Corridor

Security for AI Application SecurityDeveloper Tools also known as Corridor Security Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2025
Last updated 2026-09-11

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Corridor sells software that feeds security guidance to AI coding tools such as Cursor and Claude Code as they write code and reviews every pull request. It sells to developers and teams, and its named customers are WitnessAI, Sublime Security, Pylon, Casca, and AppOmni. Founded in 2025, it raised a $25 million Series A led by Felicis, with angel investors from Anthropic, OpenAI, and Cursor. Its leadership is its strongest asset. CEO Jack Cable led the Secure by Design program at CISA, the US cybersecurity agency, and product chief Alex Stamos was security chief at Facebook, Yahoo, and SentinelOne. The makers of the coding tools it integrates with could build the same guidance and pull-request review. Corridor depends on those integrations and on its own execution.

Sourced Details

Description Corridor builds a security platform that embeds real-time controls into AI coding workflows to prevent vulnerabilities as code is generated. [f1]
Founded 2025 [f2]
HQ San Francisco, CA [f3]
Latest funding $25M Series A (March 2026) [f3]

Products

Product What it does
Corridor Security guardrails, an MCP server, and agent hooks that inject security context into coding agents and review every pull request for vulnerabilities.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Corridor injects security context into AI coding agents and reviews every pull request for vulnerabilities (AI-Generated Code). Its MCP server and agent hooks track which AI coding tools operate across an organization (AI Orchestration Tools). Mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Corridor names the security and product-security buyer and cites research that capable models write correct and secure code little more than half the time, but that quantification reaches the reader through Corridor's blog and an investor (Felicis) post rather than multiple independent sources. [s3, s9]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Documented capabilities span an MCP server, agent hooks that scan each file edit, PR review, and custom guardrails, but the product reached general availability only in October 2025 and lacks the depth record of mature scanners. [s1, s3, s5]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The main demand evidence is the 25 million dollar March 2026 round and AI-vendor angel participation, which is investor rather than buyer demand, and the buyer-side signal is early adoption in a still-forming category, so timing reads as plausible but indirect. [s4, s9]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Jack Cable's Secure by Design record at CISA, Alex Stamos's recognized security leadership, and Ashwin Ramaswami's Stanford publications are a sustained standards and publication record, but no founder shows a category-defining prior exit. [s2, s8, s9]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 The homepage carries five named customer testimonials from security leaders at WitnessAI, Sublime Security, Pylon, Casca, and AppOmni, and the product ships through the Vercel Marketplace, multiple named references lifted further by elite venture and AI-vendor angel backing as an indirect signal. [s1, s5, s9]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A $25M Series A in March 2026 is sized to the early enterprise motion, and the company shipped a steady stream of integrations (Cursor, Factory, Vercel) in its first year, output proportional to its stage. [s4, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Corridor coined Agentic Coding Security Management and concedes it does not fit existing categories, and public evidence does not yet show it as an established budget line, though its adjacency to application security and code scanning lets buyers place it without coaching. [s3]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 The core guardrail-and-PR-review capability is a plausible feature for the AI coding platforms Corridor integrates with, or for established code-security vendors to add, and no proprietary data asset or deep workflow lock-in appears in the public record yet. [s1, s3]
Business Risks The AI coding platforms Corridor integrates with, such as Cursor and GitHub Copilot, could ship native security guardrails and absorb the core capability…
  • The AI coding platforms Corridor integrates with, such as Cursor and GitHub Copilot, could ship native security guardrails and absorb the core capability.
  • Established code-security vendors such as Semgrep and Snyk could extend their scanners to target AI-generated code and compete on installed base.
  • The self-coined Agentic Coding Security Management category may fail to gain buyer adoption, leaving Corridor sold against existing application-security budgets.
  • Public traction depends on homepage testimonials rather than disclosed deployment metrics, so the breadth of production use behind the funding is unverified.
Problem & Market Corridor targets the gap that AI coding assistants opened between the speed of code generation and the pace of security review. The company argues that developers now ship code faster than humans can review it, and that traditional tools catch vulnerabilities only after code is written. The pitch names a concrete buyer and a measurable pain. Corridor cites research that even capable models produce code that is both correct and secure just over half the time, and frames the threat as AI also helping attackers weaponize flaws faster. That gives security teams a reason to act now rather than absorb a growing backlog of post-hoc findings. The market sits adjacent to established application-security and code-scanning budgets rather than in a slot buyers already name. Corridor coined a category label, Agentic Coding Security Management, and openly concedes its scope does not fit existing product categories…

Corridor targets the gap that AI coding assistants opened between the speed of code generation and the pace of security review. The company argues that developers now ship code faster than humans can review it, and that traditional tools catch vulnerabilities only after code is written.

The pitch names a concrete buyer and a measurable pain. Corridor cites research that even capable models produce code that is both correct and secure just over half the time, and frames the threat as AI also helping attackers weaponize flaws faster. That gives security teams a reason to act now rather than absorb a growing backlog of post-hoc findings.

The market sits adjacent to established application-security and code-scanning budgets rather than in a slot buyers already name. Corridor coined a category label, Agentic Coding Security Management, and openly concedes its scope does not fit existing product categories. [s1, s3]

Product Capabilities Corridor injects security context into the coding workflow through an MCP server and agent hooks that scan every file edit in real time, integrating with Cursor, Claude Code, Copilot, Factory, and others. The aim is to guide agents toward secure code before a vulnerability is written, then test what the agent produced. The product also reviews every pull request, flagging issues such as insecure file downloads or broken access control and offering remediation guidance, and can enforce merge protections. A second layer gives security teams visibility into which AI tools developers use, what code those tools generate, and which MCP servers are in play. Pricing is public and self-serve at the low end, a twenty-dollar per month individual tier and a forty-dollar per developer per month team tier, with a contact-sales enterprise tier above them. That transparency lowers the cost of trying the product, though it says nothing about how hard the product is to leave once a team's review process depends on it…

Corridor injects security context into the coding workflow through an MCP server and agent hooks that scan every file edit in real time, integrating with Cursor, Claude Code, Copilot, Factory, and others. The aim is to guide agents toward secure code before a vulnerability is written, then test what the agent produced.

The product also reviews every pull request, flagging issues such as insecure file downloads or broken access control and offering remediation guidance, and can enforce merge protections. A second layer gives security teams visibility into which AI tools developers use, what code those tools generate, and which MCP servers are in play.

Pricing is public and self-serve at the low end, a twenty-dollar per month individual tier and a forty-dollar per developer per month team tier, with a contact-sales enterprise tier above them. That transparency lowers the cost of trying the product, though it says nothing about how hard the product is to leave once a team's review process depends on it. [s1, s6]

Competitive Positioning Corridor positions itself against static-analysis tools by moving security to the moment of generation rather than scanning after the fact. It argues SAST products create remediation backlogs and carry high false-positive rates, and that the next wave of code security should prevent work rather than add it. The differentiator is the prevention-at-generation architecture combined with the team behind it. Where traditional static-analysis tools scan code that already exists, Corridor aims to shape what the agent writes from the outset. That difference is real, but the integrations it depends on are ones the same coding platforms and established scanners could build themselves…

Corridor positions itself against static-analysis tools by moving security to the moment of generation rather than scanning after the fact. It argues SAST products create remediation backlogs and carry high false-positive rates, and that the next wave of code security should prevent work rather than add it.

The differentiator is the prevention-at-generation architecture combined with the team behind it. Where traditional static-analysis tools scan code that already exists, Corridor aims to shape what the agent writes from the outset. That difference is real, but the integrations it depends on are ones the same coding platforms and established scanners could build themselves. [s3, s5]

Go-to-Market & Traction Corridor reached general availability in October 2025 and now shows five named customer testimonials on its homepage, from security leaders at WitnessAI, Sublime Security, Pylon, Casca, and AppOmni, alongside availability in the Vercel Marketplace. Its investor base is unusually concentrated for the stage. The March 2026 round drew angels from Anthropic, OpenAI, Cursor, Cognition, Factory, and Lovable, the AI coding vendors whose output Corridor secures. That backing reads as ecosystem demand for a neutral security layer, but it also names the parties able to build the capability in-house. The breadth of production deployment behind the funding is not yet public, since the proof is testimonials rather than disclosed deployment metrics or case studies…

Corridor reached general availability in October 2025 and now shows five named customer testimonials on its homepage, from security leaders at WitnessAI, Sublime Security, Pylon, Casca, and AppOmni, alongside availability in the Vercel Marketplace. Its investor base is unusually concentrated for the stage.

The March 2026 round drew angels from Anthropic, OpenAI, Cursor, Cognition, Factory, and Lovable, the AI coding vendors whose output Corridor secures. That backing reads as ecosystem demand for a neutral security layer, but it also names the parties able to build the capability in-house. The breadth of production deployment behind the funding is not yet public, since the proof is testimonials rather than disclosed deployment metrics or case studies. [s1, s4, s5, s9]

Team & Credibility Corridor's leadership is the clearest present-day strength…

Corridor's leadership is the clearest present-day strength. CEO Jack Cable helped start the federal Secure by Design initiative at CISA and is a top-ranked bug bounty hunter, and chief product officer Alex Stamos served as security chief at Facebook, Yahoo, and SentinelOne.

CTO Ashwin Ramaswami is a published AI and foundation-models researcher at Stanford, pairing the security pedigree with model-side depth. That combination gives Corridor credibility with both security buyers and the AI coding vendors it partners with, though credibility is not yet matched by a public record of broad production traction. [s2, s8, s9]

Trust Readiness Corridor publishes a vulnerability disclosure policy with a 90-day coordinated-disclosure window and safe-harbor language, signaling a security-first posture appropriate to its buyer. It also states a privacy policy and customer-agreement framework covering how it processes code and AI-feature inputs. Corridor's trust center at trust.corridor.dev publishes a SOC 2 Type I report and named security policies, so an inspectable third-party attestation exists. The Type I scope is narrower than the SOC 2 Type II the established scanners it competes against typically carry, so the readiness gap is the report's depth rather than its absence…

Corridor publishes a vulnerability disclosure policy with a 90-day coordinated-disclosure window and safe-harbor language, signaling a security-first posture appropriate to its buyer. It also states a privacy policy and customer-agreement framework covering how it processes code and AI-feature inputs.

Corridor's trust center at trust.corridor.dev publishes a SOC 2 Type I report and named security policies, so an inspectable third-party attestation exists. The Type I scope is narrower than the SOC 2 Type II the established scanners it competes against typically carry, so the readiness gap is the report's depth rather than its absence. [s10, s11, s12]

Competitors Semgrep, Snyk, Almanax, Backline AI…
Company Relationship Note Compare
Semgrep competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Snyk competes with
Almanax competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Backline AI competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Corridor.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

The hard part of Corridor is real engineering. Steering AI coding agents toward secure code and catching exploitable flaws across languages is specialized security engineering under adversarial pressure. Little else resists copying. Customers buy software they connect and run, the SOC 2 Type I attestation is a bar rivals commonly clear, and the public record names no proprietary dataset. A team adopts Corridor self-serve and can later move its review to another tool, so the lock is workflow habit, not data a rival could not assemble. Corridor's core risk is that its guardrails and pull-request review are a feature the coding platforms it plugs into, or established scanners, could add. It stays defensible by staying embedded and out-executing them, not an asset rivals cannot obtain.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Corridor sells software teams connect and run, priced self-serve per developer, and pays out as guardrails, pull-request review, and visibility features rather than a human-expertise or accountability layer, the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Agent hooks in the IDE and a pull-request review bot weave into the coding workflow, so a security team's review process can come to depend on Corridor, but the record documents no migration cost or data lock that would block substituting another scanner.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Corridor holds a SOC 2 Type I attestation and publishes standard security policies, a bar rivals commonly clear, with no line-specific certification or regulatory mandate that requires this product.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Steering AI coding agents toward secure code and catching exploitable flaws across many languages and multiple agent tools is specialized security engineering, the same difficulty class that defends the established code-security products.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Named references are security leaders at real companies, but the self-serve, per-developer motion blends the buyer toward individual development teams rather than a regulated enterprise roster with high switching budgets.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Corridor sits in the coding and pull-request pipeline as security tooling rather than the running application, so removing it drops the review gate without breaking production, the mid-layer position.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Public materials describe security-context injection and LLM-assisted review and name no non-public dataset a funded rival could not assemble, so the detection asset is replicable.
Strategic Market Segmentation Corridor targets security and product-security teams that want developers to use AI coding tools without shipping vulnerabilities, and it reaches them through the developers' own workflow…

Corridor targets security and product-security teams that want developers to use AI coding tools without shipping vulnerabilities, and it reaches them through the developers' own workflow. The product plugs into coding agents such as Cursor and Claude Code and reviews pull requests, so adoption can start inside engineering rather than requiring a top-down security rollout.

The company frames its market as a new category it calls Agentic Coding Security Management, set against static-analysis tools that review code after it is written. Corridor argues that after-the-fact scanning builds a remediation backlog and that code security should shift to preventing flaws at the moment of generation.

The served buyer spans individual developers and security leaders. Self-serve pricing points at teams adopting the tool directly, while the named references are security executives, so Corridor sits between a bottom-up developer tool and a security-team purchase rather than squarely in either.

Product Capabilities & AI Advantages Corridor's core capability is preventing insecure code as AI agents generate it, then reviewing what they produce…

Corridor's core capability is preventing insecure code as AI agents generate it, then reviewing what they produce. Its MCP server and agent hooks feed security context to coding agents and scan every file edit in real time, and the product reviews every pull request for flaws such as SQL injection or use-after-free before they merge.

A second layer gives security teams visibility into AI coding activity. Corridor reports which AI tools developers use and what those tools generate, and enforces custom guardrails and merge protections, so a security team can see and shape agent behavior across the organization.

Corridor builds its advantage on engineering and integration rather than an owned data asset. The differentiation is moving security to the moment of generation, but the detection record is young and the public record names no proprietary corpus behind it, so the edge is the approach and the execution rather than an accumulating dataset.

Sales Engagement & Go-to-Market Corridor runs a product-led motion that starts inside the developer workflow and layers a security-team sale on top…

Corridor runs a product-led motion that starts inside the developer workflow and layers a security-team sale on top. It ships through its own app, the Vercel Marketplace, and the coding-agent MCP marketplaces, so a developer can adopt it without a procurement cycle.

The commercial proof is named references rather than disclosed deployment metrics. The homepage carries testimonials from security leaders at WitnessAI, Sublime Security, Pylon, Casca, and AppOmni, and Corridor's lead investor names Sublime Security and Pylon as production users. Named accounts with named roles are concrete evidence a buyer can check.

The investor base doubles as a credibility signal and a caution. Individual angels affiliated with Anthropic, OpenAI, Cursor, and other AI coding vendors lend standing in the ecosystems Corridor secures, though angel affiliation is not a channel, and the breadth of paid production use behind that backing is not yet public.

Pricing Model Corridor publishes transparent, self-serve pricing at the low end…

Corridor publishes transparent, self-serve pricing at the low end. A twenty-dollar individual plan and a forty-dollar per-developer team plan cover real-time pull-request review, in-IDE secure-code guidance through its MCP server, and auto-generated guardrails, with a contact-sales enterprise tier above them.

Corridor charges by the developer, defined as each unique developer interacting with the product across the IDE extension, the platform, and pull-request submissions. Charging per developer ties price to the population whose output the product secures, which is the unit a buyer already uses to size engineering.

Public pricing lowers the cost of trying Corridor but says little about switching cost. Transparent low-end tiers ease evaluation, while the enterprise tier stays negotiated, so the site shows what entry costs without revealing how hard the product is to leave once a team's review process depends on it.

Product Delivery & Operations Corridor delivers as a connected service wired into the places code already moves…

Corridor delivers as a connected service wired into the places code already moves. It integrates with coding agents including Cursor, Claude Code, Windsurf, Factory, and Devin, with GitHub pull requests, and with Vercel, returning guidance in the developer's normal flow rather than a separate console.

The product operates at two points in the lifecycle. Agent hooks act during generation inside the IDE, and the pull-request review bot acts at the merge gate, so Corridor covers both the moment code is written and the moment it enters the shared codebase.

The operational record is young. Corridor reached general availability recently and shows integration breadth, but the public record does not yet document large-scale production deployments that would prove the pipeline holds at enterprise volume.

Earning Customers' Trust Corridor publishes a security posture appropriate to its buyer…

Corridor publishes a security posture appropriate to its buyer. It runs a vulnerability disclosure policy with a 90-day coordinated-disclosure window and safe-harbor language, signaling the security-first stance its security-team buyers expect.

Corridor's trust center publishes a SOC 2 Type I report and a set of named security policies covering information security, risk management, and customer data handling, so an inspectable third-party attestation exists in its point-in-time Type I form.

For an early company the attestation clears an objection without creating an advantage. A SOC 2 report and a published disclosure policy support adoption rather than set Corridor apart.

Platform Strategy & Ecosystem Positioning Corridor positions as a security layer embedded in other companies' platforms rather than a platform of its own…

Corridor positions as a security layer embedded in other companies' platforms rather than a platform of its own. It lives inside coding agents, GitHub, and Vercel, which gives it distribution into where developers already work and makes those hosts both channel and potential competitor.

The marketplace presence is the platform-adjacent strength. Corridor ships through the Vercel Marketplace and the Cursor, Devin, and Windsurf MCP marketplaces, reaching buyers inside the tools they already run.

The dependency cuts both ways. The coding platforms Corridor plugs into, and their model providers, could each move the same guardrails and review into their own products, so the integrations that provide reach also define the exposure.

Team & Execution Capability Corridor's clearest present strength is its leadership…

Corridor's clearest present strength is its leadership. CEO Jack Cable helped start the federal Secure by Design initiative at CISA and is a top-ranked bug bounty hunter, and chief product officer Alex Stamos was security chief at Facebook, Yahoo, and SentinelOne.

CTO Ashwin Ramaswami pairs the security pedigree with model-side depth as a published AI and foundation-models researcher at Stanford. The combination gives Corridor credibility with both security buyers and the AI coding vendors it partners with.

The open execution question is scale. The team has shipped a credible product and attracted individual angels affiliated with the AI coding vendors it integrates with, but a public record of broad production traction has not yet caught up to the pedigree.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Corridor: Series A announcement official 2026-06-24
f2 The SaaS News: Corridor Raises $25M Series A press 2026-06-24
f3 FinSMEs: Corridor Raises $25M in Series A Funding press 2026-06-24
f4 Corridor: Introducing Agentic Coding Security Management official 2026-06-24
Profile Analysis Sources (12)
Id Source Tier Accessed
s1 Corridor homepage
“Agent hooks scan every file edit in real time, Cursor, Claude Code, and more. Customer testimonials from Mathew Solnik (CISO, WitnessAI), Andrew Becherer (CISO, Sublime Security), Aashish Kapur (Security Lead, Pylon), Blake Dunson (Casca), and Cory Michal (VP of Information Security, AppOmni).”
official 2026-06-24
s2 Corridor About page
“Jack Cable, Co-founder & CEO. Hacked the Pentagon at 16. Top-ranked bug bounty hunter. Led Secure by Design at CISA. Alex Stamos, Chief Product Officer. Former Chief Security Officer at Facebook, Yahoo, and SentinelOne.”
official 2026-06-24
s3 Corridor: Introducing Agentic Coding Security Management
“the best models write both correct and secure code just over half the time”
official 2026-06-24
s4 Corridor: Series A announcement
“Corridor ... has raised a $25 million Series A at a $200 million valuation, led by Felicis, with participation from Conviction, Timeless, Artisanal Ventures, Lux Capital, Sunflower Capital, Datadog, SV Angel, and leading angels from Anthropic, OpenAI, Cursor, Cognition, Factory, Lovable”
official 2026-06-24
s5 Corridor: General availability launch
“We're thrilled to announce that Corridor is now officially generally available. ... You can now access Corridor directly through our app, in the Vercel Marketplace”
official 2026-06-24
s6 Corridor pricing
“$20 /month For individual developers ... $40 /developer/month All features in Pro, plus: Deploy Corridor across your team”
official 2026-06-24
s7 FinSMEs: Corridor Raises $25M in Series A Funding
“Corridor, a San Francisco, CA-based provider of a security platform for AI-native software development, raised $25m in Series A funding, at a $200m valuation.”
press 2026-06-24
s8 The SaaS News: Corridor Raises $25M Series A at $200M Valuation
“Founded in 2025 by Jack Cable and Ashwin Ramaswami, Corridor is a company that builds security infrastructure for AI-native software development.”
press 2026-06-24
s9 Felicis: Proactive Security for the Code Gen Era
“its product is already supercharging some of the most forward-thinking and productive teams, including those at Sublime Security and Pylon.”
press 2026-06-24
s10 Corridor vulnerability disclosure policy
“Provide us a reasonable amount of time (at least 90 days from the initial report) to resolve the issue before you disclose it publicly”
official 2026-06-24
s11 Corridor privacy policy
“Access or use our products and services, such as our code security platform, including our Plugins and AI Features”
official 2026-06-24
s12 Corridor Trust Center
“Compliance: SOC 2. Resources: Corridor SOC 2 Type I, Information Security Policy, Risk Management Policy.”
official 2026-06-24
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 Corridor homepage
“Corridor's MCP server and agent hooks integrate directly with your coding tools, preventing vulnerabilities before they're even written. Proactive guardrails give coding agents the context they need to write secure code. Agent hooks scan every file edit in real time, Cursor, Claude Code, and more.”
official 2026-07-08
s2 Corridor homepage customer testimonials
“Mathew Solnik, CISO, WitnessAI. Andrew Becherer, CISO, Sublime Security. Aashish Kapur, Security Lead, Pylon. Blake Dunson, Head of Security & Reliability, Casca. Cory Michal, VP of Information Security, AppOmni.”
official 2026-07-08
s3 Corridor About page leadership
“Jack Cable, Co-founder & CEO. Top-ranked bug bounty hunter. Led Secure by Design at CISA. Ashwin Ramaswami, Co-founder & CTO. Published researcher in AI & foundation models at Stanford. Alex Stamos, Chief Product Officer. Former Chief Security Officer at Facebook, Yahoo, and SentinelOne.”
official 2026-07-08
s4 Corridor pricing
“$20 /month For individual developers ... $40 /developer/month All features in Pro, plus: Deploy Corridor across your team ... The developer count is based on the number of unique developers interacting with Corridor across the IDE extension, the Corridor platform, and submitters of pull requests.”
official 2026-07-08
s5 Corridor: Series A announcement
“Corridor ... has raised a $25 million Series A at a $200 million valuation, led by Felicis, with participation from Conviction, Timeless, Artisanal Ventures, Lux Capital, Sunflower Capital, Datadog, SV Angel, and leading angels from Anthropic, OpenAI, Cursor, Cognition, Factory, Lovable, and more.”
official 2026-07-08
s6 Corridor: Introducing Agentic Coding Security Management
“We proactively inject relevant security context into the AI coding workflow to prevent standard security flaws, such as SQL injections in web apps or use-after-free flaws in C++ code. Traditional static-analysis (SAST) tools focus on reviewing code after the fact.”
official 2026-07-08
s7 Corridor: General availability launch
“We're thrilled to announce that Corridor is now officially generally available. You can now access Corridor through our app, in the Vercel Marketplace, or through Cursor, Devin, and Windsurf's Model Context Protocol (MCP) marketplaces. Automatically review every pull request.”
official 2026-07-08
s8 Corridor vulnerability disclosure policy
“Provide us a reasonable amount of time (at least 90 days from the initial report) to resolve the issue before you disclose it publicly.”
official 2026-07-08
s9 Corridor Trust Center
“SOC 2. Corridor SOC 2 Type I 04.01.26.pdf. Information Security Policy, Risk Management Policy, Operations Security Policy, Customer Data Handling Policy.”
official 2026-07-08
s10 FinSMEs: Corridor Raises $25M in Series A Funding
“Corridor, a San Francisco, CA-based provider of a security platform for AI-native software development, raised $25m in Series A funding, at a $200m valuation.”
press 2026-07-08
s11 The SaaS News: Corridor Raises $25M Series A at $200M Valuation
“Corridor, a San Francisco, CA-based security platform built for AI-native software development, has raised a $25 million Series A at a $200 million valuation.”
press 2026-07-08
s12 Felicis: Proactive Security for the Code Gen Era
“its product is already supercharging some of the most forward-thinking and productive teams, including those at Sublime Security and Pylon.”
press 2026-07-08

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.