sca

(10)
Company
Checkmarx Built the Scanner. Now It Wants to Kill the Security Backlog.
Enterprise · Saas · Developer Tools

Checkmarx Built the Scanner. Now It Wants to Kill the Security Backlog.

The 20-year-old AppSec company made its name finding vulnerable code. Its harder second act is making the findings useful before AI-assisted development turns every security queue into a landfill.

application-security · appsecRead →
Company
Legit Security
Ai · Enterprise · Saas

Legit Security

Legit Security is an AI-native Application Security Posture Management (ASPM) company that gives security teams a single platform to discover, prioritize, and remediate risk across the entire software development lifecycle - from a developer's IDE and AI coding assistant to production. Founded in 2020 by three veterans of Israel's elite cyber units, the company consolidates fragmented AppSec findings, cuts false positives with context and reachability analysis, scans for exposed secrets, and now governs AI-generated code before it ships. Legit serves large enterprises including Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, and ZoomInfo.

application-security · aspmRead →
Company
Mend.io
Saas · Developer Tools · Enterprise

Mend.io

Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.

application-security · appsecRead →
Company
OX Security
Saas · Developer Tools · Enterprise

OX Security

OX Security is an application security company that built an Active Application Security Posture Management (ASPM) platform to give development and security teams a single, code-to-cloud view of software risk. Founded in 2021 by Check Point veterans Neatsun Ziv and Lior Arzi, OX consolidates scanning across the software development lifecycle - from source code and open-source dependencies to CI/CD pipelines and cloud - then uses context and attack-path analysis to surface the roughly 5% of vulnerabilities that are actually exploitable and reachable, so teams stop drowning in alerts. The company raised a $60M Series B in May 2025 (total funding around $94-101M) with backing from DTCP, IBM, Microsoft's M12, Evolution Equity, Team8 and others.

application-security · aspmRead →
Company
Contrast Security
Saas · Enterprise · Developer Tools

Contrast Security

Contrast Security is a Pleasanton, California-based cybersecurity company that secures software from the inside out. Founded in 2014 by OWASP veterans Jeff Williams and Arshan Dabirsiaghi, it pioneered an instrumentation-based approach that embeds security sensors directly into running applications to detect vulnerabilities and block live attacks in real time. Its runtime security platform spans Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), static analysis (SAST), software composition analysis (SCA), and Application Detection and Response (ADR), serving Fortune 500 enterprises and government agencies.

application-security · appsecRead →
Company
FOSSA
Developer Tools · Saas · Enterprise

FOSSA

FOSSA is a San Francisco software company that helps engineering, security, and legal teams manage the open source code inside their software. Its platform automates software composition analysis (SCA), open source license compliance, vulnerability management, and Software Bill of Materials (SBOM) generation - scanning packages, containers, binaries, and code snippets on a continuous basis. Founded in 2015 and used by companies such as Uber, Zendesk, Twitter, Verizon, and UiPath, FOSSA aims to let teams ship fast without sacrificing compliance or security.

open-source-management · software-composition-analysisRead →
Company
Sonatype
Developer Tools · Enterprise · Saas

Sonatype

Sonatype is the software supply chain management company behind Nexus Repository and the maintainer of Maven Central, the world's largest repository of open source Java components. Founded in 2008 by core contributors to Apache Maven, it helps developers and enterprises find, manage, and secure the open source code that powers modern software - blocking malicious packages, enforcing policy, and generating software bills of materials (SBOMs) across the development lifecycle.

software-supply-chain · open-source-securityRead →
Company
Semgrep
Developer Tools · Enterprise · Saas

Semgrep

Semgrep is a San Francisco application-security company that builds a unified AppSec platform (Code/SAST, Supply Chain/SCA, and Secrets) used by engineering teams at Dropbox, Figma, Snowflake and others. Born out of an open-source tool originally written at Facebook, it lets security teams write code-like rules and ship them through CI - cutting false positives and pushing fixes back to developers.

sast · scaRead →
Legend
Rick Fitz
Executive · Operator · Enterprise

Rick Fitz

Rick Fitz is the Chief Executive Officer and Chairman of the Board at Contrast Security, the application security company behind the 'Shift Smart' approach to securing software from within. A 25-year enterprise software veteran, Fitz came to the role in April 2023 after six-plus years as SVP and General Manager of Splunk's IT Operations and Application Development Market Group, where he steered the company through landmark acquisitions including SignalFX. At Contrast, he leads a 240-person company with $274M in total funding as it works to redefine how developers and security teams find and fix vulnerabilities at runtime - inside applications as they run, rather than scanning from the outside.

ceo · cybersecurityRead →
Legend
Isaac Evans
Founder · Executive · Engineer

Isaac Evans

Isaac Evans is the Founder and CEO of Semgrep, the developer-first application security platform that has redefined how modern engineering teams handle code security. An MIT-trained computer scientist with a background in U.S. Department of Defense security research, Evans co-founded Semgrep in 2017 with college roommates Drew Dennison and Luke O'Malley. Under his leadership, Semgrep grew from a niche static analysis tool into a platform scanning 75+ million code repositories annually, serving customers like Figma, Dropbox, Slack, and Snowflake. In February 2025, the company closed a $100M Series D led by Menlo Ventures, bringing total funding to $193M. Evans's core thesis - that security must serve developers, not obstruct them - has made Semgrep a defining force in the AppSec category.

founder · ceoRead →