A vulnerable dependency can turn a tiny security fix into a sprawling migration. Seal Security sells a way to patch the code you already run, while leaving the grand renovation for another day.
Lineaje began with a small heresy: finding vulnerable code is the easy part. Its larger bet is to trace every ingredient, judge the real risk, and send back a repair that does not wreck the build.
The Kirkland software company turned spare capacity on ordinary devices into an enterprise delivery network. Its next act is harder: convincing security teams that machines can patch machines without losing the human veto.
The Netwrix founders put $20 million of their own money behind a boring problem, narrowed the company to patching, and made the full product free for 200 devices. The wager turned routine maintenance into one of software's more unusual growth stories.

After building infrastructure at AWS and Databricks, the Depthfirst CEO is betting that security software should understand the system, prove the risk and arrive with a fix.

After years spent watching security teams produce longer lists of vulnerabilities, the Root co-founder made a different bet: patch the software, preserve the workflow, and give developers their time back.
The Boston startup began by trimming Docker images. Its sharper insight was that security teams did not need another list of vulnerabilities - they needed tested fixes that could arrive without an upgrade, a rebuild marathon or a ruined sprint.
SubImage is a San Francisco security startup building an open-core security graph that maps a company's cloud and SaaS infrastructure so teams can see who can access what, and why. Built by the original team behind Cartography, the open-source graph tool created at Lyft and now a CNCF project, SubImage sells a managed, agentless platform for attack path analysis, asset inventory, and misconfiguration detection. Backed by a $4.2M seed round, it positions itself as an open-core alternative to Wiz.
Automox is a cloud-native IT automation and endpoint management company that helps organizations patch, configure, and secure Windows, macOS, and Linux devices from a single platform. Founded in 2015 in Boulder, Colorado, its agent-based, server-free approach automates patch management and vulnerability remediation across distributed fleets, and its Otto generative-AI assistant lets IT teams build automation scripts (Worklets) in plain language. The company serves more than 1,500 customers across 30-plus countries and has raised roughly $154 million, including a $110 million Series C led by Insight Partners in 2021.
On July 8, 2026, IBM and Red Hat announced the commercial launch of Lightwell, a platform delivering automated open source vulnerability remediation at enterprise scale. The launch, which builds on a $5 billion open source security commitment made in May 2026, introduces two offerings: Lightwell Network, a generally available catalog of 6,500+ remediated, digitally signed and certified application-layer dependencies across ecosystems like Java and Python, and Lightwell Clearinghouse Premier, a limited-availability trusted intermediary for secured patch embargoes and vertical threat coordination, starting with financial services. The initiative aims to build the 'trust infrastructure' for open source as AI accelerates both software creation and cheap, automated exploits.
NinjaOne is an Austin-based software company that makes an automated, cloud-native endpoint management platform used by IT teams and managed service providers to monitor, secure, patch, back up and control laptops, servers, mobile devices and SaaS data from a single console. Founded in 2013 as NinjaRMM, it now serves more than 30,000 customers and manages over 5 million endpoints, and in 2025 raised $500 million in Series C extensions at a $5 billion valuation while remaining founder-led and debt-free.