All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Apiiro sells an application security platform to large enterprise security teams, built on patented Deep Code Analysis, an engine that maps code to runtime across full git history and inventories what AI coding agents now produce. Apiiro says Gartner ranked it first in application security posture management on the strength of that engine, while IDC named it a Leader and Frost ranked it top for innovation. Named customers include USAA, BlackRock, Shell, and TIAA. The patented engine is the part hardest for a funded rival to reproduce quickly, and it holds Apiiro above the developer-tier scanner cluster. Its AutoFix agent, launched in August 2025, is recent enough that no outside review speaks to its accuracy, while the engine at least has independent descriptive coverage.
| Description | Application security posture management platform that uses patented Deep Code Analysis to inventory code from design to runtime, builds a risk graph, and uses an AI agent to triage and fix application and supply chain risks. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | New York, New York, United States | [f2] |
| Funding | $135M total | [f2] |
| Latest funding | Series B, $100M (2022), led by General Catalyst | [f2] |
| Product | What it does |
|---|---|
| Apiiro Application Security Platform | ASPM platform unifying design-time threat modeling, SAST, SCA, secrets, IaC, API, and supply chain risk into one risk graph built on Deep Code Analysis, with native scanners on an open platform. |
| Deep Code Analysis (DCA) | Patented engine that continuously analyzes whole codebases with call-flow and code-to-runtime reachability, inventorying APIs, dependencies, secrets, AI models, AI agents, and MCP servers. |
| AutoFix AI Agent | AI agent introduced in August 2025 that pulls software graph, policy, and runtime context into the IDE to propose validated triage and remediation for design and code risks. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The Apiiro Application Security Platform inventories, prioritizes, and remediates risks across applications, code, and the software supply chain. This conventional application security maps to the Cyber Defense Matrix. [f1]
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
AutoFix secures code produced by AI coding assistants, and Deep Code Analysis inventories AI models, AI agents, and MCP servers. These lines map to the AI Defense Matrix. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Apiiro platform: Unified application security | official | 2026-06-20 |
| f2 | CRN on Apiiro Series B (founded 2019, HQ New York, R&D Tel Aviv) | press | 2026-06-20 |
| f3 | Apiiro DCA inventories AI models, AI agents, and MCP servers | official | 2026-06-20 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Apiiro platform: unified application security “Apiiro extends your coverage with native code-based scanners for software supply chain security (SSCS), secrets detection, open source security, and more.” | official | 2026-06-20 |
| s2 | Apiiro on Gartner ranking it #1 in ASPM, 2025 AST Magic Quadrant “Apiiro ranked number one in ASPM capabilities among all vendors with critical AST capabilities. ... Gartner recognized Apiiro's patented Deep Code Analysis (DCA) technology as the foundation behind its #1 ASPM ranking.” | official | 2026-06-20 |
| s3 | Apiiro named a Leader in the Gartner Magic Quadrant for Software Supply Chain Security “Apiiro has been named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security (SSCS) ... addressing coding agents as the new security perimeter” | official | 2026-06-20 |
| s4 | CRN: Apiiro raises $100M after Palo Alto Networks reportedly ends takeover talks “The Series B funding for Apiiro, a cloud-native application security firm with headquarters in New York and R&D operations in Tel Aviv, Israel, brings to $135 million that Apiiro has raised since its founding in 2019.” | press | 2026-06-29 |
| s5 | RSAC: Apiiro named Most Innovative Startup, Innovation Sandbox 2021 “Named the Most Innovative Startup, Apiiro was selected by a panel of esteemed judges for its Code Risk Platform, which provides a 360 view of security and compliance risks across applications, infrastructure and open-source code.” | press | 2026-06-20 |
| s6 | TechTarget: Apiiro wins RSA Conference Innovation Sandbox Contest “The company, based in Tel Aviv, Israel, and founded in 2019, was named Most Innovative Startup at this year's RSA Conference Innovation Sandbox Contest.” | press | 2026-06-20 |
| s7 | Apiiro homepage: recognized as a Leader by Gartner, IDC and Frost & Sullivan; named customers “IDC Recognizes Apiiro as a Leader in the 2025 IDC MarketScape for ASPM ... Frost & Sullivan Ranks Apiiro #1 for Innovation in the 2025 Frost Radar for Global ASPM ... usaa blackrock shell tiaa sofi dtcc” | official | 2026-06-20 |
| s8 | Idan Plotnik LinkedIn: Apiiro co-founder, prior Director at Microsoft (ATA/Azure ATP) “Co-Founder & CEO at Apiiro ... Director, Microsoft Advanced Threat Analytics, Azure ATP” | other | 2026-06-20 |
| s9 | Apiiro AutoFix AI Agent “Introduced in August 2025, AutoFix brings validated, context-aware remediation directly into developer workflows.” | official | 2026-06-20 |
| s10 | Apiiro Trust Center (SafeBase): ISO 27001 and SOC 2 “Compliance ISO/IEC 27001 SOC 2 ... Documents REPORTS SOC 2 Report Pentest Report Vulnerability Assessment Report” | official | 2026-06-20 |
| s11 | Yonatan Eldar LinkedIn: Apiiro co-founder and CTO “Co-Founder & CTO at Apiiro” | other | 2026-06-21 |
| s12 | GlobeNewswire: Apiiro launches AutoFix Agent (August 4, 2025) “August 04, 2025 ... Apiiro, the leading Agentic Application Security Platform, today launched its AutoFix Agent” | press | 2026-06-21 |
| s13 | AppSec Santa: Apiiro Review 2026 (Deep Code Analysis ASPM platform) “Apiiro is an ASPM platform that uses Deep Code Analysis (DCA) and a proprietary Risk Graph to understand code behavior and prioritize risk from code to runtime.” | research | 2026-06-29 |
| s14 | NVD: CVE-2022-24348 (Argo CD directory traversal, Apiiro advisory referenced) “Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go.” | regulatory | 2026-06-29 |
| s15 | SecurityWeek: Cloud-Native Application Security Firm Apiiro Raises $100 Million “Cloud-native application security provider Apiiro this week announced that it has raised $100 million in Series B funding. To date, the company has raised $135 million.” | press | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Apiiro platform: unified application security “Apiiro extends your coverage with native code-based scanners for software supply chain security (SSCS), secrets detection, open source security, and more.” | official | 2026-06-20 |
| s2 | Apiiro on Gartner ranking it #1 in ASPM, 2025 AST Magic Quadrant “Gartner recognized Apiiro's patented Deep Code Analysis (DCA) technology as the foundation behind its #1 ASPM ranking.” | official | 2026-06-20 |
| s3 | Apiiro named a Leader in the Gartner Magic Quadrant for Software Supply Chain Security “Apiiro has been named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security (SSCS).” | official | 2026-06-20 |
| s4 | CRN: Apiiro raises $100M after Palo Alto Networks reportedly ends takeover talks “The Series B funding for Apiiro, a cloud-native application security firm with headquarters in New York and R&D operations in Tel Aviv, Israel, brings to $135 million that Apiiro has raised since its founding in 2019.” | press | 2026-06-29 |
| s5 | RSAC: Apiiro named Most Innovative Startup, Innovation Sandbox 2021 “Named the Most Innovative Startup, Apiiro was selected by a panel of esteemed judges for its Code Risk Platform, which provides a 360 view of security and compliance risks across applications, infrastructure and open-source code.” | press | 2026-06-20 |
| s6 | TechTarget: Apiiro wins RSA Conference Innovation Sandbox Contest “The company, based in Tel Aviv, Israel, and founded in 2019, was named Most Innovative Startup at this year's RSA Conference Innovation Sandbox Contest.” | press | 2026-06-20 |
| s7 | Apiiro Trust Center (SafeBase): ISO 27001 and SOC 2 “Compliance ISO/IEC 27001 SOC 2 ... Documents REPORTS SOC 2 Report Pentest Report Vulnerability Assessment Report” | official | 2026-06-20 |
| s8 | Apiiro homepage: recognized as a Leader by Gartner, IDC and Frost & Sullivan “Apiiro Recognized as a Leader by Gartner, IDC and Frost & Sullivan ... IDC Recognizes Apiiro as a Leader in the 2025 IDC MarketScape for ASPM ... Frost & Sullivan Ranks Apiiro #1 for Innovation in the 2025 Frost Radar for Global ASPM” | official | 2026-06-20 |
| s9 | Apiiro AutoFix AI Agent “Introduced in August 2025, AutoFix brings validated, context-aware remediation directly into developer workflows.” | official | 2026-06-20 |
| s10 | Idan Plotnik LinkedIn: Apiiro co-founder, prior Director at Microsoft (ATA/Azure ATP) “Co-Founder & CEO at Apiiro ... Director, Microsoft Advanced Threat Analytics, Azure ATP” | other | 2026-06-20 |
| s11 | Apiiro homepage: named enterprise customers and testimonials “usaa blackrock schrodinger shell jackhenry tiaa c.h.robinson equinix sofi dtcc ... Our overarching goal is to keep Shell safe ... Adam Jordan ... Shell ... Zach Schulze ... SoFi” | official | 2026-06-20 |
| s12 | Yonatan Eldar LinkedIn: Apiiro co-founder and CTO “Co-Founder & CTO at Apiiro” | other | 2026-06-21 |
| s13 | GlobeNewswire: Apiiro launches AutoFix Agent (August 4, 2025) “August 04, 2025 ... Apiiro, the leading Agentic Application Security Platform, today launched its AutoFix Agent” | press | 2026-06-21 |
| s14 | AppSec Santa: Apiiro Review 2026 (Deep Code Analysis ASPM platform) “Apiiro is an ASPM platform that uses Deep Code Analysis (DCA) and a proprietary Risk Graph to understand code behavior and prioritize risk from code to runtime.” | research | 2026-06-29 |
| s15 | NVD: CVE-2022-24348 (Argo CD directory traversal, Apiiro advisory referenced) “Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go.” | regulatory | 2026-06-29 |
| s16 | SecurityWeek: Cloud-Native Application Security Firm Apiiro Raises $100 Million “Cloud-native application security provider Apiiro this week announced that it has raised $100 million in Series B funding. To date, the company has raised $135 million.” | press | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.