All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Apiiro sells an application security platform to large enterprise security teams, built on patented Deep Code Analysis, an engine that maps code to runtime across full git history and inventories what AI coding agents now produce. Apiiro says Gartner ranked it first in application security posture management on the strength of that engine, while IDC named it a Leader and Frost ranked it top for innovation. Named customers include USAA, BlackRock, Shell, and TIAA. The patented engine is the part hardest for a funded rival to reproduce quickly, and it distinguishes Apiiro from pattern-oriented scanners. Its AutoFix agent, launched in August 2025, is recent enough that no outside review speaks to its accuracy, while the engine at least has independent descriptive coverage.
| Description | Application security posture management platform that uses patented Deep Code Analysis to inventory code from design to runtime, builds a risk graph, and uses an AI agent to triage and fix application and supply chain risks. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | New York, New York, United States | [f2] |
| Funding | $135M total | [f2] |
| Latest funding | Series B, $100M (2022), led by General Catalyst | [f2] |
| Product | What it does |
|---|---|
| Apiiro Application Security Platform | ASPM platform unifying design-time threat modeling, SAST, SCA, secrets, IaC, API, and supply chain risk into one risk graph built on Deep Code Analysis, with native scanners on an open platform. |
| Deep Code Analysis (DCA) | Patented engine that continuously analyzes whole codebases with call-flow and code-to-runtime reachability, inventorying APIs, dependencies, secrets, AI models, AI agents, and MCP servers. |
| AutoFix AI Agent | AI agent introduced in August 2025 that pulls software graph, policy, and runtime context into the IDE to propose validated triage and remediation for design and code risks. |
| Apiiro Guardian Agent | AI application-security agent that infuses a developer's prompts to AI coding assistants with security guidance drawn from the organization's threat models, compliance policies, and architecture. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The Apiiro Application Security Platform inventories, prioritizes, and remediates risks across applications, code, and the software supply chain. This conventional application security maps to the Cyber Defense Matrix. [f1]
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
AutoFix secures code produced by AI coding assistants, and Deep Code Analysis inventories AI models, AI agents, and MCP servers. These lines map to the AI Defense Matrix. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Apiiro names a specific buyer, the enterprise application security leader, and a pain that AI coding assistants amplify by multiplying code volume and risk. Gartner standing up a software supply chain security category corroborates the problem at scale, and an independent ASPM review describes the same risk-centric, code-to-runtime approach. [s2, s3, s6, s13] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Public product pages document Deep Code Analysis, the risk graph, native scanners, and AutoFix, and Gartner cited the patented DCA engine by name as the basis for its top ASPM ranking, a third-party validation point beyond marketing claims. An independent review credits the same engine for understanding code behavior rather than pattern matching. [s2, s1, s13] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Multiple buyer-side signals converge within the last year: Gartner stood up a software supply chain security category and ranked ASPM, and the AI coding assistant wave is the why-now enabler driving the risk volume Apiiro addresses with AutoFix, launched in August 2025. An independent review tracks the same code-to-runtime shift. [s3, s2, s9, s12, s13] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Idan Plotnik's Microsoft directorship over Advanced Threat Analytics and Azure ATP is senior big-company security leadership, and the NVD record for CVE-2022-24348, a directory traversal flaw in Argo CD, references an Apiiro advisory for it. Neither a cited founder exit nor the single 2021 RSA Innovation Sandbox win lifts the team to 4, so credibility holds at 3. [s8, s5, s14] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Apiiro displays named enterprise reference customers including USAA, BlackRock, Shell, TIAA, DTCC, and SoFi, and analyst recognition it displays from Gartner, IDC, and Frost reinforces that traction beyond vendor claims standing alone. CRN independently reports the $135 million raised, consistent with a funded enterprise go-to-market. [s7, s2, s4] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Apiiro has raised $135 million since 2019, with no round beyond its 2022 Series B appearing in the reviewed record, reaching analyst-leader status and named enterprise customers on that capital. CRN and SecurityWeek independently report the $100 million Series B and the $135 million total, and the absence of a later raise reads as efficient rather than strained, though margins are unobservable from outside. [s4, s2, s15] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Gartner ranks Apiiro first in ASPM and names it a Leader in the software supply chain security Magic Quadrant, with IDC and Frost adding leader placements the company displays, and an independent ASPM review positions it in the same category. That recognition fits an established category clearly (4) rather than singularly defining it (5). [s2, s3, s7, s13] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The patented Deep Code Analysis engine and code-to-runtime risk graph are harder to copy than commodity scanner logic, and an independent review credits the engine for understanding code behavior rather than pattern matching. But Palo Alto Networks reportedly pursued Apiiro, and adjacent platform vendors sell application security, so absorption pressure is real even with the engineering moat. [s2, s4, s13] |
Apiiro addresses a problem its buyers feel acutely: application security teams cannot keep pace with code that AI assistants now generate at multiples of prior volume and complexity. The company frames the pain as a sharp rise in code volume and risk, and Gartner standing up a brand-new software supply chain security category corroborates that the pain is real at scale.
The target buyer is the enterprise application security leader securing a large, interconnected estate of repositories, pipelines, and runtime. That is a budgeted, named persona under measurable consolidation pressure, which is why Apiiro's framing reads as a buyer problem rather than a vendor narrative. [s2, s3]
The technical core is patented Deep Code Analysis, which continuously reads whole codebases across their history with a call-flow and code-to-runtime reachability engine, then connects the output into a living software graph. Gartner cited that engine by name as the foundation of its top ASPM ranking, unusually specific third-party validation of a capability claim.
Around the graph, Apiiro runs native scanners for supply chain security, secrets, and open source, ingests third-party findings as an open platform, and ships the AutoFix agent that pulls graph, policy, and runtime context into the IDE to propose validated fixes. The graph also inventories AI-related code resources, extending the product toward securing what AI coding assistants generate.
An independent ASPM review credits the same engine, describing Deep Code Analysis and the Risk Graph as understanding code behavior and prioritizing risk from code to runtime rather than scanning for known patterns. [s2, s1, s9, s13]
Apiiro positions above a fragmented stack as the risk-graph layer that correlates findings rather than adding one more scanner. Its differentiation is depth: code-to-runtime reachability that determines whether a finding is a real risk, which is the basis for its claim to cut false positives.
The competitive exposure is consolidation from above. Palo Alto Networks reportedly tried to acquire Apiiro in 2022, and developer-security and application-security-testing incumbents sell adjacent capabilities that a platform roadmap could extend into posture management. Apiiro competes by being the deepest analysis layer, not the broadest suite. [s4, s2]
Apiiro runs an enterprise sales motion supported by marketplace and channel distribution, with the 2022 raise earmarked primarily for sales and marketing. Named reference customers cluster in regulated financial services, including USAA, BlackRock, TIAA, DTCC, SoFi, and Shell.
Analyst recognition does double duty as proof and demand generation. Being ranked first in ASPM by Gartner and named a leader by IDC and Frost gives enterprise sellers third-party validation that shortens procurement, which matters in a crowded category where buyers struggle to compare claims. SecurityWeek independently reported the $100 million Series B that brought Apiiro's total to $135 million raised since founding. [s7, s2, s3, s15]
Apiiro was founded in 2019 by Idan Plotnik and Yonatan Eldar. Plotnik previously served as a director at Microsoft on the Advanced Threat Analytics and Azure ATP security teams, verifiable prior security leadership at a large vendor before founding Apiiro.
External validation came early with the 2021 RSA Conference Innovation Sandbox win, a contest whose finalists have a documented record of acquisitions and follow-on funding, consistent with scaling an enterprise go-to-market. The NVD record for CVE-2022-24348, a directory traversal flaw in Argo CD, references an Apiiro advisory for it, a concrete signal of the company's published security research beyond the founders' resumes. [s8, s6, s5, s11, s14]
For a product that reads a customer's entire source code, trust collateral is close to a requirement. Apiiro maintains an inspectable trust center hosted on SafeBase that lists ISO/IEC 27001 and SOC 2 certifications and offers a downloadable SOC 2 report, pentest report, and vulnerability assessment alongside standard self-assessments.
Sharing the underlying reports rather than only displaying badges removes a procurement objection that would otherwise stall enterprise deals, signaling the operational maturity a financial-sector buyer expects before granting code access. [s10]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Cycode | competes with | Application security posture management and software supply chain security platform competing for the same enterprise AppSec buyer. | |
| Snyk | competes with | Developer-security platform spanning SAST and SCA that overlaps Apiiro's code and supply chain coverage from a developer-led motion. | |
| Checkmarx | competes with | Established application security testing vendor expanding into ASPM, competing for the enterprise application security budget. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Arnica | competes with | Pipelineless application security platform competing in ASPM, positioned toward developer-native, real-time scanning. | |
| Palo Alto Networks | adjacent | Platform vendor that reportedly pursued an Apiiro acquisition in 2022 and could fold application security posture management into its suite. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with Apiiro.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Apiiro plugs into a customer's development pipeline as an analysis layer a customer can uninstall without changing what it ships. It plugs into source control and build pipelines and maps code to running systems. A customer that drops it must redo that wiring and mapping work. That rework is the main reason to stay. The product is otherwise standard software the customer configures and runs, and its SOC 2 and ISO 27001 certifications match what any vendor reading source code must carry. Rivals face a different barrier, the patented Deep Code Analysis engine behind the number-one ASPM ranking Apiiro attributes to Gartner. Watch whether larger application-security vendors ship engines that map code to running systems the way Apiiro's does.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Apiiro delivers software the customer configures and runs against its own repositories. AutoFix proposes fixes but is automated output, not a human-expertise service that accepts accountability for the result. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The risk graph becomes a system of record wired into source control, CI/CD, and runtime, so leaving means reabsorbing that correlation work. The cost is real in effort to re-integrate rather than in broken production, since the platform is an overlay. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | SOC 2 and ISO 27001 are table-stakes attestations for a vendor reading source code, not a line-specific regulatory mandate that locks buyers in or bars rivals. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Continuously building a code-to-runtime reachability graph across whole codebases and full history is genuinely hard engineering, Apiiro reports Gartner cited the patented engine as the basis for its top ASPM ranking, and an independent review credits the same Deep Code Analysis for understanding code behavior rather than pattern matching. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Apiiro sells to application security leaders at regulated, high-stakes enterprises, with public financial-sector customers including USAA, BlackRock, TIAA, and DTCC, an evidenced demanding buyer rather than an aspirational one. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The platform sits in the development and delivery path through SCM, CI/CD, and IDE integration, but it is an analysis-and-remediation overlay whose removal would not break a customer's running production systems. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Deep Code Analysis is a named, patented engine that a funded rival cannot copy outright, which separates it from unpatented scanner logic. That is protected IP and implementation know-how rather than a proprietary accumulated-data corpus or cross-customer data flywheel, so under the rubric it earns the lower score. |
Apiiro targets the application security leader inside large enterprises, the buyer responsible for securing code across a sprawling estate of repositories, pipelines, and now AI coding agents. The customer logos it displays cluster in regulated, high-stakes industries: USAA, BlackRock, TIAA, SoFi, and DTCC in financial services, plus Shell and Equinix elsewhere.
The segment is deliberately upmarket. Deep Code Analysis pays off most where codebases are large, old, and interconnected, which is precisely the enterprise estate that overwhelms file-by-file scanners. That focus aligns the product with buyers who have budget and consolidation pressure, but it also concedes the developer-led, bottom-up adoption motion to lighter rivals.
The technical core is patented Deep Code Analysis, which continuously reads whole codebases across their history with a call-flow and code-to-runtime reachability engine, then connects the output into a living software graph. Apiiro's own announcement says Gartner cited that engine as the foundation behind its top ASPM ranking, a vendor-relayed characterization of the analyst finding rather than an independently fetched one.
Around the graph, Apiiro runs native scanners for supply chain security, secrets, and open source, and presents itself as an open platform that also ingests third-party findings. The AI advantage is twofold: the graph inventories AI-related code resources as first-class objects, and the AutoFix agent, launched on August 4, 2025, pulls graph, policy, and runtime context into the IDE to propose validated fixes.
An independent ASPM review credits the same Deep Code Analysis and Risk Graph for understanding code behavior and prioritizing risk from code to runtime. The honest limit is that AutoFix is recent, launched in August 2025, so its real-world remediation accuracy is not yet independently established in the reviewed record the way the underlying graph is.
Apiiro runs an enterprise sales motion backed by marketplace and channel distribution. The CEO told CRN the company was expanding channel sales, and the 2022 raise was earmarked primarily for sales and marketing.
Analyst recognition does double duty as demand generation here. Apiiro says Gartner ranked it first in ASPM and that IDC and Frost named it a leader. Relaying that recognition gives enterprise sellers third-party proof that plausibly helps credibility in a crowded category, though no reviewed source measures an effect on buying cycles. SecurityWeek independently reported the $100 million Series B that brought Apiiro's total to $135 million.
No public pricing appeared in the reviewed sources. The visible buying path is a demo request and an enterprise sales conversation. That is standard for a platform sold to large security organizations. An independent ASPM review reports that Apiiro publishes no prices and that its enterprise contracts are custom quoted against deployment scope rather than sold at a list price.
The absence of public, self-serve pricing reinforces the upmarket positioning but offers no transparency signal a buyer could use to compare against a developer-tier rival, and it leaves the per-unit economics unobservable from outside.
Apiiro is delivered as a cloud-native SaaS platform that connects to a customer's source control and CI/CD, maps code to runtime context, and continuously rebuilds the software graph as code changes. The continuous, change-driven model is the operational expression of the product thesis: security follows material changes rather than periodic scans.
Operating this for major enterprises means handling very large codebases and full git history at scale, which is a real engineering burden, but the company publishes a network diagram, a pentest report, and a SOC 2 report through its trust center, signaling operational maturity to security buyers.
Apiiro maintains an inspectable trust center, hosted on SafeBase, that lists ISO/IEC 27001 and SOC 2 certifications alongside a SOC 2 report, a pentest report, a vulnerability assessment, and CAIQ and SIG self-assessments, each document behind a request-access flow. For a vendor that asks to read a customer's entire source code, this attestation depth is closer to a requirement than a differentiator.
That a product reading proprietary source code carries audited certifications and offers the underlying reports on request, rather than only displaying badges, removes a procurement objection that would otherwise stall enterprise deals.
Apiiro positions itself as an open platform: it ships native scanners but also ingests and correlates third-party SAST, SCA, DAST, secrets, and IaC findings into one risk picture. That posture lets it sit above a buyer's existing tools rather than forcing a rip-and-replace, which is the natural consolidation play in a fragmented application security stack.
The ecosystem risk runs the other direction. The same correlation layer is a plausible roadmap item for the platform vendors next to this buyer. Palo Alto Networks reportedly tried to acquire Apiiro in 2022, and larger adjacent application-security vendors sell overlapping capabilities, so the open-platform strategy competes against companies that could fold posture management into a broader suite.
Apiiro was founded in 2019 by Idan Plotnik (CEO) and Yonatan Eldar (CTO). Plotnik previously served as a director at Microsoft on the Advanced Threat Analytics and Azure ATP security teams, verifiable senior security leadership at a large vendor before founding Apiiro.
The early external validation was strong: Apiiro won the RSA Conference Innovation Sandbox in 2021, a contest whose finalists have a documented record of acquisitions and follow-on funding, consistent with a company scaling an enterprise go-to-market rather than a founder-fronted early stage. The NVD record for CVE-2022-24348, a directory traversal flaw in Argo CD, references an Apiiro advisory for it, a concrete signal of the company's published security research.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Apiiro platform: Unified application security | official | 2026-06-20 |
| f2 | CRN on Apiiro Series B (founded 2019, HQ New York, R&D Tel Aviv) | press | 2026-06-20 |
| f3 | Apiiro DCA inventories AI models, AI agents, and MCP servers | official | 2026-06-20 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Apiiro platform: unified application security “Apiiro extends your coverage with native code-based scanners for software supply chain security (SSCS), secrets detection, open source security, and more.” | official | 2026-06-20 |
| s2 | Apiiro on Gartner ranking it #1 in ASPM, 2025 AST Magic Quadrant “Apiiro ranked number one in ASPM capabilities among all vendors with critical AST capabilities. ... Gartner recognized Apiiro's patented Deep Code Analysis (DCA) technology as the foundation behind its #1 ASPM ranking.” | official | 2026-06-20 |
| s3 | Apiiro named a Leader in the Gartner Magic Quadrant for Software Supply Chain Security “Apiiro has been named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security (SSCS) ... addressing coding agents as the new security perimeter” | official | 2026-06-20 |
| s4 | CRN: Apiiro raises $100M after Palo Alto Networks reportedly ends takeover talks “The Series B funding for Apiiro, a cloud-native application security firm with headquarters in New York and R&D operations in Tel Aviv, Israel, brings to $135 million that Apiiro has raised since its founding in 2019.” | press | 2026-06-29 |
| s5 | RSAC: Apiiro named Most Innovative Startup, Innovation Sandbox 2021 “Named the Most Innovative Startup, Apiiro was selected by a panel of esteemed judges for its Code Risk Platform, which provides a 360 view of security and compliance risks across applications, infrastructure and open-source code.” | press | 2026-06-20 |
| s6 | TechTarget: Apiiro wins RSA Conference Innovation Sandbox Contest “The company, based in Tel Aviv, Israel, and founded in 2019, was named Most Innovative Startup at this year's RSA Conference Innovation Sandbox Contest.” | press | 2026-06-20 |
| s7 | Apiiro homepage: recognized as a Leader by Gartner, IDC and Frost & Sullivan; named customers “IDC Recognizes Apiiro as a Leader in the 2025 IDC MarketScape for ASPM ... Frost & Sullivan Ranks Apiiro #1 for Innovation in the 2025 Frost Radar for Global ASPM ... usaa blackrock shell tiaa sofi dtcc” | official | 2026-06-20 |
| s8 | Idan Plotnik LinkedIn: Apiiro co-founder, prior Director at Microsoft (ATA/Azure ATP) “Co-Founder & CEO at Apiiro ... Director, Microsoft Advanced Threat Analytics, Azure ATP” | other | 2026-06-20 |
| s9 | Apiiro AutoFix AI Agent “Introduced in August 2025, AutoFix brings validated, context-aware remediation directly into developer workflows.” | official | 2026-06-20 |
| s10 | Apiiro Trust Center (SafeBase): ISO 27001 and SOC 2 “Compliance ISO/IEC 27001 SOC 2 ... Documents REPORTS SOC 2 Report Pentest Report Vulnerability Assessment Report” | official | 2026-06-20 |
| s11 | Yonatan Eldar LinkedIn: Apiiro co-founder and CTO “Co-Founder & CTO at Apiiro” | other | 2026-06-21 |
| s12 | GlobeNewswire: Apiiro launches AutoFix Agent (August 4, 2025) “August 04, 2025 ... Apiiro, the leading Agentic Application Security Platform, today launched its AutoFix Agent” | press | 2026-06-21 |
| s13 | AppSec Santa: Apiiro Review 2026 (Deep Code Analysis ASPM platform) “Apiiro is an ASPM platform that uses Deep Code Analysis (DCA) and a proprietary Risk Graph to understand code behavior and prioritize risk from code to runtime.” | research | 2026-06-29 |
| s14 | NVD: CVE-2022-24348 (Argo CD directory traversal, Apiiro advisory referenced) “Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go.” | regulatory | 2026-06-29 |
| s15 | SecurityWeek: Cloud-Native Application Security Firm Apiiro Raises $100 Million “Cloud-native application security provider Apiiro this week announced that it has raised $100 million in Series B funding. To date, the company has raised $135 million.” | press | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Apiiro platform: unified application security “Apiiro extends your coverage with native code-based scanners for software supply chain security (SSCS), secrets detection, open source security, and more.” | official | 2026-06-20 |
| s2 | Apiiro on Gartner ranking it #1 in ASPM, 2025 AST Magic Quadrant “Gartner recognized Apiiro's patented Deep Code Analysis (DCA) technology as the foundation behind its #1 ASPM ranking.” | official | 2026-06-20 |
| s3 | Apiiro named a Leader in the Gartner Magic Quadrant for Software Supply Chain Security “Apiiro has been named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security (SSCS).” | official | 2026-06-20 |
| s4 | CRN: Apiiro raises $100M after Palo Alto Networks reportedly ends takeover talks “The Series B funding for Apiiro, a cloud-native application security firm with headquarters in New York and R&D operations in Tel Aviv, Israel, brings to $135 million that Apiiro has raised since its founding in 2019.” | press | 2026-06-29 |
| s5 | RSAC: Apiiro named Most Innovative Startup, Innovation Sandbox 2021 “Named the Most Innovative Startup, Apiiro was selected by a panel of esteemed judges for its Code Risk Platform, which provides a 360 view of security and compliance risks across applications, infrastructure and open-source code.” | press | 2026-06-20 |
| s6 | TechTarget: Apiiro wins RSA Conference Innovation Sandbox Contest “The company, based in Tel Aviv, Israel, and founded in 2019, was named Most Innovative Startup at this year's RSA Conference Innovation Sandbox Contest.” | press | 2026-06-20 |
| s7 | Apiiro Trust Center (SafeBase): ISO 27001 and SOC 2 “Compliance ISO/IEC 27001 SOC 2 ... Documents REPORTS SOC 2 Report Pentest Report Vulnerability Assessment Report” | official | 2026-06-20 |
| s8 | Apiiro homepage: recognized as a Leader by Gartner, IDC and Frost & Sullivan “Apiiro Recognized as a Leader by Gartner, IDC and Frost & Sullivan ... IDC Recognizes Apiiro as a Leader in the 2025 IDC MarketScape for ASPM ... Frost & Sullivan Ranks Apiiro #1 for Innovation in the 2025 Frost Radar for Global ASPM” | official | 2026-06-20 |
| s9 | Apiiro AutoFix AI Agent “Introduced in August 2025, AutoFix brings validated, context-aware remediation directly into developer workflows.” | official | 2026-06-20 |
| s10 | Idan Plotnik LinkedIn: Apiiro co-founder, prior Director at Microsoft (ATA/Azure ATP) “Co-Founder & CEO at Apiiro ... Director, Microsoft Advanced Threat Analytics, Azure ATP” | other | 2026-06-20 |
| s11 | Apiiro homepage: named enterprise customers and testimonials “usaa blackrock schrodinger shell jackhenry tiaa c.h.robinson equinix sofi dtcc ... Our overarching goal is to keep Shell safe ... Adam Jordan ... Shell ... Zach Schulze ... SoFi” | official | 2026-06-20 |
| s12 | Yonatan Eldar LinkedIn: Apiiro co-founder and CTO “Co-Founder & CTO at Apiiro” | other | 2026-06-21 |
| s13 | GlobeNewswire: Apiiro launches AutoFix Agent (August 4, 2025) “August 04, 2025 ... Apiiro, the leading Agentic Application Security Platform, today launched its AutoFix Agent” | press | 2026-06-21 |
| s14 | AppSec Santa: Apiiro Review 2026 (Deep Code Analysis ASPM platform) “Apiiro is an ASPM platform that uses Deep Code Analysis (DCA) and a proprietary Risk Graph to understand code behavior and prioritize risk from code to runtime.” | research | 2026-06-29 |
| s15 | NVD: CVE-2022-24348 (Argo CD directory traversal, Apiiro advisory referenced) “Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go.” | regulatory | 2026-06-29 |
| s16 | SecurityWeek: Cloud-Native Application Security Firm Apiiro Raises $100 Million “Cloud-native application security provider Apiiro this week announced that it has raised $100 million in Series B funding. To date, the company has raised $135 million.” | press | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.