Almanax

Application SecurityDeveloper Tools acquired also known as Almanax Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2024
Funding $1.5M
Last updated 2026-08-22

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Almanax sold engineering and security teams an AI scanner that connects to a GitHub repository, reviews every pull request, and drafts patches for what it finds. depthfirst acquired the company in late June 2026 and welcomed Piccoli, Watson and the team by name, and depthfirst's product list still names no Almanax entry. Almanax nonetheless advertises a seven-day free trial on its own site, while its co-founder now publishes research at depthfirst. Nothing public says what becomes of the scanner under the new owner. Its named users are blockchain companies including Privy, Stellar, the Solana Foundation and Aptos Labs. No third-party evaluation of what the scanner catches appears in public sources, and the benchmark Almanax published requires a reader to accept access conditions.

Sourced Details

Description AI application security product that connects to a GitHub repository, scans the codebase with LLMs to find vulnerabilities, and reviews pull requests to block risky code before it merges. [f1]
Acquisition depthfirst, announced 2026-06-26 [f2]
Founded 2024 [f3]
HQ New York, New York, USA [f4]
Funding $1.5M total [f5]
Latest funding $1M reported January 2025 [f3]

Products

Product What it does
Almanax AI Security Engineer that scans a connected codebase for vulnerabilities, runs continuous code reviews on every pull request, and drafts committable patches for the issues it finds.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Almanax uses AI to find and remediate vulnerabilities in the customer's own software, a conventional application-security problem, and is mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 23 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Almanax names its buyer, the engineering and security teams who cannot wait on manual review, and states the pain concretely as audits costing between tens and hundreds of thousands of dollars with waits of up to eight months. Every figure behind that, including the 9 billion dollars stolen across Web3 in three years, comes from the company's own posts, so the problem is clearly stated and not independently quantified. [s1, s4, s9]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 A public documentation portal describes the mechanism rather than the pitch, covering language-model detection over connected code, automated security reviews on pull requests, reachability triage of third-party alerts, and generated patch suggestions. The benchmark Almanax published, a set of intentionally vulnerable Solana programs, requires an accepted access agreement and records six downloads in the past month, so nothing outside the vendor's own pages validates the capability. [s2, s3, s23, s24]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is dated and the company argues it, tying its 2025 launch to language models good enough to read code for exploitable logic and its 2026 farewell to the wider attack surface that vibe coding created. Buyer-side demand stays indirect, carried by that argument, an NVIDIA Inception selection and investor backing rather than by budget or procurement signals. [s4, s9, s18, s17]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Both co-founders show in-domain build experience, with Maxwell Watson building Capsule8's runtime-security products before Sophos acquired that company and Francesco Piccoli leading product at AnChain.AI on investigation tooling for US agencies. Almanax's own launch post, Piccoli's personal site, an investor portfolio page and one June 2024 trade report carry those build claims, and neither named founder shows a prior exit of their own. [s5, s20, s21]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Almanax names real organizations as users, with Privy, Stellar, the Solana Foundation and Aptos Labs on its trust center, six role-attributed references on its homepage, and Bridge, DFNS and Algorand added in its farewell post. Almanax itself published every one of those names, its scale claims of 100 million lines scanned and hundreds of security teams are its own measurements, and depthfirst calls the commercial results strong without giving a figure. [s6, s7, s8, s9, s10]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Piccoli's site reports 1.5 million dollars raised, and the component reports are consistent with that total: a June 2024 article puts the amount raised by then at 500,000 dollars, and a January 2025 round is reported at 1 million dollars. The capital is small on every figure, and it produced a live product with a SOC 2 Type II attestation, public documentation and named users, which is output proportional to the stage. depthfirst then acquired the company without disclosing terms, so the sale discloses no measure of output per dollar, and no revenue figure appears. [s15, s18, s20, s10, s3, s6]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Buyers can place an AI code scanner in the application-security budget line without coaching, but Almanax's own materials straddle two slots, a Web3 smart-contract pitch on the launch post and general application security in most languages on the homepage. depthfirst's product list names no Almanax entry, so the placement under the new owner is undocumented. [s1, s4, s12, s10]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 GitHub, the platform the Almanax app installs on, already ships Copilot code review to every paid Copilot plan, and GitHub's documentation says that review gives feedback on bugs, security vulnerabilities and style, so the general form of the capability is a shipped platform feature. The dedicated security scanning Almanax sells on top, with reachability triage and models tuned per blockchain ecosystem, reads as a plausible next release for an adjacent scanner rather than a checkbox one already ships. [s22, s2, s24]
Business Risks GitHub already ships an AI review of pull requests to paid Copilot plans, so extending it with reachability triage would remove what still separates Almanax from the platform it installs on…
  • GitHub already ships an AI review of pull requests to paid Copilot plans, so extending it with reachability triage would remove what still separates Almanax from the platform it installs on.
  • depthfirst's product list names no Almanax entry, so the standalone scanner could be folded into that platform or retired without a public notice.
  • Almanax's named users are almost entirely blockchain companies, so the move into general application security could stall if buyers outside that market find no comparable reference to check.
  • No cited source states what ALMX-1 and ALMX-2 accumulate from, so a buyer cannot tell whether detection depends on a third-party frontier model whose pricing and roadmap Almanax does not control.
  • Almanax still advertises a seven-day free trial while its named founders work at depthfirst, so a team adopting the scanner now could find ownership of support and roadmap unclear.
Problem & Market Almanax sold to engineering and security teams who cannot wait on a manual code audit…

Almanax sold to engineering and security teams who cannot wait on a manual code audit. Its launch post puts the cost of traditional security work at tens to hundreds of thousands of dollars and the wait for a skilled reviewer at up to eight months.

The blockchain origin sharpened that problem into a specific form. Almanax started in Web3 because, as its launch post puts it, money is stolen directly once a hack happens and the transaction cannot be reversed, and the same post attributes 9 billion dollars of losses across three years to causes running from smart-contract exploits to phishing and wallet compromise. Almanax published those figures itself, so they establish the shape of the problem rather than its measured scale.

The homepage later widened the pitch from blockchain to most programming languages. That enlarged the addressable market and moved the company onto ground where larger scanners already define the pain for buyers. [s1, s4, s9]

Product Capabilities Almanax connects to a GitHub repository, scans the codebase, and reviews every pull request to block risky code before it merges to main…

Almanax connects to a GitHub repository, scans the codebase, and reviews every pull request to block risky code before it merges to main. The documented flow runs one manual scan across an existing codebase and then continuous reviews on each new pull request.

Remediation and context sit on top of detection. The docs describe reachability analysis that triages third-party alerts so a team acts only on issues it can reach, and committable patch suggestions generated for the vulnerabilities Almanax reports. One of the homepage's offering panels advertises automatic threat modeling that maps architecture from code structure, identifies trust boundaries, and applies STRIDE-based classification.

Public sources supply no outside evidence of detection quality. Almanax published a benchmark of its own, a set of intentionally vulnerable Solana programs, and a reader must accept access conditions before opening its files. A buyer weighing the detection claims has only the vendor's own documentation to check them against. [s2, s3, s23]

Competitive Positioning Almanax competed in two arenas with different odds, building its customer list and its founders' standing in smart-contract security while facing established scanners in general application security…

Almanax competed in two arenas with different odds, building its customer list and its founders' standing in smart-contract security while facing established scanners in general application security.

The platform Almanax installs on now offers a version of its core move. GitHub ships Copilot code review to every paid Copilot plan, and GitHub's documentation says that review gives feedback on bugs, security vulnerabilities and style. What Almanax layered on top, reachability triage of third-party alerts and models tuned per blockchain ecosystem, does not appear in the reviewed sources as a shipped incumbent feature.

The company's own evidence pointed at the niche it was leaving. Its named users, its founders' backgrounds and the irreversibility of blockchain loss all support smart-contract work, while the broad application-security pitch put Almanax against rivals that already sell into that budget. [s1, s6, s22, s24]

Go-to-Market & Traction Almanax published two kinds of traction evidence, and both point at the same crypto-native base…

Almanax published two kinds of traction evidence, and both point at the same crypto-native base. Its trust center names Privy, Stellar, the Solana Foundation and Aptos Labs as teams using the product. Its homepage carries six references attributed to named roles at Aptos Labs, Privy, Sapien AI, Phantom, Cat Town and Flexclub.

The proof and the pitch point different ways. The named accounts cluster in blockchain, which backs the original smart-contract product, while the homepage leads with general application security. The farewell post widens that roster to Bridge, DFNS and Algorand, all blockchain names again.

Almanax itself published every one of those names. Its scale claims, over 100 million lines of code scanned and hundreds of security teams, are the company's own measurements, and depthfirst calls the commercial results strong without giving a figure. No independent report of revenue or deployment appears in public sources, so nothing outside Almanax's own account establishes the size of the business. [s6, s7, s8, s9, s10]

Team & Credibility Almanax was founded in 2024 and based in New York, and its named co-founders bring in-domain build experience…

Almanax was founded in 2024 and based in New York, and its named co-founders bring in-domain build experience. Maxwell Watson built Capsule8's runtime-security products before Sophos acquired that company, and he led blockchain infrastructure work as a senior engineer at Coinbase. Francesco Piccoli led product at AnChain.AI, where the launch post says he built tooling used to investigate hacks for US agencies.

Four cited pages carry those build claims: Almanax's own launch post, Piccoli's personal site, defy.vc's portfolio page, and a June 2024 Startupbusiness report. defy.vc is an investor writing about its own holding, and the Startupbusiness piece quotes Piccoli directly. Two press reports also name a third founder, Giorgio Demarchi, whom the vendor pages never mention, so the public account of who founded the company does not agree with itself.

Both named founders are now inside the acquirer. A depthfirst research post published on 2026-07-28 carries Piccoli's byline under the role Member of Technical Staff, and depthfirst welcomed him, Watson and the team by name in its own announcement of the deal. According to a SecurityWeek article, depthfirst had raised 120 million dollars in total by its Series B, against the roughly 1.5 million dollars Almanax disclosed. [s5, s20, s21, s15, s16, s19, s11, s10, s13, s14]

Trust Readiness Almanax keeps an inspectable trust posture for a company at its stage…

Almanax keeps an inspectable trust posture for a company at its stage. Its trust center lists a SOC 2 Type II attestation, a penetration test, and a policy set covering incident response, cryptography and business continuity.

The product-level answers address what buyers ask a code scanner. The homepage states that no customer data trains its AI, that code is analyzed in a sandbox and then deleted, and that deployment on the customer's own infrastructure is available.

For an early company that attestation removes an objection rather than creating an advantage. It answers a buyer's due-diligence question, and the cited record shows nothing beyond it that a replacement would have to match. [s6, s2, s25]

Competitors Snyk, Semgrep, Checkmarx, GitHub…
Company Relationship Note Compare
Snyk competes with Competes for the developer-security budget Almanax moved toward when it widened past smart contracts. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Semgrep competes with Competes for the same pull-request scanning slot in a developer's workflow.
Checkmarx competes with Competes for the enterprise application-security buyer Almanax targeted with its general-purpose pitch.
GitHub adjacent Adjacent because Almanax installs as an app on the code platform GitHub owns. N/AGitHub is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.

Add analyzed competitors to compare them side by side with Almanax.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

The hardest part of Almanax to reproduce was the engineering that detected exploitable logic across many languages, triaged third-party alerts by reachability, and ran models tuned for individual blockchain ecosystems. That depth was a head start rather than a lasting advantage. Almanax installed as an app on a repository, and no cited page documents state a customer would lose on the way out. No source states what ALMX-1 and ALMX-2 accumulate from or whether Almanax owns any weights. GitHub now offers an AI review of pull requests to all paid Copilot plans, which is the general form of what Almanax sold. depthfirst bought the company in June 2026, and its product list names no Almanax entry, so the scanner's place under the new owner is undocumented.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers connect a GitHub app, start on a seven-day free trial, and pay for scanning, triage and patch drafting that their own team runs and acts on, with no human review or accountability layer described on the cited pages.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Routing every pull request through the Almanax app builds real friction in integration and habit, but the cited record documents no state a replacement could not rebuild and does not size what leaving would cost, so the friction stays at the integration-and-workflow level.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Almanax's trust center publishes a SOC 2 Type II attestation and a penetration test, an ordinary enterprise-market credential, and the cited record names no mandate or authorization specific to this product that would block a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Detecting exploitable logic across many languages with language models, triaging third-party alerts by reachability, and running models tuned per blockchain ecosystem is machine-learning and program-analysis work rather than assembly of standard components, and Almanax built its own Solana vulnerability benchmark to test it.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The named users are blockchain companies and foundations such as Privy, Stellar, the Solana Foundation and Aptos Labs, real organizations with engineering governance, while the self-serve GitHub app on a seven-day trial pulls the profile toward individual development teams and the cited record names no regulated-enterprise or government buyer.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Almanax runs inside the GitHub pull-request flow and CI/CD as security tooling that other engineering work passes through, above a single-purpose end-user application, and the cited record shows nothing depending on it as infrastructure.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Press names ALMX-1 and ALMX-2 as Almanax's models and the homepage lists models specialized per blockchain ecosystem, but no cited source states what those models accumulate from or whether Almanax owns their weights, and the docs describe only state-of-the-art large language models. The corpus the company published, its Solana vulnerability benchmark, is public on Hugging Face rather than retained.
Strategic Market Segmentation Almanax sold to engineering and security teams that need vulnerabilities found without waiting on scarce manual review, and it reached them through developers rather than through a security-team project…

Almanax sold to engineering and security teams that need vulnerabilities found without waiting on scarce manual review, and it reached them through developers rather than through a security-team project. Its launch post prices traditional security work at tens to hundreds of thousands of dollars, which is the cost its own pitch is built against, though no cited page discloses what Almanax charges. The product installs as a GitHub app and runs inside the pull-request workflow.

The company entered through a narrow door and then widened it. Almanax began as a Web3 security product specialized in smart-contract ecosystems, which is where its named users, Privy, Stellar, the Solana Foundation and Aptos Labs, all come from. The homepage now covers most programming languages, which enlarges the market and moves the company off the ground where its proof concentrates.

The buyer it actually served skews crypto-native and developer-led. A self-serve GitHub app and a seven-day free trial with no credit card point at individual development teams adopting the tool directly, while the same pages carry an enterprise block and a contact route.

Product Capabilities & AI Advantages Almanax's capability is language-model vulnerability detection with remediation attached…

Almanax's capability is language-model vulnerability detection with remediation attached. Its docs credit state-of-the-art large language models reading connected code, reachability analysis that triages third-party alerts for validity, and committable patch suggestions and pull-request drafts generated for what it reports.

Ecosystem specialization is the sharpest technical asset. The homepage's captured text names models specialized for EVM, Solana, Stellar and Aptos alongside codebase indexing and internet access for threat intelligence, which lines up with the users Almanax names. The same page's text also carries automatic threat modeling that maps architecture from code structure, identifies trust boundaries and applies STRIDE-based classification.

Almanax built its advantage on engineering rather than on an owned corpus. Press describes ALMX-1 as the platform behind its smart-contract detection and ALMX-2 as a model built to widen language support, and no cited source states what either accumulates from or whether Almanax owns any weights. The corpus the company published, a set of intentionally vulnerable Solana programs, is posted on Hugging Face rather than kept private.

Sales Engagement & Go-to-Market Almanax ran a product-led, bottom-up motion…

Almanax ran a product-led, bottom-up motion. A developer connects a GitHub repository, runs one manual scan, and turns on continuous pull-request reviews, starting from a seven-day free trial with no credit card, which lowers the barrier to first use without an enterprise sales cycle.

The adoption proof is named organizations rather than design partners. The trust center names Privy, Stellar, the Solana Foundation and Aptos Labs, and the homepage carries six references attributed to named roles at Aptos Labs, Privy, Sapien AI, Phantom, Cat Town and Flexclub.

The proof and the pitch point different ways. The used-by list concentrates in blockchain organizations backing the original smart-contract product, while the homepage leads with general application security. The farewell post widens the roster to Bridge, DFNS and Algorand and cites ethical disclosures to Ripple, Coinbase and Fireblocks, so the proof set stayed blockchain-weighted to the end of the standalone period.

Pricing Model Almanax published an entry point rather than a price…

Almanax published an entry point rather than a price. The homepage advertises a seven-day free trial with no credit card required and invites a team to connect a repository, and a probe of almanax.ai/pricing on 2026-08-22 returned the site's own not-found page.

What a paid engagement costs is not disclosed. The cited pages establish only the free entry, so a buyer cannot tell from the site whether Almanax charges by seat, by repository or by usage.

The trial-first shape puts price discovery after proof of value, and no cited page states how a paid tier would be structured. Letting a team scan its own codebase before any commitment suits a product whose value shows most clearly on the buyer's real code, which is a reasonable stance for an early vendor still establishing willingness to pay.

Product Delivery & Operations Almanax delivers as a connected service rather than software a customer installs and runs alone, and it answers the data-handling worry that comes with ingesting source code…

Almanax delivers as a connected service rather than software a customer installs and runs alone, and it answers the data-handling worry that comes with ingesting source code. The homepage states that code is analyzed in a sandbox and then deleted, that no customer data trains its AI, and that deployment on the customer's own infrastructure is available.

The operational fit is the developer pipeline. Almanax integrates with GitHub and CI/CD, reviews every pull request, and returns contextual feedback and committable fixes where code already moves, rather than in a separate console.

The enterprise controls are stated and stage-appropriate. Organization, role and access controls plus CI/CD integration cover what a security buyer expects, and no cited page names an enterprise deployment or an independent measure of these controls at volume.

Earning Customers' Trust Almanax keeps an inspectable trust posture for its stage…

Almanax keeps an inspectable trust posture for its stage. Its trust center lists a SOC 2 Type II attestation, a penetration test, and named policies for incident response, cryptography and business continuity.

The product-level trust story addresses the specific fear a code scanner raises. Code is analyzed in a sandbox and then deleted, no customer data trains the models, and on-infrastructure deployment is offered, which answers the data-exposure questions a security team asks before connecting a repository.

For an early company the attestation removes an objection without creating an advantage. It answers a buyer's due-diligence question, and the cited record shows nothing beyond it that a replacement would have to match.

Platform Strategy & Ecosystem Positioning Almanax positions as a single product embedded in someone else's platform rather than a platform of its own…

Almanax positions as a single product embedded in someone else's platform rather than a platform of its own. It plugs into GitHub and the pull-request workflow, which gives it distribution into where developers already work and makes the host a potential competitor.

Ecosystem tuning is the platform-adjacent strength. By shipping models specialized for EVM, Solana, Stellar and Aptos, Almanax lines up with the blockchain developer communities where it has users, which is a sharper position than a generic scanner bolted onto the same integration points.

The dependency cuts both ways. GitHub ships Copilot code review to every paid Copilot plan, and GitHub's documentation says that review gives feedback on bugs, security vulnerabilities and style, so the platform that carries Almanax to developers also offers the general form of what Almanax sold.

Team & Execution Capability Almanax was founded in 2024 and based in New York, and its execution capability rested on a domain-credible founding pair the vendor pages name…

Almanax was founded in 2024 and based in New York, and its execution capability rested on a domain-credible founding pair the vendor pages name. Maxwell Watson built Capsule8's runtime-security products before Sophos acquired that company and led blockchain infrastructure work at Coinbase, while Francesco Piccoli led product at AnChain.AI and did AI research at Ripple. Two press reports also name Giorgio Demarchi as a founder, whom the vendor pages never mention, so the public account of who founded the company does not agree with itself.

The team matched the entry point it chose. Blockchain and security backgrounds map directly onto the smart-contract niche where its named users concentrate, which is the clearest sign the founders could execute on the problem they started with.

Both named founders now work at the acquirer. depthfirst welcomed Piccoli, Watson and the team by name in its own announcement on 2026-06-26, and a depthfirst research post published on 2026-07-28 carries Piccoli's byline under the role Member of Technical Staff. A probe of depthfirst's sitemap on 2026-08-22 found a single URL naming Almanax, and that one is the announcement post, so the acquirer's product surface does not yet describe what happens to the scanner.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Almanax homepage official 2026-08-22
f2 depthfirst: Almanax is joining depthfirst official 2026-08-22
f3 The AI Insider: Almanax Secures $1M to Advance AI-Driven Web3 Security Solutions press 2026-08-22
f4 Startup Intros: Almanax quick facts research 2026-08-22
f5 Francesco Piccoli: personal site official 2026-08-22
Profile Analysis Sources (25)
Id Source Tier Accessed
s1 Almanax homepage: The AI Security Engineer
“An AI-native application security product that understands code, business logic, and infrastructure like a human security expert.”
official 2026-08-22
s2 Almanax homepage: product steps and offering
“Review every pull request and block risky code before it merges to main”
official 2026-08-22
s3 Almanax Docs: overview of the detection and remediation mechanism
“State-of-the-art LLMs with comprehensive context understanding detect complex security vulnerabilities that traditional tools miss.”
official 2026-08-22
s4 Almanax blog: Introducing Almanax, the Web3 origin and audit pain
“Traditional security can be prohibitively expensive, often costing between tens and hundreds of thousands of dollars, making security out of reach for many projects.”
official 2026-08-22
s5 Almanax blog: founder backgrounds at AnChain.AI, Coinbase and Capsule8
“Francesco was the former Head of Product at AnChain.AI, where he built products to investigate multi-million-dollar hacks for the US SEC, FinCEN, IRS, and Italian Police.”
official 2026-08-22
s6 Almanax Trust Center: attestation, policies and named user teams
“SOC 2 Type II”
official 2026-08-22
s7 Almanax homepage: role-attributed customer references
“Security @ Aptos Labs”
official 2026-08-22
s8 Almanax homepage: vendor-stated scale claims
“Over 100M lines of code scanned”
official 2026-08-22
s9 Almanax blog: Almanax is joining depthfirst
“We ended up working with some of the largest blockchain companies: Solana, Stellar, Aptos, Privy and Bridge (now part of Stripe), DFNS, Algorand.”
official 2026-08-22
s10 depthfirst: Almanax is joining depthfirst
“Today we are excited to welcome Francesco, Maxwell, and the Almanax team to depthfirst.”
official 2026-08-22
s11 depthfirst research post: Graduating from CyberGym Level 1
“Authors Francesco Piccoli”
official 2026-08-22
s12 depthfirst.com sitemap probe: 59 URLs enumerated 2026-08-22, one naming Almanax
“https://depthfirst.com/post/almanax-is-joining-depthfirst/”
official 2026-08-22
s13 Almanax on X: acquisition announcement
“Almanax has been acquired by @depthfirstlabs!”
official 2026-08-22
s14 SecurityWeek: Depthfirst Raises $80 Million in Series B Funding
“Software security startup Depthfirst has raised $80 million in Series B funding, bringing the total raised to $120 million in less than three months after closing its Series A funding round in mid-January.”
press 2026-08-22
s15 The AI Insider: Almanax Secures $1M to Advance AI-Driven Web3 Security Solutions
“New York-based AI Web3 security firm Almanax has raised $1 million in funding from investors including Blockchain Builders Fund, Exor Ventures, Vento Ventures, Italian Angels for Growth, Eden Ventures, Moonbase, and a group of angel investors.”
press 2026-08-22
s16 citybiz: Almanax Raises $1M Funding
“Formed in 2024 by Francesco Piccoli, Giorgio Demarchi, and Maxwell Watson, Almanax aims to tackle security problems across web3.”
press 2026-08-22
s17 FinSMEs: Almanax Receives Pre-Seed Funding From defy.vc
“Almanax , a Web3 Security company, raised an undisclosed amount in Pre-Seed funding.”
press 2026-08-22
s18 Startupbusiness: Almanax, the New York Web3 security startup
“Founded in New York by Francesco Piccoli and Maxwell Watson aims to solve critical issues related to smart contracts and has already raised $500,000”
press 2026-08-22
s19 Startup Intros: Almanax quick facts
“Founded 2024”
research 2026-08-22
s20 Francesco Piccoli personal site: Almanax funding and prior roles
“Almanax raised $1.5 million to develop an AI Security Engineer that detects and patches software vulnerabilities like a senior security engineer would.”
official 2026-08-22
s21 defy.vc portfolio page: Almanax co-founders and prior employers
“Francesco and Maxwell bring years of blockchain + security experience from their time building at Coinbase, Anchain.ai, Ripple, and Capsule8 (acquired by Sophos).”
official 2026-08-22
s22 GitHub Docs: About GitHub Copilot code review
“Copilot reviews your pull requests, identifies issues, and suggests fixes you can apply in a couple of clicks.”
official 2026-08-22
s23 Hugging Face: almanax/insecure-solana-programs benchmark dataset card
“This benchmark is dedicated to Solana contracts that are intentionally vulnerable to a list of most common vulnerabilities specific to Solana.”
official 2026-08-22
s24 Almanax homepage: Detection panel of the offering tabs
“State-of-the-art LLMs, combined with comprehensive context understanding, detect complex security vulnerabilities in your codebase.”
official 2026-08-22
s25 Almanax homepage: enterprise controls and trial
“No AI training on your data”
official 2026-08-22
Deep-Dive Sources (25)
Id Source Tier Accessed
s1 Almanax homepage: The AI Security Engineer
“An AI-native application security product that understands code, business logic, and infrastructure like a human security expert.”
official 2026-08-22
s2 Almanax homepage: product steps and offering
“Review every pull request and block risky code before it merges to main”
official 2026-08-22
s3 Almanax Docs: overview of the detection and remediation mechanism
“State-of-the-art LLMs with comprehensive context understanding detect complex security vulnerabilities that traditional tools miss.”
official 2026-08-22
s4 Almanax blog: Introducing Almanax, the Web3 origin and audit pain
“Traditional security can be prohibitively expensive, often costing between tens and hundreds of thousands of dollars, making security out of reach for many projects.”
official 2026-08-22
s5 Almanax blog: founder backgrounds at AnChain.AI, Coinbase and Capsule8
“Francesco was the former Head of Product at AnChain.AI, where he built products to investigate multi-million-dollar hacks for the US SEC, FinCEN, IRS, and Italian Police.”
official 2026-08-22
s6 Almanax Trust Center: attestation, policies and named user teams
“SOC 2 Type II”
official 2026-08-22
s7 Almanax homepage: enterprise controls and trial
“No AI training on your data”
official 2026-08-22
s8 Almanax homepage: role-attributed customer references
“Security @ Aptos Labs”
official 2026-08-22
s9 Almanax blog: Almanax is joining depthfirst
“We ended up working with some of the largest blockchain companies: Solana, Stellar, Aptos, Privy and Bridge (now part of Stripe), DFNS, Algorand.”
official 2026-08-22
s10 depthfirst: Almanax is joining depthfirst
“Today we are excited to welcome Francesco, Maxwell, and the Almanax team to depthfirst.”
official 2026-08-22
s11 depthfirst research post: Graduating from CyberGym Level 1
“Authors Francesco Piccoli”
official 2026-08-22
s12 depthfirst.com sitemap probe: 59 URLs enumerated 2026-08-22, one naming Almanax
“https://depthfirst.com/post/almanax-is-joining-depthfirst/”
official 2026-08-22
s13 Almanax on X: acquisition announcement
“Almanax has been acquired by @depthfirstlabs!”
official 2026-08-22
s14 SecurityWeek: Depthfirst Raises $80 Million in Series B Funding
“Software security startup Depthfirst has raised $80 million in Series B funding, bringing the total raised to $120 million in less than three months after closing its Series A funding round in mid-January.”
press 2026-08-22
s15 The AI Insider: Almanax Secures $1M to Advance AI-Driven Web3 Security Solutions
“New York-based AI Web3 security firm Almanax has raised $1 million in funding from investors including Blockchain Builders Fund, Exor Ventures, Vento Ventures, Italian Angels for Growth, Eden Ventures, Moonbase, and a group of angel investors.”
press 2026-08-22
s16 citybiz: Almanax Raises $1M Funding
“Formed in 2024 by Francesco Piccoli, Giorgio Demarchi, and Maxwell Watson, Almanax aims to tackle security problems across web3.”
press 2026-08-22
s17 FinSMEs: Almanax Receives Pre-Seed Funding From defy.vc
“Almanax , a Web3 Security company, raised an undisclosed amount in Pre-Seed funding.”
press 2026-08-22
s18 Startupbusiness: Almanax, the New York Web3 security startup
“Founded in New York by Francesco Piccoli and Maxwell Watson aims to solve critical issues related to smart contracts and has already raised $500,000”
press 2026-08-22
s19 Startup Intros: Almanax quick facts
“Founded 2024”
research 2026-08-22
s20 Francesco Piccoli personal site: Almanax funding and prior roles
“Almanax raised $1.5 million to develop an AI Security Engineer that detects and patches software vulnerabilities like a senior security engineer would.”
official 2026-08-22
s21 defy.vc portfolio page: Almanax co-founders and prior employers
“Francesco and Maxwell bring years of blockchain + security experience from their time building at Coinbase, Anchain.ai, Ripple, and Capsule8 (acquired by Sophos).”
official 2026-08-22
s22 GitHub Docs: About GitHub Copilot code review
“Copilot reviews your pull requests, identifies issues, and suggests fixes you can apply in a couple of clicks.”
official 2026-08-22
s23 Hugging Face: almanax/insecure-solana-programs benchmark dataset card
“This benchmark is dedicated to Solana contracts that are intentionally vulnerable to a list of most common vulnerabilities specific to Solana.”
official 2026-08-22
s24 Almanax homepage: Detection panel of the offering tabs
“State-of-the-art LLMs, combined with comprehensive context understanding, detect complex security vulnerabilities in your codebase.”
official 2026-08-22
s25 Almanax pricing-page probe 2026-08-22: /pricing renders a 404
“Oops! Page not found”
official 2026-08-22

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.