bhagwat Swaroop is the CEO of Sonatype, the software supply chain security company behind the Nexus platform and the world's largest repository of open source component intelligence. Appointed in July 2025, he brings nearly 30 years of cybersecurity and enterprise software leadership from Entrust, One Identity, Proofpoint, Symantec, NetApp, McKinsey, and Intel. Armed with an MBA from Wharton and an MS in Electrical Engineering from Arizona State, Swaroop is betting that developers - not perimeter firewalls - are the new front line of cybersecurity, and he's building Sonatype's AI-powered platform to prove it.

Mehran Farimani is the co-founder and CEO of RapidFort, a Sunnyvale-based software supply chain security company that raised a $42M Series A in February 2026. A 25-year technology veteran, Mehran previously led the Fiery division at Electronics for Imaging (EFI) as SVP & GM, then founded Percipo—a computer vision AI company whose technology reached 40,000+ retail locations. At RapidFort, he is pioneering the category of Software Attack Surface Management (SASM), helping organizations automatically harden container images and eliminate up to 80% of CVEs through runtime-aware profiling, without touching a single line of application code.
RapidFort is a Sunnyvale-based software supply chain security company that automatically hardens container images, strips unused components, and ships a library of curated near-zero-CVE images so engineering teams can ship secure software without rewriting it.

Aaron Williams is CEO of FOSSA, the San Francisco software supply chain risk management company that watches the open source dependencies inside enterprise code. He arrived in 2022 as VP of Marketing, was promoted to CMO, and stepped into the top job when founder Kevin Wang moved to Chairman. Two Case Western degrees, twenty-plus years of developer marketing at Sun Microsystems, D2iQ, OmniSci, HEAVY.ai and Civis Analytics, and a long habit of building technical communities around tools engineers actually use.

Chris Hughes is a U.S. Air Force veteran, co-founder and president of Aquia Inc., VP of Security Strategy at Zenity, and the founder of Resilient Cyber - a cybersecurity newsletter and podcast with 31,000+ subscribers. A three-time Wiley/Springer author, inaugural CISA Cyber Innovation Fellow, and adjunct professor at two universities, Hughes has become one of the most influential voices on software supply chain security, vulnerability management, and agentic AI security.