All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Mend.io sells application security to enterprise development and security teams: scanning for open source and custom code, plus a newer line securing the AI models, prompts, and agents inside their applications. The AI line now reaches production. Mend.io announced in July 2026 that Mend AI adds real-time guardrails inspecting prompts and responses, deployable inside the application or as a standalone proxy. The rate card prices that line at up to 300 dollars per developer a year, bought as an add-on to the code platform or on its own. The scale a buyer will hear, more than 1,000 customers and about a quarter of the Fortune 100, is Mend's own 2022 statement, which no newer cited source updates. Mend now sells at both layers and publishes what each one costs.
| Description | Mend.io sells application security software for enterprise development teams. It scans open source dependencies and custom code, automates dependency updates, and through its Mend AI line inventories the AI models, prompts, and agents inside an application and guards them at runtime. | [f1] |
|---|---|---|
| Founded | 2011 | [f2] |
| HQ | Israel | [f3] |
| Funding | $120M total | [f2] |
| Latest funding | Series D, $75M (April 2021) | [f4] |
| Deployment | SaaS | [f5] |
| Product | What it does |
|---|---|
| Mend AI | Mend AI: Inventories the AI models, frameworks, and agents inside an application, hardens system prompts, runs red teaming against conversational AI, and inspects model inputs and outputs at runtime. |
| Mend SCA | Mend SCA: Finds open source dependency risk, uses reachability analysis to show whether code interacts with vulnerable functions, and exports SBOMs in SPDX and CycloneDX formats. |
| Mend SAST | Mend SAST: Scans proprietary code across more than 30 programming languages, detects hardcoded credentials and API keys, and can run on-premises so source code stays inside the customer's environment. |
| Mend Renovate | Mend Renovate: Detects outdated packages and delivers dependency updates as pull requests, built on the open source Renovate CLI that Mend.io maintains. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Mend AI discovers and inventories AI components in applications, assesses their risks, enforces AI policies, and red teams AI behavior for issues like prompt injection. It is mapped to the AI Defense Matrix. [f6]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Mend SCA and Mend SAST scan open source dependencies and custom code for vulnerabilities and exposed secrets. This conventional application security is mapped to the Cyber Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Mend.io names the buyer, the security and development teams shipping software, and ties the pain to shadow AI, open source dependency risk, and compliance pressure it attributes to the EU AI Act and the Cyber Resilience Act. The independent surveys in the cited record measure what buyers are funding rather than how often the harm occurs, and Mend's own improvement figures are vendor-reported, so the pain is credible but not independently quantified at the scale claimed. [s1, s2, s17] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Mend documents concrete mechanics across three lines: reachability over direct and transitive dependencies ranked by CVSS 4.0 and EPSS, custom-code scanning across 30-plus languages with secrets detection, and AI red teaming with runtime inspection of prompts and responses. Renovate, the dependency updater Mend maintains, is published under the AGPL-3.0 licence with more than 22,000 stars and about 3,300 forks on GitHub, so code implementing a scored capability is open to inspection and independently adopted. [s3, s4, s20, s23] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Two kinds of buyer-side signal are documented within the past year. Regulatory: the European Commission states that the AI Act's enforcement powers apply from 2 August 2026. Budget: Enterprise Technology Research's March 2026 survey of 517 security leaders found protection for large language models had overtaken cloud security as the top security budget priority, and a Thales survey relayed by Help Net Security put dedicated AI-security budgets at 30 percent of respondents, up from 20 percent. [s16, s17, s18] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Globes reported that CA was acquiring Eurekify, an Israeli identity and role management developer that Mend.io co-founder Ron Rymon founded in 2002 and that co-founder Azi Cohen ran as chief executive, and KuppingerCole's profile of Rymon records the two managing Eurekify up to that acquisition. A prior build and exit in security software, plus the WhiteSource-to-Mend.io build from 2011, clears the bar on multiple independent sources. [s27, s28, s14, s9] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Enterprise references speak on record: a security architect for WTW's ICT business crediting at least an 80 percent cut in remediation time, a senior security architect quoted naming Vonage, and a principal software engineer at Span Software and AI Solutions quoted in Mend.io's own July 2026 announcement of the AI line. CRN reported a channel motion with GuidePoint Security and Defy Security. The headline scale, more than 1,000 customers and about a quarter of the Fortune 100, is the company's own 2022 statement, so it does not independently confirm reach. [s13, s2, s23, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | CRN reported about 120 million dollars raised since 2011, including a 75 million dollar Series D in April 2021 that Calcalist attributes to Pitango Growth with M12, Susquehanna Growth Equity, and 83North participating. The growth figures in the record, 800 percent revenue growth over three years and 127 percent enterprise net retention, are the company's own 2022 statements with no absolute revenue or margin figure behind them, so efficiency itself stays unconfirmed. [s9, s15, s10] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Software composition analysis and static application security testing are established budget lines. SecurityWeek describes Mend adding static analysis to complement its existing software composition analysis functionality, CRN places the company in the application security market, and TechCrunch records WhiteSource as one of the early companies to coin the term software composition analysis, so reporters and buyers place the business in recognized stack slots without vendor coaching. [s8, s9, s14] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Embedding into editors, repositories, registries, and build pipelines creates real friction against a platform vendor absorbing the work. Neither asset that would add to that friction is exclusive: Mend publishes its vulnerability database on its own site as an aggregation of the NVD, security advisories, and open source project issue trackers, and the install-base figure that would evidence a procurement position is the company's own 2022 statement. [s3, s19, s9] |
Mend.io sells security for the whole span of what a development team ships, from the open source packages it pulls in to the custom code it writes to the AI models and agents now embedded in its applications. The audience is the security and development teams inside an enterprise. Mend's homepage argues that AI components, open source dependencies, and production agents have introduced risk that traditional developer security tools were not built to find, test, or govern.
The pain is tied to named regulation rather than to generalities. Mend's homepage names the EU AI Act, Executive Order 14028, and the Cyber Resilience Act as requiring verifiable technical evidence that software and AI systems have been inventoried, tested, and secured. Mend AI scans code to surface shadow AI, the models and libraries developers adopted without security or governance review.
Independent evidence supports the demand rather than the size of the harm. Enterprise Technology Research's March 2026 survey of 517 security leaders found that protection for large language models and generative AI had overtaken cloud security as the top cybersecurity budget priority, and a Thales survey relayed by Help Net Security put dedicated AI-security budgets at 30 percent of respondents, up from 20 percent the year before. Those measure what buyers are funding, not how often the risk Mend describes actually bites. [s1, s2, s17, s18]
Mend.io runs three priced lines rather than a single point product. Mend SCA finds open source risk using what the company calls a unique reachability analysis, showing whether code interacts with vulnerable functions in both direct and transitive dependencies, then ranks findings with CVSS 4.0 severity and EPSS exploitability data and exports SBOMs in SPDX and CycloneDX with VEX data. Mend SAST scans proprietary code across 30-plus languages including Java, Python, Go, and C/C++, detects hardcoded credentials, API keys, tokens, and certificates, and, Mend says, can run on-premises so source code never leaves the customer's perimeter.
Mend AI extends the platform to the AI layer of an application. It maintains a real-time inventory of every model, framework, and AI agent in that application, including hard-to-detect shadow AI and the tools and MCP servers agents connect to, hardens system prompts, and runs prebuilt red teaming scenarios against conversational AI for prompt injection, context leakage, data exfiltration, jailbreaks, hallucinations, and bias. It measures a program against the OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act.
The runtime layer now ships. Mend says Mend AI inspects every input before it reaches the model and every output before it reaches the user, catching prompt injection, jailbreak attempts, sensitive data exposure, and harmful content in real time, and announced in July 2026 that those guardrails are deployable in the application or through a standalone proxy or interface. Detection-quality figures stay Mend's own: the 38 percent better precision and 48 percent better recall it reports for static analysis carry no third-party benchmark in the fetched pages. [s3, s4, s2, s5, s23]
Mend.io competes on two fronts at once and says so in print. It publishes head-to-head pages against established application security vendors, telling readers that Snyk is racing to become an AI security company while Mend.io already is one, and that Checkmarx focuses on remediating code faster inside the editor while Mend.io also secures the models, agents, and system prompts generating that code. On the AI side it runs the same play against Noma Security, arguing that Noma brings AI asset discovery and posture management while Mend AI adds supply chain security, prompt hardening, and red teaming in one product.
The stated differentiator is one governed system across both layers. Mend's about page puts it as the dangerous gaps living at the seams between layers, and says that is exactly where Mend.io sits. The company also argues that AI tools let developers ship faster than ever, and that doubling output without security governance grows the attack surface faster.
Independence is the other selling point. Mend's about page observes that three of five AI security vendors are now inside big platforms and states that Mend.io is not beholden to any model provider. [s24, s25, s26, s7]
Named enterprise references speak on record. Andrei Ungureanu, a security architect for WTW's ICT business, says his team's remediation time has gone down considerably, and in a testimonial on the Mend AI page he puts the reduction at at least 80 percent. Chris Wallace, a senior security architect, credits Mend with letting Vonage align speed, security, and compliance in a competitive market. Mend.io's own July 2026 announcement quotes Alen Pešikan, a principal software engineer at Span Software and AI Solutions, on Mend.io helping his team face the risks AI brings in generated code and in AI components.
The channel motion is documented but dated. CRN reported at the 2022 rebrand that Mend worked closely with systems integrators and planned to strengthen and deepen its channel ties, quoting the company on strong relationships with GuidePoint Security and Defy Security and on a move toward a full channel-led business model over two years. No newer cited source reports where that move landed.
The headline scale figures are the company's own and four years old. CRN and Help Net Security both relayed Mend's May 2022 statement of more than 1,000 customers including about a quarter of the Fortune 100, alongside revenue up 800 percent over three years and enterprise net retention of 127 percent in 2021. So a buyer weighing Mend.io today has the named references and the published prices, and no cited source that updates the customer count. [s13, s2, s23, s9, s10]
Mend.io's founders had built and sold a security company before this one. Globes reported that CA was acquiring Eurekify, an Israeli identity and role management developer that Ron Rymon founded in 2002 and that Azi Cohen ran as chief executive, and KuppingerCole's profile of Rymon records the two of them managing Eurekify up to that acquisition. TechCrunch reported that Sass, Cohen, Rymon, and Roni Einav went on to start WhiteSource in 2011, and Israel's companies registry lists that entity as active from its 09/05/2011 incorporation.
The company changed chief executive in December 2025. Mend.io announced that Azi Cohen, co-founder and president, had been appointed chief executive officer with immediate effect, and that co-founder Rami Sass would move to general manager for Mend AI. The current about page lists Cohen as co-founder and chief executive and Gil Regev as general manager of Mend AI, and does not list Sass.
Press has followed the product line as it widened. TechCrunch notes that WhiteSource was among the early companies to coin the term software composition analysis, and SecurityWeek recorded the move into static analysis. [s27, s28, s14, s12, s22, s7]
Mend.io publishes the assurance package an enterprise security review expects. Its trust page states an integrated information security management system incorporating controls for ISO 27001, ISO 27017, and ISO 27701, reviewed externally every year, and a SOC 2 Type II assessment evaluated by Schellman with the report available through the account team. It also states GDPR commitments for a company headquartered in Israel with operations across the EU, the US, and worldwide.
Those are credentials a funded competitor can obtain. No federal authorization or government mandate attached to the product appears in the reviewed sources, so nothing in that record blocks a replacement on compliance grounds and the attestations read as enterprise entry cost.
The newest layer is where a review will concentrate. Mend AI inspects prompts and responses in production, and Mend.io states that those guardrails can be deployed inside the application or as a standalone proxy or interface, so a security team will ask where model traffic goes and on what terms. The one adversarial record among the cited sources is NVD's CVE-2020-5304, a log injection in the legacy WhiteSource Application Vulnerability Management dashboard fixed in version 20.4.1. [s6, s2, s23, s11]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Snyk | competes with | Mend.io publishes a head-to-head comparison page against it covering both application security and AI security. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Checkmarx | competes with | Mend.io publishes a head-to-head comparison page against it covering application security testing and AI coverage. | |
| Noma Security | competes with | Mend.io publishes a head-to-head comparison page against it for the Mend AI line. |
Add analyzed competitors to compare them side by side with Mend.io.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Mend.io sells scanning for open source and custom code to enterprise development teams, and now sells security for an application's AI layer alongside it. The engineering is the durable part. Deciding whether an application actually calls the vulnerable code inside a dependency, covering custom code in more than 30 languages, and simulating attacks on conversational AI all take years of specialized work. Mend publishes its vulnerability database on its own site as an aggregation of public feeds and maintains Renovate under an open licence with more than 22,000 stars on GitHub. Its SOC 2 and ISO attestations are ones a funded rival can earn. A customer that leaves has to wire a replacement into its editors, repositories, and pipelines.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Mend.io delivers configurable software that the customer's own team operates and owns the outcomes of: scanners wired into the pipeline, reachability prioritization, automated remediation suggestions, and AI red teaming that returns findings. Agentic triage and AI-assisted fixes are software output rather than a human-validated service layer, and no cited source describes Mend taking responsibility for what the tools miss. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Mend.io embeds across editors, repositories, registries, and build pipelines, and a customer accumulates findings, policies, and build gates inside it, which is real friction to replace. That is integration and learned workflow rather than a documented non-portable asset, and the cited record does not size the migration: no source states what leaving would cost in time, parties, or complexity. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Mend.io's trust page states externally reviewed ISO 27001, 27017, and 27701 controls and a SOC 2 Type II assessment by Schellman, which a funded competitor can obtain through ordinary enterprise-market preparation. No federal authorization or government mandate attached to the product appears in the reviewed sources, and the SBOM and audit-evidence layer is a feature serving customers' own compliance work rather than an authorization Mend.io itself holds. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Tracing whether an application reaches a vulnerable function through direct and transitive dependencies, scanning custom code across 30-plus languages with secrets detection, and running adversarial red teaming that probes conversational AI for prompt injection, context leakage, and jailbreaks are program-analysis and adversarial-testing work. Inspecting every model input and output in production adds a real-time systems requirement on top. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The named reference is WTW's Insurance Consulting and Technology business, whose legal teams treated copyleft licences as an area of particular concern, and press relayed Mend.io's statement of a base including about a quarter of the Fortune 100. Published price ceilings let a smaller team size the platform, but every pricing tier's call to action is a demo request, so the purchase runs through enterprise sales rather than self-service. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Mend.io is a platform whose application features scan, prioritize, and gate code and AI components across the development pipeline. Its runtime guardrails do inspect live model inputs and outputs before they reach the model or the user, and Mend.io states they can run as a standalone proxy, but they wrap the customer's own application and the customer opts into them, so they are not infrastructure other applications are built on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Mend.io operates a named vulnerability database covering over 3 million open source components across more than 200 languages, but publishes it openly on its own site and describes it as an aggregation of the NVD, security advisories, and open source project issue trackers. Renovate, the other accumulated artifact, is published under an open licence. No granted patent, licensed corpus, or non-public dataset appears in the reviewed record. |
Mend.io sells to the security and development teams inside an enterprise, reaching developers where they already work. The about page frames the pain as the dangerous gaps living at the seams between layers, and argues that AI tools let developers ship faster than ever while doubling output without security governance grows the attack surface faster. The AI line reaches that same buyer through a platform it already owns, and Mend also sells it standalone.
The base is enterprise and, where it is named, carries its own governance obligations. The named reference is WTW's Insurance Consulting and Technology business, whose legal teams treated copyleft licences as an area of particular concern. The wider scale claim, more than 1,000 customers including about a quarter of the Fortune 100, is the company's own May 2022 statement relayed by CRN and Help Net Security, with no newer cited source updating it.
Published prices widen who can evaluate Mend.io without widening who can buy it. The pricing page lists ceilings of up to 1,000 dollars per developer per year for Mend AppSec, up to 300 for Mend AI, and up to 250 for Mend Renovate Enterprise, so a team can size the cost before a conversation. Each of the three tiers still closes on a demo request, so the purchase itself runs through sales.
Mend.io's technical claim rests on deciding what actually matters in a large codebase. Mend SCA employs what the company calls a unique reachability analysis, showing whether code interacts with vulnerable functions in both direct and transitive dependencies, then ranks findings with CVSS 4.0 severity and EPSS exploitability data. Mend SAST covers 30-plus languages spanning web, mobile, server-side, and infrastructure-as-code, detects hardcoded credentials, API keys, tokens, and certificates, and can fail the build before exposed secrets reach production.
The AI line applies the same shape one layer up. Mend AI keeps a real-time inventory of every model, framework, and agent in an application, including shadow AI and the tools and MCP servers agents connect to, runs prebuilt red teaming for prompt injection, context leakage, data exfiltration, jailbreaks, hallucinations, and bias, and measures the program against the OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act.
Runtime protection is the newest piece and the one with the least outside evidence. Mend says the product inspects every input before it reaches the model and every output before it reaches the user, and announced in July 2026 that the guardrails deploy in the application or through a standalone proxy or interface. The efficacy figures around the platform stay Mend's own, including the 38 percent better precision and 48 percent better recall it reports for static analysis, with no third-party benchmark in the fetched record.
The motion is enterprise sales with a channel layer on top. CRN reported at the 2022 rebrand that Mend worked closely with systems integrators, quoted the company on strong relationships with GuidePoint Security and Defy Security, and recorded a stated plan to move to a full channel-led business model over two years. Where that plan landed is not in any cited source.
Product marketing does a lot of the qualifying work. Mend.io publishes per-developer price ceilings and head-to-head pages against named rivals on both the application security and AI fronts, which lets a buyer self-assess fit and cost before contact. The conversion step is still a demo request on every pricing tier.
The named references now reach the AI line as well as the older business. A security architect for WTW's ICT business credits at least an 80 percent cut in remediation time and a senior security architect names Vonage, both on code security. Mend.io's own July 2026 announcement quotes Alen Pešikan, a principal software engineer at Span Software and AI Solutions, saying Mend.io has helped his team face the risks AI brings in generated code and in AI components, so the AI line now has a named reference in the fetched record rather than only the code-security portfolio.
Mend.io prices per contributing developer and publishes the rate. The pricing page lists Mend AppSec at up to 1,000 dollars per developer per year, Mend AI at up to 300, and Mend Renovate Enterprise at up to 250, so cost grows with engineering headcount and with the modules a team turns on. Mend AI can be bought as an add-on to Mend AppSec or as a standalone product.
Mend defines the unit tightly. A contributing developer is any employee or contractor who uses the web application or writes, develops, or modifies scanned code, and the page states that the same individual is not counted more than once even when acting in two roles. Mend answers that there are no additional fees per gigabyte, arguing that managers have better visibility into headcount growth than into the size of their software or lines of code.
Publishing the number cuts both ways for Mend.io. A team can size the platform from the rate card and the counting rule before it talks to anyone, and the same published unit is available to anyone building a competing quote. In-app runtime guardrails sit inside the Mend AI tier rather than the base platform, so the newest capability is a separate line on a buyer's quote.
Mend.io is delivered where developers already work. Mend SCA feeds vulnerability information with reachability analysis into AI code assistants for remediation directly in the workflow, and secrets detection in Mend SAST triggers automated policy violations that can fail a build before exposed credentials reach production. Both paths put the control inside the pipeline the team already runs.
One line is deliberately not cloud-only. Mend says Mend SAST performs scanning on-premises or inside the customer's own environment so proprietary source code never leaves the perimeter, while findings, dashboards, and policy management run in the Mend cloud. Mend positions that split for regulated and high-IP industries, and it means the platform is not uniformly operated by Mend.
The AI line adds operational surface a buyer has to accept. Mend says Mend AI inspects every input before it reaches the model and every output before it reaches the user, and that these runtime guardrails deploy in the application or as a standalone proxy or interface. Which of those a customer picks decides where its prompts and responses are handled, and the fetched pages state no data-handling terms for either, so a buyer should ask for them.
Mend.io publishes the assurance package an enterprise review expects. The trust page states an integrated information security management system incorporating controls for ISO 27001, ISO 27017, and ISO 27701, reviewed externally every year, and a SOC 2 Type II assessment evaluated by Schellman with the report available through the account team. GDPR commitments are stated for a company headquartered in Israel with operations across the EU, the US, and worldwide.
Compliance is also sold as a product feature. Mend positions inventory, findings, test results, and remediation status in one governed workflow that it says gives security and compliance teams the structured, auditable record regulators require, and Mend AI measures a program against the OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act. The characterization of what regulators require is Mend's own.
No federal authorization or government mandate attached to the product appears in the reviewed sources, so the attestations Mend.io holds read as ordinary enterprise entry cost rather than something that blocks a replacement. The assurance question that will take real work is the AI line, because reviewing a control that inspects live model traffic turns on data-handling terms the fetched pages do not state.
Mend.io is built to be one vendor across code and AI rather than a point tool. The platform covers open source dependencies, custom code, secrets, dependency updates, and AI components under a single per-developer billing relationship, and the company's argument for that shape is that the dangerous gaps live at the seams between layers.
Outward, the platform reaches the developer ecosystem through open source. Renovate, the dependency updater behind Mend Renovate, is published on GitHub under the AGPL-3.0 licence with more than 22,000 stars and about 3,300 forks, supports over 90 package managers, and is available self-hosted at no cost. Mend describes it as the trusted standard for automated dependency updates running on millions of repositories, which is the company's own characterization.
Inward, the same breadth concentrates a customer's application security operations on one supplier. Standardizing open source, custom-code, and AI-component security on Mend.io puts accumulated findings, policy, and audit evidence in one place, which is the consolidation Mend sells and also the concentration a buyer wary of a single supplier weighs against it.
Mend.io's founders had built and sold a security company before this one. Globes reported CA acquiring Eurekify, an Israeli identity and role management developer that Ron Rymon founded in 2002 and that Azi Cohen ran as chief executive, and KuppingerCole's profile of Rymon records the two of them managing Eurekify up to that acquisition. TechCrunch reported that Rami Sass, Cohen, Rymon, and Roni Einav went on to start WhiteSource in 2011, and Israel's companies registry lists that entity as active from its 09/05/2011 incorporation.
Leadership turned over in December 2025. Mend.io announced that Azi Cohen, co-founder and president, had been appointed chief executive officer with immediate effect and that co-founder Rami Sass would move to general manager for Mend AI. The current about page lists Cohen as co-founder and chief executive and Gil Regev as general manager of Mend AI, and does not list Sass.
The Series D investor list is on record. Calcalist reported that the 75 million dollar round was led by Pitango Growth with existing investors M12, Susquehanna Growth Equity, and 83North participating.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Mend.io: pricing page describing what each product line secures | official | 2026-08-27 |
| f2 | WhiteSource Has New Security Directions, New Name: Meet 'Mend' (CRN) | press | 2026-08-27 |
| f3 | Mend.io: trust and compliance page stating where the company is headquartered | official | 2026-08-27 |
| f4 | WhiteSource rebrands as Mend (Help Net Security) | press | 2026-08-27 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f7 | Mend.io platform | official | 2026-06-14 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Mend.io homepage: unified application security and AI security platform “Unified governance for the software you write and the AI you build.” | official | 2026-08-27 |
| s2 | Mend.io: Mend AI product page covering discovery, red teaming, prompt hardening, and runtime protection “Mend AI inspects every input before reaching your model and every output before reaching your user, catching prompt injection, jailbreak attempts, sensitive data exposure, and harmful content in real time.” | official | 2026-08-27 |
| s3 | Mend.io: Mend SCA product page on reachability analysis, prioritization, and SBOM export “Mend SCA employs a unique reachability analysis, showing whether your code interacts with vulnerable functions in both direct and transitive dependencies that pose a threat to your AI models.” | official | 2026-08-27 |
| s4 | Mend.io: Mend SAST product page on detection accuracy, language coverage, and on-premises scanning “Mend SAST starts with highly accurate detection, delivering 38% better precision and 48% better recall than benchmark competitors.” | official | 2026-08-27 |
| s5 | Mend.io: pricing page listing per-developer rate ceilings and module contents “Mend AppSec Up to $1000 per dev/ per year” | official | 2026-08-27 |
| s6 | Mend.io: trust and compliance page listing ISO controls and the SOC 2 Type II assessment “At Mend.io, we have established an integrated information security management system incorporating controls for ISO 27001, ISO 27017, and ISO 27701. These controls are reviewed externally every year.” | official | 2026-08-27 |
| s7 | Mend.io: about page carrying the current leadership roster and the independence positioning “Azi Cohen Co-Founder & CEO” | official | 2026-08-27 |
| s8 | SecurityWeek: WhiteSource Becomes Mend, Adds Automatic Code Remediation “with the addition of automated code remediation to the newly named Mend Application Security Platform.” | press | 2026-08-27 |
| s9 | CRN: WhiteSource Has New Security Directions, New Name: Meet 'Mend' “Mend, as the company is now called as of this week, has raised a total of $120 million in funding since its founding in 2011, of which $75 million was raised in April 2021.” | press | 2026-08-27 |
| s10 | Help Net Security: WhiteSource rebrands as Mend “With revenue up 800% over the past three years and enterprise net retention at 127% in 2021, the company added 350 new customers in the last year.” | press | 2026-08-27 |
| s11 | NVD: CVE-2020-5304 record for the WhiteSource Application Vulnerability Management dashboard “The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI.” | regulatory | 2026-08-27 |
| s12 | Israel Companies Registry via data.gov.il: WHITE SOURCE LTD, company number 514613587 “"שם באנגלית":"WHITE SOURCE LTD"” | regulatory | 2026-08-27 |
| s13 | Mend.io: WTW customer story on automating open source dependency review “We recognized that we needed to improve and automate our processes,” said Andrei Ungureanu, security architect for WTW’s ICT business.” | official | 2026-08-27 |
| s14 | TechCrunch: WhiteSource nabs $35M to track open source code for security vulnerabilities “WhiteSource has been around since 2011, founded by Rami Sass (CEO), Azi Cohen, Ron Rymon and Roni Einav — four alums from a previous startup, an identity management firm called Eurekify, which was acquired by CA about a decade ago.” | press | 2026-08-27 |
| s15 | Calcalist CTech: Israel's WhiteSource announces $75 million series D “announced on Wednesday that it completed a $75 million series D funding round led by Pitango Growth, with participation by existing investors M12, Susquehanna Growth Equity, and 83North.” | press | 2026-08-27 |
| s16 | European Commission: the enforcement framework of the AI Act “The enforcement powers of the AI Office and the national competent authorities of the Member States apply from 2 August 2026, when certain provisions of the AI Act become enforceable.” | regulatory | 2026-08-27 |
| s17 | Enterprise Technology Research: 2026 Annual State of Security report announcement “New survey of 517 security leaders shows rapid rise of AI security spending, increasing focus on identity, and a shift toward vendor consolidation” | research | 2026-08-27 |
| s18 | Help Net Security: AI risk moves into the security budget spotlight “Thirty percent of respondents report having a dedicated AI security budget, up from 20% in the prior year.” | press | 2026-08-27 |
| s19 | Mend.io: open source vulnerability database page, publicly browsable listing “The Mend.io open source vulnerabilities database covers over 200 programming languages and over 3 million open source components. It aggregates information from a variety of sources including the NVD, security advisories, and open source project issue trackers, multiple times a day.” | official | 2026-08-27 |
| s20 | GitHub: renovatebot/renovate repository page for the Renovate CLI “Home of the Renovate CLI: Cross-platform Dependency Automation by Mend.io” | other | 2026-08-27 |
| s21 | Mend.io: Mend Renovate product page on automated dependency updates “Mend Renovate automatically detects outdated packages and delivers updates as pull requests — so developers spend less time maintaining dependencies and more time shipping.” | official | 2026-08-27 |
| s22 | Mend.io blog: leadership update announcing the chief executive transition “Effective immediately, Azi Cohen , Mend.io co-founder and president, has been appointed Chief Executive Officer .” | official | 2026-08-27 |
| s23 | Help Net Security: Mend.io enhances application security with AI runtime protection and faster zero-day response “Mend AI runtime protection also adds real-time guardrails, deployable in-app or via a standalone proxy/API, that inspect prompts and responses for prompt injection, jailbreaks, sensitive-data exposure, exposed secrets, and unsafe content.” | press | 2026-08-27 |
| s27 | Globes: CA buys role management co Eurekify “CA Inc. (NYSE: CA) today announced that it is acquiring Israeli identity and role management solutions developer Eurekify Ltd.” | press | 2026-08-27 |
| s28 | KuppingerCole: speaker profile for Dr. Ron Rymon “Prior to CA, Ron was Founder of Eurekify, the pioneer and leading provider of role & compliance management solutions, where he filled management roles ranging from R&D, to product management, to business development.” | research | 2026-08-27 |
| s24 | Mend.io: head-to-head comparison page against Snyk “Snyk is racing to become an AI security company. Mend.io already is one, without sacrificing the AppSec foundation your team depends on.” | official | 2026-08-27 |
| s25 | Mend.io: head-to-head comparison page against Checkmarx “Mend.io secures the AI stack generating that code” | official | 2026-08-27 |
| s26 | Mend.io: head-to-head comparison page against Noma Security “Noma brings AI asset discovery and posture management to the table. Mend AI goes further—combining AI-SPM with supply chain security, system prompt hardening, adversarial red teaming, and AppSec in a single solution.” | official | 2026-08-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Mend.io homepage: unified application security and AI security platform “Unified governance for the software you write and the AI you build.” | official | 2026-08-27 |
| s2 | Mend.io: Mend AI product page covering discovery, red teaming, prompt hardening, and runtime protection “Mend AI inspects every input before reaching your model and every output before reaching your user, catching prompt injection, jailbreak attempts, sensitive data exposure, and harmful content in real time.” | official | 2026-08-27 |
| s3 | Mend.io: Mend SCA product page on reachability analysis, prioritization, and SBOM export “Mend SCA employs a unique reachability analysis, showing whether your code interacts with vulnerable functions in both direct and transitive dependencies that pose a threat to your AI models.” | official | 2026-08-27 |
| s4 | Mend.io: Mend SAST product page on detection accuracy, language coverage, and on-premises scanning “Mend SAST starts with highly accurate detection, delivering 38% better precision and 48% better recall than benchmark competitors.” | official | 2026-08-27 |
| s5 | Mend.io: pricing page listing per-developer rate ceilings and module contents “Mend AppSec Up to $1000 per dev/ per year” | official | 2026-08-27 |
| s6 | Mend.io: trust and compliance page listing ISO controls and the SOC 2 Type II assessment “At Mend.io, we have established an integrated information security management system incorporating controls for ISO 27001, ISO 27017, and ISO 27701. These controls are reviewed externally every year.” | official | 2026-08-27 |
| s7 | Mend.io: about page carrying the current leadership roster and the independence positioning “Azi Cohen Co-Founder & CEO” | official | 2026-08-27 |
| s8 | SecurityWeek: WhiteSource Becomes Mend, Adds Automatic Code Remediation “with the addition of automated code remediation to the newly named Mend Application Security Platform.” | press | 2026-08-27 |
| s9 | CRN: WhiteSource Has New Security Directions, New Name: Meet 'Mend' “Mend, as the company is now called as of this week, has raised a total of $120 million in funding since its founding in 2011, of which $75 million was raised in April 2021.” | press | 2026-08-27 |
| s10 | Help Net Security: WhiteSource rebrands as Mend “With revenue up 800% over the past three years and enterprise net retention at 127% in 2021, the company added 350 new customers in the last year.” | press | 2026-08-27 |
| s11 | NVD: CVE-2020-5304 record for the WhiteSource Application Vulnerability Management dashboard “The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI.” | regulatory | 2026-08-27 |
| s12 | Israel Companies Registry via data.gov.il: WHITE SOURCE LTD, company number 514613587 “"שם באנגלית":"WHITE SOURCE LTD"” | regulatory | 2026-08-27 |
| s13 | Mend.io: WTW customer story on automating open source dependency review “We recognized that we needed to improve and automate our processes,” said Andrei Ungureanu, security architect for WTW’s ICT business.” | official | 2026-08-27 |
| s14 | TechCrunch: WhiteSource nabs $35M to track open source code for security vulnerabilities “WhiteSource has been around since 2011, founded by Rami Sass (CEO), Azi Cohen, Ron Rymon and Roni Einav — four alums from a previous startup, an identity management firm called Eurekify, which was acquired by CA about a decade ago.” | press | 2026-08-27 |
| s15 | Calcalist CTech: Israel's WhiteSource announces $75 million series D “announced on Wednesday that it completed a $75 million series D funding round led by Pitango Growth, with participation by existing investors M12, Susquehanna Growth Equity, and 83North.” | press | 2026-08-27 |
| s16 | European Commission: the enforcement framework of the AI Act “The enforcement powers of the AI Office and the national competent authorities of the Member States apply from 2 August 2026, when certain provisions of the AI Act become enforceable.” | regulatory | 2026-08-27 |
| s17 | Enterprise Technology Research: 2026 Annual State of Security report announcement “New survey of 517 security leaders shows rapid rise of AI security spending, increasing focus on identity, and a shift toward vendor consolidation” | research | 2026-08-27 |
| s18 | Help Net Security: AI risk moves into the security budget spotlight “Thirty percent of respondents report having a dedicated AI security budget, up from 20% in the prior year.” | press | 2026-08-27 |
| s19 | Mend.io: open source vulnerability database page, publicly browsable listing “The Mend.io open source vulnerabilities database covers over 200 programming languages and over 3 million open source components. It aggregates information from a variety of sources including the NVD, security advisories, and open source project issue trackers, multiple times a day.” | official | 2026-08-27 |
| s20 | GitHub: renovatebot/renovate repository page for the Renovate CLI “Home of the Renovate CLI: Cross-platform Dependency Automation by Mend.io” | other | 2026-08-27 |
| s21 | Mend.io: Mend Renovate product page on automated dependency updates “Mend Renovate automatically detects outdated packages and delivers updates as pull requests — so developers spend less time maintaining dependencies and more time shipping.” | official | 2026-08-27 |
| s22 | Mend.io blog: leadership update announcing the chief executive transition “Effective immediately, Azi Cohen , Mend.io co-founder and president, has been appointed Chief Executive Officer .” | official | 2026-08-27 |
| s23 | Help Net Security: Mend.io enhances application security with AI runtime protection and faster zero-day response “Mend AI runtime protection also adds real-time guardrails, deployable in-app or via a standalone proxy/API, that inspect prompts and responses for prompt injection, jailbreaks, sensitive-data exposure, exposed secrets, and unsafe content.” | press | 2026-08-27 |
| s27 | Globes: CA buys role management co Eurekify “CA Inc. (NYSE: CA) today announced that it is acquiring Israeli identity and role management solutions developer Eurekify Ltd.” | press | 2026-08-27 |
| s28 | KuppingerCole: speaker profile for Dr. Ron Rymon “Prior to CA, Ron was Founder of Eurekify, the pioneer and leading provider of role & compliance management solutions, where he filled management roles ranging from R&D, to product management, to business development.” | research | 2026-08-27 |
| s24 | Mend.io: head-to-head comparison page against Snyk “Snyk is racing to become an AI security company. Mend.io already is one, without sacrificing the AppSec foundation your team depends on.” | official | 2026-08-27 |
| s25 | Mend.io: head-to-head comparison page against Checkmarx “Mend.io secures the AI stack generating that code” | official | 2026-08-27 |
| s26 | Mend.io: head-to-head comparison page against Noma Security “Noma brings AI asset discovery and posture management to the table. Mend AI goes further—combining AI-SPM with supply chain security, system prompt hardening, adversarial red teaming, and AppSec in a single solution.” | official | 2026-08-27 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.