Legit Security

Security for AI also known as Legit Security, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2020
Funding $77M
Last updated 2026-08-27

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Legit Security sells large enterprises software that follows code from a developer's keyboard to production. It pulls together the findings of the security scanners a team already runs and prioritizes which fixes matter most. Gartner Peer Insights carries 31 published customer ratings of Legit, against 433 for Veracode and 401 for Checkmarx's code scanner, the two vendors it lists as Legit's top alternatives. Legit's newer VibeGuard software runs on the developer's own machine and checks code as an AI assistant writes it. Named customers include Kraft-Heinz, Netskope, ACV Auctions and the Chicago Board of Options Exchange. Most defensible for an enterprise consolidating its security tools, weakest for a buyer who screens on published peer reviews.

Sourced Details

Description Legit Security is an application security posture management platform that unifies AppSec testing, secrets prevention, software supply chain security, and vulnerability remediation, with an AI line that inventories AI models, MCP servers, and coding assistants and guards AI-generated code. [f1]
Founded 2020 [f2]
HQ Boston, Massachusetts, USA [f3]
Funding $77M total [f2]
Latest funding Series B ($40M, September 2023, led by CRV) [f2]

Products

Product What it does
Legit ASPM Platform Application security posture management unifying code security (SAST, SCA), secrets detection, software supply chain security, and unified vulnerability remediation across the SDLC.
Legit AI Security (VibeGuard and AI Security Command Center) Inventories AI models, MCP servers, and coding assistants across development with reputation scoring, and VibeGuard analyzes AI-generated code in the IDE to detect, fix, and prevent vulnerabilities.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Legit's AI Security Command Center keeps a real-time inventory of AI models and flags unapproved ones, inventories MCP servers and AI coding assistants, and VibeGuard analyzes AI-generated code in the IDE before commit. These capabilities are mapped to the AI Defense Matrix. [f4]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

The Legit ASPM platform inventories the software development lifecycle and applies code security (SAST, SCA), secrets detection, and software supply chain security to conventional applications and pipelines. This application-security posture management is mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Legit names the enterprise security team as the buyer and frames AI coding assistants as the change that outruns review, and independent coverage by The Hacker News and CSO Online of Legit's GitLab Duo research shows the exposure class is real. No cited source quantifies the pain at the scale Legit claims, which holds the evidence at present but unproven. [s1, s2, s14, s15]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Vendor pages carry feature-level detail on the scanner orchestration, the native SAST and SCA scanning, secrets detection and the VibeGuard endpoint software. IDC evaluated Legit inside an 18-vendor study whose findings are not public, Gartner Peer Insights carries customer satisfaction ratings rather than a technical evaluation, and the reviewed sources show no third-party benchmark. [s2, s3, s12, s13]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Two kinds of buyer-side signal are documented within the past year. IDC published an application security posture management MarketScape in September 2025, an analyst category assessment of 18 vendors built on vendor briefings and customer reference interviews. Gartner Peer Insights carries 31 published buyer ratings of Legit averaging 4.7, including one dated August 2026. The enabler is the spread of AI coding assistants, which Legit answered with VibeGuard, released in the fourth quarter of 2025. [s12, s13, s20]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 TechCrunch places the three founders together in the Israel Defense Forces cyber warfare division and afterwards at Microsoft and Checkmarx, and Legit's own page records Lior Barak on the founding team of Checkmarx's CxSCA product. That is senior in-domain experience with one named prior build, and no second named build appears in the reviewed sources. [s10, s6]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Legit's customers page carries attributed testimonials from security leaders at Netskope, Chicago Board of Options Exchange, ACV Auctions and Kraft-Heinz, and TechCrunch named Google, the New York Stock Exchange, Kraft Heinz and Takeda Pharmaceuticals as customers in 2023. Gartner Peer Insights adds 31 published buyer ratings, well short of the 433 and 401 that Veracode and Checkmarx's scanner carry in the same directory, so the named references do the work in this score. [s5, s10, s13]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Legit raised 77 million dollars through its 2023 Series B and the reviewed sources record no round since, while shipping native SAST and SCA in 2025, VibeGuard in the fourth quarter of 2025, autonomous remediation agents in June 2026 and a rebuilt VibeGuard in August 2026. That shipping record shows continued product output since the 2023 raise, and no revenue, margin or growth-efficiency figure appears in the reviewed sources, so efficiency itself stays unconfirmed. [s10, s17, s20]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 IDC evaluated Legit Security Ltd. inside its application security posture management study, Gartner Peer Insights lists Legit under the application security posture management and application security testing markets, and TechCrunch placed Legit in the category Gartner coined in 2023. Its Leader placement in that study appears only in Legit's own announcement among the reviewed sources, which holds the score below the independently confirmed level. [s12, s13, s10, s16]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Replacing Legit means re-wiring an orchestration layer across repositories, build systems and developer machines and reabsorbing the enforced guardrails and policies, which is real friction in the buyer's environment. IDC's September 2025 study covered CrowdStrike, Palo Alto Networks and Wiz alongside Legit, so a buyer can reach this category through a platform it already owns, which caps the score rather than lifting it. [s9, s2, s3, s12]
Business Risks A vendor that already supplies an AI coding assistant, such as GitHub with Copilot, could add the in-editor checks and model inventory Legit now leads with…
  • A vendor that already supplies an AI coding assistant, such as GitHub with Copilot, could add the in-editor checks and model inventory Legit now leads with.
  • IDC covered CrowdStrike, Palo Alto Networks and Wiz in the same application security posture management study as Legit, so a buyer consolidating on a security platform it already owns could displace it.
  • Legit's most recent disclosed round is its 2023 Series B, while TechCrunch reported that Apiiro had raised 100 million dollars by then, so a better-funded rival could outspend it for the same enterprise budget.
  • Legit carries 31 buyer ratings on Gartner Peer Insights against 433 for Veracode, so a buyer screening on published peer volume could pass it over.
  • Legit's differentiators are reproducible by a funded rival, so growth depends on execution and reference depth rather than on a data or compliance barrier.
Problem & Market Legit sells to the enterprise security team that has to govern code, secrets and software supply chain risk across many development teams…

Legit sells to the enterprise security team that has to govern code, secrets and software supply chain risk across many development teams. Its own pages frame AI coding assistants as the change that widens the gap between how fast developers ship and how fast security can review.

Independent outlets have documented the exposure this problem class produces. The Hacker News and CSO Online both covered research by Legit showing that hidden instructions in comments, commit messages and merge request descriptions could make GitLab's Duo assistant leak private source code.

IDC places the buying decision in a category it calls increasingly crowded. Its September 2025 assessment of the application security posture management market evaluated 18 vendors. IDC built that assessment from vendor briefings, surveys and customer reference interviews, and it named the diversity of capabilities and origins as a source of complexity for buyers. [s1, s2, s14, s15, s12]

Product Capabilities Legit's platform orchestrates the scanners a customer already runs, then correlates and de-duplicates their findings to show where one action reduces the most risk…

Legit's platform orchestrates the scanners a customer already runs, then correlates and de-duplicates their findings to show where one action reduces the most risk. The same platform covers code security with SAST and SCA, secrets detection, software supply chain security and unified vulnerability remediation, and customers can use Legit's native scanners instead of their own.

The AI work splits into two named offerings. The AI Security Command Center inventories AI models, MCP servers and coding assistants across development and attaches reputation data to each model. VibeGuard runs security scans inside the editor and restricts which files an assistant may read.

Legit rebuilt VibeGuard as endpoint software in August 2026. A Help Net Security industry-news item states that the release discovers and integrates with coding agents such as Claude Code, Cursor and GitHub Copilot, and that it adds anti-tampering to stop an agent or a user from disabling it. [s2, s4, s3, s20]

Competitive Positioning TechCrunch reported in 2023 that chief executive Roni Fuchs named Apiiro, Cycode and ArmorCode as Legit's closest competition…

TechCrunch reported in 2023 that chief executive Roni Fuchs named Apiiro, Cycode and ArmorCode as Legit's closest competition. Legit's own site lists OX Security, ArmorCode, Apiiro and Cycode under a Compare heading.

The category also holds vendors a buyer may already own. IDC's September 2025 application security posture management assessment covered CrowdStrike, Palo Alto Networks, Wiz, Snyk, Checkmarx and Veracode alongside Legit Security Ltd., in a market IDC calls increasingly crowded.

The cited record carries no capability-by-capability comparison of these vendors. A buyer weighing Legit against a security platform already in its estate has to run that comparison itself, because the published record names the field without grading it. [s10, s5, s12]

Go-to-Market & Traction Legit publishes named enterprise references as its traction evidence…

Legit publishes named enterprise references as its traction evidence. Its customers page carries attributed testimonials from a deputy chief information security officer at Netskope, a global chief information security officer at Chicago Board of Options Exchange and a vice president of security at ACV Auctions, plus a customer testimonial from Ricardo Lafosse, chief information security officer at Kraft-Heinz.

Outside its own pages, Legit's published buying record is thin. Gartner Peer Insights carries 31 ratings of Legit averaging 4.7 out of 5, against 433 for Veracode and 401 for Checkmarx's static analysis product in the same directory, so a buyer screening on peer volume has little to read.

The motion is enterprise sales through a demo and a quote. Legit offers a self-guided tour of the platform and a free trial of VibeGuard, and TechCrunch reported in 2023 that Legit's chief executive disclosed a 2.25 million dollar customer deal that year, with second-quarter deals averaging about 341,000 dollars. [s5, s13, s3, s2, s10]

Team & Credibility Legit was founded in 2020 by Roni Fuchs, Liav Caspi and Lior Barak…

Legit was founded in 2020 by Roni Fuchs, Liav Caspi and Lior Barak. TechCrunch reported that the three served together in the cyber warfare division of the Israel Defense Forces and afterwards worked in cybersecurity at companies including Microsoft and Checkmarx.

The founding backgrounds concentrate in application security. Roni Fuchs led product and business units at Checkmarx and Microsoft, Liav Caspi held product and engineering leadership roles at Checkmarx and Argus Cyber Security, and Lior Barak was on the founding team of Checkmarx's CxSCA product.

Legit added senior operators in 2026. It announced Tamar Nulman as vice president of human resources and Omri Arnon as head of engineering, and Omri Arnon spent more than five years building engineering teams at SentinelOne. CRV led the 2023 Series B with Cyberstarts, Bessemer Venture Partners and TCV participating. [s10, s6, s17]

Trust Readiness Legit publishes a trust center hosted on Scytale that lists SOC 2 Type II and ISO/IEC 27001:2022…

Legit publishes a trust center hosted on Scytale that lists SOC 2 Type II and ISO/IEC 27001:2022. The page lists a SOC 2 report, a penetration-test report and the ISO certificate, and it documents groups of controls covering product security and access management.

The assurance package matches what an enterprise expects from a vendor whose product reads source code and governs what an AI assistant may read from a developer's machine. It supplies the artifacts an enterprise security review commonly asks for.

The reviewed sources identify no federal authorization and no sector-specific mandate for this product class. A funded rival can obtain the same two certifications through ordinary enterprise preparation, so the compliance posture shapes how fast Legit clears procurement rather than whether a buyer can replace it. [s7, s3, s2]

Competitors Apiiro, Cycode, ArmorCode, OX Security, Snyk…
Company Relationship Note Compare
Apiiro competes with TechCrunch reported that Legit's chief executive named Apiiro among its closest competition, and Legit's own site lists it under a Compare heading. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Cycode competes with TechCrunch reported that Legit's chief executive named Cycode among its closest competition, and Legit's own site lists it under a Compare heading. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
ArmorCode competes with TechCrunch reported that Legit's chief executive named ArmorCode among its closest competition, and IDC's application security posture management study covered both companies.
OX Security competes with Legit's own site lists OX Security under a Compare heading, and IDC's application security posture management study covered both companies.
Snyk competes with IDC's application security posture management study covered Snyk alongside Legit, and Legit's integrations catalogue also ingests Snyk scanner results. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Legit Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Legit Security's advantages are reproducible. Its platform pulls together the output of scanners a customer already owns, and the reviewed sources name no dataset or patent that Legit alone holds. What Legit does hold is position. VibeGuard runs on the developer's own machine and checks code as an AI assistant writes it, which puts Legit in front of the build systems its platform also covers. That position is a head start rather than a durable lead, because a company that already supplies an AI coding assistant could build the same checks. Legit is strongest where a customer has already wired it into repositories, build systems and developer machines.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Legit delivers software the customer configures and runs against its own repositories, build systems and developer machines, and the customer's teams own the outcome. Its automated prioritization and remediation agents produce software output rather than a service that accepts accountability.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Wiring Legit into repositories, build systems and developer machines accumulates integration work and tuned policy that a team has to reabsorb to leave, which is real friction in re-integration effort rather than broken production. The switching mechanism is documented and the cited record does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Legit's trust center lists SOC 2 Type II and ISO/IEC 27001:2022, with a SOC 2 report, a penetration-test report and the ISO certificate. A funded competitor can obtain both certifications through ordinary enterprise preparation, and the reviewed sources identify no federal authorization and no sector-specific mandate for this product class.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Correlating and de-duplicating findings across many scanners into one prioritized view, and checking AI-generated code on the developer's machine before it reaches source control, is hard engineering. Legit's own researchers demonstrated hidden-prompt exfiltration against GitLab Duo using Base16 encoding, Unicode smuggling and white-text formula rendering, which The Hacker News and CSO Online both covered.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Legit's named references are enterprises with formal security functions, including Netskope, Chicago Board of Options Exchange and ACV Auctions on the customers page and Kraft-Heinz in a named customer testimonial. TechCrunch separately reported Google, the New York Stock Exchange, Kraft Heinz and Takeda Pharmaceuticals as customers, and the Series B announcement claims additional Fortune 500 customers without naming them.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Legit sits in the development and build path and now on the developer's own machine, which is an important position in the customer's engineering estate. Removing it costs the buyer coverage and accumulated context rather than breaking software already running in production.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The reviewed sources name no dataset, content licence or granted patent that Legit retains, and no cross-customer corpus appears in them. The learning they describe runs from each customer's own codebase, and the AI model reputation data the product shows is not described as a corpus Legit accumulates and keeps.
Strategic Market Segmentation Legit sells to enterprise security teams…

Legit sells to enterprise security teams. Its named references cluster at the large-enterprise end, with testimonials from a deputy chief information security officer at Netskope, a global chief information security officer at Chicago Board of Options Exchange and a vice president of security at ACV Auctions.

The customers page states that Fortune 500 and cybersecurity companies trust Legit, and its case studies and testimonials name Kraft-Heinz, Noname Security and Firebolt Analytics. TechCrunch reported in 2023 that Legit's customers included Google, the New York Stock Exchange, Kraft Heinz and Takeda Pharmaceuticals.

The AI line reaches the same buyer from a newer angle. The AI Security Command Center inventories AI models, MCP servers and coding assistants across development, which turns those tools into assets the security team has to govern rather than opening a separate market.

Product Capabilities & AI Advantages Legit's platform orchestrates the scanners a customer already runs, then correlates and de-duplicates their findings to show where one action reduces the most risk…

Legit's platform orchestrates the scanners a customer already runs, then correlates and de-duplicates their findings to show where one action reduces the most risk. Customers can use Legit's native SAST and SCA scanning instead of their own, and the platform also covers secrets detection, software supply chain security and unified vulnerability remediation.

The AI work splits into two named offerings. The AI Security Command Center inventories AI models, MCP servers and coding assistants and attaches reputation data to each model. VibeGuard runs SAST and SCA inside the editor, restricts which files an assistant may read, and integrates with Cursor, Windsurf and GitHub Copilot.

External assessment of these capabilities is limited but real. IDC's September 2025 application security posture management study evaluated 18 vendors including Legit Security Ltd., using vendor briefings, surveys and customer reference interviews, and its findings sit behind a paywall, so the study's coverage of Legit is on the public record while its verdict is not. Gartner Peer Insights publishes 31 customer ratings of Legit averaging 4.7 out of 5. The written comments there praise the automated remediation, and fault inconsistent workflows and integrations with a few tools that a reviewer could not complete.

Sales Engagement & Go-to-Market Legit's motion is enterprise sales through a demo and a quote…

Legit's motion is enterprise sales through a demo and a quote. Its site offers a self-guided tour of the platform and a free trial of VibeGuard.

Named references anchor the pitch. TechCrunch reported in 2023 that Legit's customers included Google, the New York Stock Exchange, Kraft Heinz and Takeda Pharmaceuticals, and the customers page carries an attributed testimonial from Ricardo Lafosse, chief information security officer at Kraft-Heinz.

Analyst recognition carries the rest. Legit announced in September 2025 that IDC named it a Leader in an application security posture management MarketScape, and its newsroom records a Sample Vendor citation in Gartner's 2026 Hype Cycle for Secure Software Engineering under both agentic coding security and application security posture management. Both placements come from Legit's own announcements, and no analyst page among the reviewed sources carries either one, so a buyer who wants IDC's own words has to buy that report, which the IDC page prices at 20,000 dollars.

Pricing Model Legit publishes no list prices, packaging or pricing metric on the pages reviewed here, which is ordinary for an enterprise platform sold through evaluation…

Legit publishes no list prices, packaging or pricing metric on the pages reviewed here, which is ordinary for an enterprise platform sold through evaluation. The site lists Plans and Packages and Contact Sales under a Pricing heading.

Two public signals bound the price level even without a price list. Gartner Peer Insights records that Legit uses a subscription model, tiered by features, scale and support, with custom pricing available for enterprises with specific requirements. TechCrunch reported in 2023 that Legit's chief executive disclosed a 2.25 million dollar customer deal that year, with second-quarter deals averaging about 341,000 dollars.

Those figures are three years old and describe individual deals rather than a price list. A buyer sizing a contract today has to reach a number through a demo and a quote, and the reviewed record gives no basis for updating the 2023 averages.

Product Delivery & Operations Legit delivers software the customer configures against its own repositories, build systems and developer tools…

Legit delivers software the customer configures against its own repositories, build systems and developer tools. The AI Defense Matrix Catalog records a SaaS deployment for the product.

VibeGuard is a second delivery surface. It runs on the developer's endpoint rather than as an editor extension, and a Help Net Security industry-news item states that the August 2026 release discovers and integrates with coding agents such as Claude Code, Cursor and GitHub Copilot and adds anti-tampering that stops an agent or a user from disabling it.

The customer's security and engineering teams carry the operating burden, setting the policies and acting on the findings. Legit's automated remediation suggests fixes and opens tickets, and the customer's teams still own the outcome.

Earning Customers' Trust Legit publishes a trust center hosted on Scytale that lists SOC 2 Type II and ISO/IEC 27001:2022…

Legit publishes a trust center hosted on Scytale that lists SOC 2 Type II and ISO/IEC 27001:2022. The page lists a SOC 2 report, a penetration-test report and the ISO certificate, and it documents groups of controls covering product security and access management.

The assurance package matches what an enterprise expects from a vendor whose product reads source code and governs what an AI assistant may read from a developer's machine. It supplies the artifacts an enterprise security review commonly asks for.

The reviewed sources identify no federal authorization and no sector-specific mandate for this product class. A funded rival can obtain the same two certifications through ordinary enterprise preparation, so the compliance posture shapes how fast Legit clears procurement rather than whether a buyer can replace it.

Platform Strategy & Ecosystem Positioning Legit positions the platform as one control plane over the tools a customer already owns…

Legit positions the platform as one control plane over the tools a customer already owns. Its integrations page describes out-of-the-box connections across security scanning, cloud posture, build systems, workflow automation, notifications and ticketing, and the catalogue lists 120 entries.

That catalogue includes direct rivals. It names Snyk, Checkmarx and Veracode among the scanners Legit ingests, alongside Wiz and CrowdStrike on the cloud side.

Large security vendors sit inside the same evaluated category. IDC's September 2025 application security posture management study covered CrowdStrike, Palo Alto Networks, Wiz, Snyk, Checkmarx, Veracode and OpenText alongside Legit Security Ltd. A buyer can therefore reach this category through a platform already in its estate, which is the standing commercial pressure on an orchestration layer.

Team & Execution Capability Legit was founded in 2020 by Roni Fuchs, Liav Caspi and Lior Barak…

Legit was founded in 2020 by Roni Fuchs, Liav Caspi and Lior Barak. TechCrunch reported that the three served together in the cyber warfare division of the Israel Defense Forces and afterwards worked in cybersecurity at companies including Microsoft and Checkmarx.

The founding backgrounds concentrate in application security. Roni Fuchs led product and business units at Checkmarx and Microsoft, Liav Caspi held product and engineering leadership roles at Checkmarx and Argus Cyber Security, and Lior Barak was on the founding team of Checkmarx's CxSCA product.

Legit added senior operators in 2026. It announced Tamar Nulman as vice president of human resources and Omri Arnon as head of engineering, and Omri Arnon spent more than five years building engineering teams at SentinelOne. CRV led the 2023 Series B with Cyberstarts, Bessemer Venture Partners and TCV participating.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Legit Security homepage: platform scope and the AI line official 2026-08-27
f2 TechCrunch: Legit Security lands $40M to lock down apps and dev environments press 2026-08-27
f3 Legit Security: contact page listing the Boston office official 2026-08-27
f4 AI Defense Matrix Catalog mapping (Legit Security) other 2026-08-27
Profile Analysis Sources (20)
Id Source Tier Accessed
s1 Legit Security homepage: platform overview and VibeGuard
“Legit VibeGuard is Application Security for AI-led development. VibeGuard prevents vulnerabilities, secrets and risk at the developer endpoint”
official 2026-08-27
s2 Legit Security: the enterprise ASPM platform page
“application security posture management (ASPM) platform unifies AppSec discovery, prioritization and remediation”
official 2026-08-27
s3 Legit Security: VibeGuard product page
“VibeGuard from Legit secures AI code, agents and workflows at generation.”
official 2026-08-27
s4 Legit Security: AI Security Command Center product page
“With Legit’s AI Security Command Center, you get comprehensive visibility into developer AI tools for security.”
official 2026-08-27
s5 Legit Security: customer stories and testimonials
“Legit is providing us with visibility across the entire software supply chain, which helps us minimize risk and raise analyst and engineering productivity.”
official 2026-08-27
s6 Legit Security: about page with management team and investors
“Roni is the CEO of Legit Security. In previous roles, Roni led Product and Business Units at Checkmarx and Microsoft, both after startup acquisition. Roni’s early career was in the Israeli Defense Force’s Unit 8200.”
official 2026-08-27
s7 Legit Security Trust Center on Scytale: certifications and controls
“Welcome to our Trust Center — a centralized hub for showcasing our commitment to security, privacy, and compliance.”
official 2026-08-27
s8 Legit Security: contact page listing Boston and Tel Aviv offices
“100 Summer Street, Suite 1600, Boston, MA 02110”
official 2026-08-27
s9 Legit Security: integrations catalogue
“Legit delivers out-of-the-box integrations with the tools you know and love – from application security scanning and CSPM to CI/CD tooling, workflow automations, notifications and ticketing.”
official 2026-08-27
s10 TechCrunch: Legit Security lands $40M to lock down apps and dev environments
“Legit Security , a cybersecurity company developing a platform to identify app vulnerabilities from code, has raised $40 million in a Series B funding round led by CRV with participation from Cyberstarts, Bessemer Venture Partners and TCV.”
press 2026-08-27
s11 PR Newswire: Legit Security Secures $40 Million Series B Investment Led by CRV
“Legit Security's rapid customer growth includes a roster of prominent enterprise brands such as Google, NYSE, Kraft Heinz and Takeda Pharmaceuticals.”
press 2026-08-27
s12 IDC: IDC MarketScape Worldwide Application Security Posture Management 2025 Vendor Assessment
“This IDC study evaluates 18 vendors in the worldwide application security posture management (ASPM) market.”
research 2026-08-27
s13 Gartner Peer Insights: Legit Security reviews and ratings page
“Legit Security software uses a subscription-based pricing model. The pricing is tiered and may vary based on features, scale, and support levels included within each plan. Custom pricing can be offered for enterprises with specific requirements.”
research 2026-08-27
s14 The Hacker News: GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts
“Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject untrusted HTML into its responses”
press 2026-08-27
s15 CSO Online: Prompt injection flaws in GitLab Duo highlights risks in AI assistants
“GitLab’s coding assistant Duo can parse malicious AI prompts hidden in comments, source code, merge request descriptions and commit messages from public repositories, researchers found.”
press 2026-08-27
s16 Legit Security: announcement of its Leader placement in the IDC MarketScape for ASPM
“This first IDC MarketScape for ASPM evaluated 18 vendors.”
official 2026-08-27
s17 Legit Security: news and press-release index
“Legit Security Named as a Sample Vendor in the Gartner® Hype Cycle™ for Secure Software Engineering 2026”
official 2026-08-27
s18 AI Defense Matrix Catalog: Legit Security product entry
“AI discovery capability that inventories AI models, MCP servers, and coding assistants across development, plus VibeGuard guardrails for AI-generated code in the IDE.”
other 2026-08-27
s19 The Hacker News: Apache Cordova App Harness Targeted in Dependency Confusion Attack
“Researchers have identified a dependency confusion vulnerability impacting an archived Apache project called Cordova App Harness”
press 2026-08-27
s20 Help Net Security: Legit Security VibeGuard 2.0 brings endpoint security and real-time guardrails to AI coding agents
“Legit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents”
press 2026-08-27
Deep-Dive Sources (20)
Id Source Tier Accessed
s1 Legit Security homepage: platform overview and VibeGuard
“Legit VibeGuard is Application Security for AI-led development. VibeGuard prevents vulnerabilities, secrets and risk at the developer endpoint”
official 2026-08-27
s2 Legit Security: the enterprise ASPM platform page
“application security posture management (ASPM) platform unifies AppSec discovery, prioritization and remediation”
official 2026-08-27
s3 Legit Security: VibeGuard product page
“VibeGuard from Legit secures AI code, agents and workflows at generation.”
official 2026-08-27
s4 Legit Security: AI Security Command Center product page
“With Legit’s AI Security Command Center, you get comprehensive visibility into developer AI tools for security.”
official 2026-08-27
s5 Legit Security: customer stories and testimonials
“Legit is providing us with visibility across the entire software supply chain, which helps us minimize risk and raise analyst and engineering productivity.”
official 2026-08-27
s6 Legit Security: about page with management team and investors
“Roni is the CEO of Legit Security. In previous roles, Roni led Product and Business Units at Checkmarx and Microsoft, both after startup acquisition. Roni’s early career was in the Israeli Defense Force’s Unit 8200.”
official 2026-08-27
s7 Legit Security Trust Center on Scytale: certifications and controls
“Welcome to our Trust Center — a centralized hub for showcasing our commitment to security, privacy, and compliance.”
official 2026-08-27
s8 Legit Security: contact page listing Boston and Tel Aviv offices
“100 Summer Street, Suite 1600, Boston, MA 02110”
official 2026-08-27
s9 Legit Security: integrations catalogue
“Legit delivers out-of-the-box integrations with the tools you know and love – from application security scanning and CSPM to CI/CD tooling, workflow automations, notifications and ticketing.”
official 2026-08-27
s10 TechCrunch: Legit Security lands $40M to lock down apps and dev environments
“Legit Security , a cybersecurity company developing a platform to identify app vulnerabilities from code, has raised $40 million in a Series B funding round led by CRV with participation from Cyberstarts, Bessemer Venture Partners and TCV.”
press 2026-08-27
s11 PR Newswire: Legit Security Secures $40 Million Series B Investment Led by CRV
“Legit Security's rapid customer growth includes a roster of prominent enterprise brands such as Google, NYSE, Kraft Heinz and Takeda Pharmaceuticals.”
press 2026-08-27
s12 IDC: IDC MarketScape Worldwide Application Security Posture Management 2025 Vendor Assessment
“This IDC study evaluates 18 vendors in the worldwide application security posture management (ASPM) market.”
research 2026-08-27
s13 Gartner Peer Insights: Legit Security reviews and ratings page
“Legit Security software uses a subscription-based pricing model. The pricing is tiered and may vary based on features, scale, and support levels included within each plan. Custom pricing can be offered for enterprises with specific requirements.”
research 2026-08-27
s14 The Hacker News: GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts
“Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject untrusted HTML into its responses”
press 2026-08-27
s15 CSO Online: Prompt injection flaws in GitLab Duo highlights risks in AI assistants
“GitLab’s coding assistant Duo can parse malicious AI prompts hidden in comments, source code, merge request descriptions and commit messages from public repositories, researchers found.”
press 2026-08-27
s16 Legit Security: announcement of its Leader placement in the IDC MarketScape for ASPM
“This first IDC MarketScape for ASPM evaluated 18 vendors.”
official 2026-08-27
s17 Legit Security: news and press-release index
“Legit Security Named as a Sample Vendor in the Gartner® Hype Cycle™ for Secure Software Engineering 2026”
official 2026-08-27
s18 AI Defense Matrix Catalog: Legit Security product entry
“AI discovery capability that inventories AI models, MCP servers, and coding assistants across development, plus VibeGuard guardrails for AI-generated code in the IDE.”
other 2026-08-27
s19 The Hacker News: Apache Cordova App Harness Targeted in Dependency Confusion Attack
“Researchers have identified a dependency confusion vulnerability impacting an archived Apache project called Cordova App Harness”
press 2026-08-27
s20 Help Net Security: Legit Security VibeGuard 2.0 brings endpoint security and real-time guardrails to AI coding agents
“Legit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents”
press 2026-08-27

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.