# Cyber Company Profiles: DryRun Security

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-08-25
Canonical: https://cybercompanyprofiles.com/companies/dryrun-security
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of DryRun Security, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [dryrun.security](https://www.dryrun.security)
- Profile: https://cybercompanyprofiles.com/companies/dryrun-security
- Type: Application Security, Developer Tools
- Market readiness: Emerging (24/40)
- Defensibility: Exposed (12/21)
- Founded: 2023
- Last updated: 2026-08-25

## Executive Summary

DryRun Security sells application-security teams an AI review that runs on each pull request, models how the application works, and rates whether a code change is exploitable. It now scans whole repositories too, and it says three patents have been awarded on the part that picks out risky code. Its customers page names ten customers, among them Tines and BrightHR, and the 8.7 million dollar seed of January 2025 is the last raise in the record. Its homepage, customers page and comparison site report 500,000 code reviews a week, 350,000 a month, and 500,000 a month. It suits teams willing to test it themselves, because no independent measurement of its scale or accuracy appears in the record.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Application security company whose Contextual Security Analysis engine reads each code change for intent and data flow, judges whether it is exploitable, and enforces policies a team writes in plain language across pull requests and whole repositories. | [\[f1\]](#company-detail-sources) |
| Founded | 2023 | [\[f2\]](#company-detail-sources) |
| HQ | Austin, Texas, United States | [\[f2\]](#company-detail-sources) |
| Latest funding | Seed ($8.7M, announced January 2025, investors LiveOak Ventures, Work-Bench and Cannage Capital) | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Contextual Security Analysis | Engine behind the platform, which reads a code change for intent and inspects data flow across files and services rather than matching patterns. |
| PR Code Reviews | Reviews every pull request in real time and returns findings as comments and checks, with explanations, code references, and suggested fixes. |
| DeepScan Agent | Full repository security scan that returns prioritized, actionable findings in hours rather than in the weeks a manual assessment takes. |
| Custom Code Policies | Turns policies a team writes in natural language into checks enforced on every pull request, without scripted rules or regular expressions. |
| Codebase Intelligence | Answers natural-language questions about risk, trends, and exposure across a codebase through the Code Insights integration. |
| Secrets | Analysis that identifies hardcoded secrets in a code change and suppresses the alarms it judges false. |
| Infrastructure as Code (IaC) | Scans Terraform configurations for security misconfigurations and insecure defaults in the pull request. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Applications | ✓ | ✓ | ✓ |  |  |

DryRun Security's Contextual Security Analysis engine maps a codebase's architecture, routes, auth, and data flow, enforces code policies in the pull request, and rates whether a change is exploitable. These capabilities are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Emerging (24/40)**

Analyzed 2026-08-25. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | DryRun names the application-security buyer and states the pain concretely, and independent coverage describes the same triage burden and the code-volume growth behind it (s11, s12). No independent quantification of that pain appears in the record, since the 87 percent of pull requests carrying a vulnerability comes from DryRun's own study run with its own product (s20). \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s20](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | The vendor's pages carry specific mechanism detail, including the signals the engine gathers, the review model behind each finding, and documentation covering scanning, policy, the API, and agent integrations (s1, s8, s10). The reviewed record holds no third-party benchmark, audited evaluation, or inspectable implementation of that engine (s3): the accuracy report SecurityBrief relayed is the company's own test, reported as detecting 88 percent of seeded vulnerabilities, so the documented depth stays inside what the vendor publishes. \[[s1](#profile-analysis-sources), [s8](#profile-analysis-sources), [s10](#profile-analysis-sources), [s12](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Market Timing | 3/5 | The enabler is dated and independently described. The New Stack reported in January 2025 that use of AI coding assistants was growing rapidly and that developers were generating more code faster (s12), and IT Brief wrote in February 2026 that AI-assisted development had increased both the volume of code shipped and the pace of change (s11). Buyer-side demand reaches the record as one kind of signal, the 19 reviews DryRun cites from a customer review platform (s7, s17). \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s7](#profile-analysis-sources), [s17](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | Two surfaces outside DryRun document sustained standing in this field: a USENIX speaker page describes James Wickett as the creator and founder of the Lonestar Application Security Conference, which OWASP records as an annual Austin gathering of 400 or more practitioners (s13, s18), and Ken Johnson co-hosts the Absolute AppSec podcast, whose episode list runs to 331 (s14). Wickett also built the initial product infrastructure at Signal Sciences and Johnson led product security engineering at GitHub (s4). \[[s13](#profile-analysis-sources), [s18](#profile-analysis-sources), [s14](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | DryRun publishes ten customer names in the logo images on its customers page and role-attributed testimonials for several of them, including Tines, Invisible and BrightHR, next to a 4.9 rating from 19 reviews it cites (s7, s1). DryRun published every one of those proofs, its three usage figures disagree across its own pages (s1, s7, s17), and no revenue, customer count, or independently verified scale figure appears in the record. \[[s7](#profile-analysis-sources), [s1](#profile-analysis-sources), [s17](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The 8.7 million dollar seed of January 2025 is the most recent raise in the reviewed record (s2), and output since then is visible in a repository-wide DeepScan review launched in February 2026 (s11) alongside secrets, infrastructure-as-code and policy scanning (s1, s10). No revenue, margin, or growth-efficiency figure is disclosed, so how far that money went stays unconfirmed. \[[s2](#profile-analysis-sources), [s11](#profile-analysis-sources), [s1](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | Independent outlets place DryRun in application security and against static analysis without the vendor's help (s2, s11), and it cites a review-platform placement in the static analysis category (s17). DryRun leads with a label of its own, calling itself a code security intelligence platform and marketing Contextual Security Analysis as the engine (s1, s19), so a buyer still needs its explanation to place the product precisely. \[[s2](#profile-analysis-sources), [s11](#profile-analysis-sources), [s17](#profile-analysis-sources), [s1](#profile-analysis-sources), [s19](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | DryRun names the products it measures itself against, including GitHub Advanced Security, Snyk Code, SonarQube, Wiz Code and Claude Code Security (s1), which is where it locates its own competition. Against that set the reviewed record evidences workflow integration and stated patents (s1, s9) rather than an accumulated asset a larger vendor could not assemble. \[[s1](#profile-analysis-sources), [s9](#profile-analysis-sources), [s17](#profile-analysis-sources)\] |

### Business Risks

- A vendor on DryRun's own comparison list, such as GitHub Advanced Security or Snyk Code, could carry pull-request context review inside tools a buyer already pays for, removing the reason to add a separate product.
- The usage and reference figures on DryRun's pages are the company's own, and those pages already disagree on the review count, so a buyer's diligence could stall on evidence the company cannot corroborate.
- The 8.7 million dollar seed of January 2025 is the last announced raise, so a longer enterprise sales cycle or a price move by a better-funded rival could outrun DryRun's runway.
- DryRun markets a category label of its own, so buyers who keep evaluating it inside the static analysis budget line may price it against scanners rather than fund it separately.
- The reviewed record identifies no cross-customer data asset behind the product, so a rival that matches the engineering could reach the same quality without needing DryRun's install base.
- The reviewed record carries no inspectable attestation report, so a buyer whose review board requires one before granting full codebase access could stall the deal.

### Problem & Market

DryRun Security sells to the application-security team that has to review code faster than developers and their AI assistants ship it. The company describes a platform that verifies code security, validates exploitable risk, guides remediation, and enforces policies across human and AI-generated code.

Independent coverage describes the same pain without the vendor's framing. IT Brief writes that teams running traditional static analysis often triage large numbers of findings, that the work takes time, and that false positives erode confidence in results. The same article reports that AI-assisted development has increased both the volume of code shipped and the pace of change.

What the record lacks is an independent measure of that pain at DryRun's buyers. The company's own study of agent-written code reports that 87 percent of pull requests introduced at least one security vulnerability, a study DryRun designed and ran with its own product. \[[s1](#profile-analysis-sources), [s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s20](#profile-analysis-sources)\]

### Product Capabilities

The engine is the product. DryRun says it maps architecture, code relationships, Git behavior, frameworks, routes, auth, and data flow to understand how an application works, then applies confidence scores to findings based on impact before raising an alert.

The platform reaches past the single change. Alongside pull-request review, DryRun sells repository-wide DeepScan reviews, code policies a team writes in plain language, codebase intelligence, secrets scanning, and infrastructure-as-code scanning, and its documentation covers scanning, policy configuration, an API, and a Model Context Protocol integration.

The published detail is specific and self-supplied. The FAQ names a five-part signal model covering surface, language, intent, design and environment, sets out the review model behind a finding, and lists the languages and frameworks the product supports. The New Stack reported in January 2025 that DryRun says contextual security analysis run in GitHub takes only 10 seconds. No third-party benchmark or audited evaluation of the engine appears in the reviewed record. \[[s1](#profile-analysis-sources), [s8](#profile-analysis-sources), [s10](#profile-analysis-sources), [s12](#profile-analysis-sources), [s22](#profile-analysis-sources), [s23](#profile-analysis-sources)\]

### Competitive Positioning

DryRun positions itself against the tools its buyers already run. Its site links comparison pages for Semgrep, GitHub Advanced Security, Snyk Code, Claude Code Security, SonarQube, Aikido, and Wiz Code.

Those comparisons are the company's own work. DryRun publishes them on a capability-matrix site headed "How Your AppSec Stack Compares to DryRun Security", generated in July 2026. No independent evaluation weighing DryRun against those products appears in the reviewed record.

Its lever is reach into the developer workflow. DryRun integrates with GitHub, GitLab, Slack, and coding agents including Claude Code, Codex and Cursor, so its footprint sits inside tools the buyer already administers. \[[s1](#profile-analysis-sources), [s17](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Go-to-Market & Traction

DryRun's commercial proof is a set of named customers and a review count it reports itself. Its customers page publishes ten customer names in its logo images, Tines, Commerce, Invisible, BrightHR, Gusto, PlanetArt, SimpleRose, Flex, Dematic and Zepto, and carries role-attributed testimonials from security engineers at several of them.

The usage figures do not agree across DryRun's own pages. The homepage reports more than 500,000 code reviews a week, the customers page more than 350,000 a month, and the capability-matrix site 500,000 monthly reviews. SecurityBrief reported the company's stated figure of more than 250,000 monthly reviews in early 2026.

Third-party signals exist and stay thin. The customers page states a 4.9 out of 5 rating from 19 reviews on a customer review platform, the capability-matrix site claims a High Performer placement in static analysis for spring 2026, and DryRun reached the four finalists of the 2024 Black Hat Startup Spotlight. No revenue, customer count, or independently verified scale figure appears in the reviewed record. \[[s7](#profile-analysis-sources), [s1](#profile-analysis-sources), [s17](#profile-analysis-sources), [s3](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Team & Credibility

The founders are established figures in application security, which is the team's strongest signal. An investor account documents James Wickett as an early engineer at Signal Sciences who built the initial product infrastructure before becoming Head of Research, and Ken Johnson as a former Director of Product Security Engineering at GitHub.

Their standing shows up outside DryRun's own pages. A USENIX speaker page describes Wickett as the creator and founder of the Lonestar Application Security Conference and says he runs DevOps Days Austin and Serverless Days Austin, and OWASP describes that conference as an annual Austin gathering of 400 or more practitioners. Ken Johnson co-hosts the Absolute AppSec podcast with Seth Law, whose episode list runs to 331. Security press quotes Wickett as an expert voice on AI application risk.

Governance has been added alongside the founders. DryRun appointed Andrew Peterson, a co-founder of Signal Sciences, to its board in February 2026, and trade press covered the appointment. What the record does not show is a founder exit of their own or an independently recognized research program. \[[s4](#profile-analysis-sources), [s13](#profile-analysis-sources), [s18](#profile-analysis-sources), [s14](#profile-analysis-sources), [s15](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Trust Readiness

The capability-matrix site DryRun publishes carries the label "SOC2 Type II Certified" in its footer, and the FAQ says the product is delivered as software as a service with strict data handling.

Nothing in the reviewed record lets a buyer inspect the audit behind that label. A probe on 2026-08-25 found that /security, /trust and /compliance return 404 and that neither a trust nor a security subdomain resolves, with a control subdomain also failing to resolve.

The published detail covers handling rather than assurance. DryRun says its app installs through GitHub or GitLab and that a customer can revoke its permissions instantly at any time, that processing runs in ephemeral microservices, and that it stores security findings and related metadata rather than a copy of the codebase. DryRun also says a third-party security advisor runs quarterly audits of its infrastructure and that a letter of audit is available on request, which a buyer can test only by asking. The FAQ frames SOC 2, ISO 27001, PCI and HIPAA as artifacts the product generates for a customer's own controls. \[[s17](#profile-analysis-sources), [s8](#profile-analysis-sources), [s21](#profile-analysis-sources), [s9](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Snyk | competes with | DryRun publishes a comparison page against Snyk Code, and both sell into the same application-security buyer. |
| Semgrep | competes with | DryRun publishes a comparison page against Semgrep, and both cover the same application code in the developer workflow. |
| Sonar | competes with | DryRun publishes a comparison page against SonarQube, which Sonar sells into the same code-quality and code-security budget. |
| Aikido Security | competes with | DryRun publishes a comparison page against Aikido, placing the two in front of the same developer-security buyer. |
| Wiz | adjacent | DryRun publishes a comparison page against Wiz Code, the code-security line of a cloud-security platform. |
| GitHub | adjacent | Adjacent because DryRun installs through GitHub and publishes a comparison page against GitHub Advanced Security. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (12/21)**

Band guidance: pivot urgently. Analyzed 2026-08-25. Scope: whole company.

The hardest part for a rival to reproduce is the engineering behind DryRun Security's review engine, which models an application and then rules on whether a code change is exploitable. The company says three patents have been awarded on the part that picks out risky code paths, and the reviewed record identifies none of them. That record names no dataset DryRun accumulates across customers, and describes a model built for each codebase. The product installs as a source-control app whose permissions a customer can revoke at any time, so leaving costs the review work and the policies a team wrote rather than a technical unwind. So durability comes down to timing and the founders' standing in application security, a head start rather than a lasting lead.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | DryRun sells software the customer installs through GitHub or GitLab and operates itself, with findings and remediation guidance returned into the pull request (s9, s1). The cited record describes no human review or accountability layer delivered alongside that software. \[[s9](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Switching Cost | 2/3 | The product accumulates a per-codebase model, policies a team writes in plain language, and stored findings that a customer would rebuild elsewhere (s1, s22, s9), which is meaningful friction. DryRun's own page states that its permissions can be revoked instantly through GitHub or GitLab (s9), and the cited record does not size the migration, so the exit is expensive in effort rather than in consequence. \[[s1](#deep-dive-sources), [s22](#deep-dive-sources), [s9](#deep-dive-sources), [s8](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | DryRun's capability-matrix site carries a SOC2 Type II Certified label (s17), and the FAQ frames SOC 2, ISO 27001, PCI and HIPAA as artifacts the product generates for a customer's own audits (s8). A probe found no report, portal or dedicated trust page (s21), and an attestation of that class is ordinary enterprise-market preparation rather than a barrier to replacement. \[[s17](#deep-dive-sources), [s8](#deep-dive-sources), [s21](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Modeling a codebase's architecture, routes, auth and data flow and then ruling on whether a change is exploitable is machine-learning and real-time engineering work (s1), delivered inside a pull-request check the company says returns in seconds, and The New Stack relayed DryRun's claim of a ten-second run (s8, s12). The documentation names supported languages and frameworks from Ruby to Python, which compounds the specialist effort (s8, s10). \[[s1](#deep-dive-sources), [s8](#deep-dive-sources), [s12](#deep-dive-sources), [s10](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The buyers named in the customers page logo images include Tines, Gusto, Dematic and BrightHR (s7, s1), and one of them describes using DryRun while serving Fortune 50 clients of its own (s1). The compliance signal the record carries is a customer story the page labels for e-commerce and PCI (s7), short of the regulated-enterprise or government buyer, with procurement and legal between the company and a replacement, that the next rung describes. \[[s7](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Layer | 2/3 | DryRun runs across the developer toolchain through its own integrations with GitHub, GitLab, Slack, Jira, coding agents and an API (s1, s10), which is platform reach with application features. The product runs on source-control platforms DryRun does not own, and the cited record shows no other software depending on it as infrastructure. \[[s1](#deep-dive-sources), [s10](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The cited record evidences no accumulated asset that accrues to DryRun: the model is built per codebase, and the company says it stores each customer's own security findings and metadata and does not commingle data streams (s1, s9). Its statement that three patents have been awarded carries no identifier, applicant or assignee anywhere in the record (s1), so that intellectual property is stated rather than evidenced. \[[s1](#deep-dive-sources), [s9](#deep-dive-sources)\] |

### Strategic Market Segmentation

DryRun Security sells to application-security and engineering teams at software companies that ship continuously, and it reaches them inside the pull request rather than through a separate console. Its customers page publishes ten customer names in its logo images: Tines, Commerce, Invisible, BrightHR, Gusto, PlanetArt, SimpleRose, Flex, Dematic and Zepto.

The compliance context the record carries is a customer story the page labels for e-commerce and PCI. One customer describes using DryRun while serving Fortune 50 clients of its own, so the served buyer runs an active development organization with some security governance.

Who signs is not visible in the record. Pricing is described as aligned to the size of the engineering and security teams, which points to a sales-assisted purchase, and the public record does not show who controls that budget or how top-down the motion runs. \[[s7](#deep-dive-sources), [s1](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The Contextual Security Analysis engine is the hardest engineering DryRun does and the part it markets most. The company says the engine maps architecture, code relationships, Git behavior, frameworks, routes, auth and data flow, then applies confidence scores to findings based on impact before raising an alert.

The capability now covers the whole repository as well as the single change. A DeepScan Agent launched in February 2026 reviews entire repositories and returns a risk-ranked report within hours, and the platform adds policies a team writes in plain language, secrets scanning and infrastructure-as-code scanning.

What the record evidences is engineering rather than an accumulated asset. DryRun says three patents have been awarded on the part of the engine that finds the changes most likely to create meaningful risk, and the reviewed record identifies none of them. It also identifies no dataset that accumulates across customers, and the company says it stores each customer's own findings and metadata without commingling data streams. \[[s1](#deep-dive-sources), [s11](#deep-dive-sources), [s10](#deep-dive-sources), [s9](#deep-dive-sources), [s22](#deep-dive-sources), [s23](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

DryRun runs a developer-native, demo-led motion. The product installs through GitHub or GitLab and surfaces findings where developers already work, and the site routes a prospective buyer to a demo rather than a self-serve checkout.

Its commercial proof pairs named customers with a usage count it reports itself. Ten customer names appear in the logo images on the customers page, role-attributed testimonials on DryRun's pages name engineers at Tines, BrightHR and Invisible, and trade press quoted a Tines engineer on the repository review at launch.

The gap is independent confirmation of paying scale. DryRun's three usage figures disagree across its own pages, the count measures reviews rather than accounts, and no revenue or customer count is disclosed. \[[s1](#deep-dive-sources), [s7](#deep-dive-sources), [s11](#deep-dive-sources), [s17](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Pricing Model

DryRun publishes its pricing drivers and no rates. The FAQ says pricing aligns with the size of the engineering and security teams, counting the developers, security-team members and owners who need codebase visibility, while the site routes a buyer to a demo.

That choice fits the buyer and the motion. A product that reads an entire codebase and installs into the development workflow is normally sold through evaluation and procurement rather than a card payment.

With drivers published and no rates, a buyer cannot compare DryRun's cost against other scanners from the site alone, which moves price discovery into the sales conversation. \[[s8](#deep-dive-sources), [s1](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Product Delivery & Operations

DryRun delivers as a hosted service that connects to source control and runs inside the pull request. It models the codebase, judges whether a change is exploitable, and returns guidance to developers and their coding agents, so the security work lands in the existing workflow.

The operating signature is per-change review at volume, and the volume is self-reported. The homepage reports more than 500,000 reviews a week, the customers page more than 350,000 a month, and the capability-matrix site 500,000 a month, each of them the company's own count.

What makes DryRun easy to adopt also makes it easy to disconnect. The company says processing runs in ephemeral microservices, that it stores security findings and related metadata rather than a copy of the codebase, and that a customer can revoke its permissions instantly through GitHub or GitLab. \[[s1](#deep-dive-sources), [s7](#deep-dive-sources), [s17](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Earning Customers' Trust

The capability-matrix site DryRun publishes carries the label "SOC2 Type II Certified", and the FAQ describes delivery as software as a service with strict data handling.

The reviewed record offers nothing to inspect behind that label. A probe on 2026-08-25 found that /security, /trust and /compliance return 404 and that neither a trust nor a security subdomain resolves, with a control subdomain also failing to resolve.

What the site does document is data handling. DryRun says it uses its own private model rather than a shared one, that analysis runs in ephemeral microservices, and that it keeps security findings and related metadata rather than a copy of the codebase, and that a third-party advisor audits its infrastructure quarterly with a letter available on request. For a product with full codebase access, an attestation report, a penetration-test summary or a vulnerability-disclosure program is the next thing a careful buyer asks for. \[[s17](#deep-dive-sources), [s8](#deep-dive-sources), [s21](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

DryRun spans the developer toolchain through its own connectors rather than a partner marketplace. It integrates with GitHub, GitLab, Slack and Jira, exposes an API and a Model Context Protocol server, and works alongside coding agents including Claude Code, Codex and Cursor.

The reviewed record shows no third-party marketplace and no partner-built integration catalog behind those connectors.

The same breadth is the exposure. DryRun plugs into platforms it does not own, and it names security products sold by those platforms among the ones it compares itself against. \[[s1](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Team & Execution Capability

DryRun's founders carry verifiable application-security builds, which is the team's strongest signal. An investor account documents James Wickett as an early Signal Sciences engineer who built the initial product infrastructure, and Ken Johnson as a former Director of Product Security Engineering at GitHub.

Their standing is visible outside the company's own pages. A USENIX speaker page describes Wickett as the creator and founder of the Lonestar Application Security Conference, which OWASP describes as an annual Austin gathering of 400 or more practitioners, and Ken Johnson co-hosts the Absolute AppSec podcast, whose episode list runs to 331.

The board addition reinforces the founding pedigree. DryRun appointed Andrew Peterson, a co-founder of Signal Sciences, in February 2026. What the record does not show is an exit of the founders' own or a research program the industry cites back. \[[s4](#deep-dive-sources), [s13](#deep-dive-sources), [s18](#deep-dive-sources), [s14](#deep-dive-sources), [s16](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [DryRun Security homepage: how it works](https://www.dryrun.security/) | official | 2026-08-25 |
| f2 | [FinSMEs: DryRun Security co-founded in 2023 by James Wickett and Ken Johnson](https://www.finsmes.com/2025/01/dryrun-security-raises-8-7m-in-seed-funding.html) | press | 2026-08-25 |
| f3 | [SecurityWeek: DryRun raises $8.7 million seed](https://www.securityweek.com/application-security-firm-dryrun-raises-8-7-million-in-seed-funding/) | press | 2026-08-25 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [DryRun Security homepage: platform description, how it works, usage and patent claims, customer testimonials, comparison links](https://www.dryrun.security/) “The AI-native code security verification platform that understands your code, validates exploitable risk, guides remediation, and enforces policies across human and AI-generated code.” | official | 2026-08-25 |
| s2 | [SecurityWeek: DryRun raises 8.7 million dollar seed, launched from stealth in 2023](https://www.securityweek.com/application-security-firm-dryrun-raises-8-7-million-in-seed-funding/) “The company raised seed funding from LiveOak Ventures, Work-Bench and Cannage Capital. The investment will be used to grow its engineering team and for go-to-market initiatives.” | press | 2026-08-25 |
| s3 | [SecurityBrief UK: DryRun reports more than 250,000 monthly code reviews after its first year out of stealth](https://securitybrief.co.uk/story/dryrun-raises-usd-8-7m-to-secure-ai-driven-coding) “The Austin-based company said it has completed its first year out of stealth. It reported more than 250,000 code reviews run each month by customers.” | press | 2026-08-25 |
| s4 | [Work-Bench investor post: why the firm invested in DryRun Security, with founder backgrounds](https://www.work-bench.com/post/announcing-our-investment-in-dryrun-security) “James brings deep expertise from his time as an early engineer at Signal Sciences, where he built out the initial product infrastructure before moving into developer advocacy as Head of Research.” | official | 2026-08-25 |
| s5 | [FinSMEs: Austin-based DryRun Security raises 8.7 million dollar seed](https://www.finsmes.com/2025/01/dryrun-security-raises-8-7m-in-seed-funding.html) “DryRun Security , an Austin, TX-based AI-native company delivering application security (AppSec) for development and security teams, raised $8.7M in Seed funding.” | press | 2026-08-25 |
| s6 | [DryRun Security newsroom: awards, recognition, and press index](https://www.dryrun.security/newsroom) “We were thrilled to be counted among the four finalists in the BlackHat Startup Spotlight 2024 competition, one of the most prestigious security competitions in the world.” | official | 2026-08-25 |
| s7 | [DryRun Security customers page: customer names published in logo image alt text, customer stories, review rating, monthly review count](https://www.dryrun.security/customers) “Trusted with 350,000+ Code Reviews a Month” | official | 2026-08-25 |
| s8 | [DryRun Security FAQ: pricing drivers, DeepScan Agent, COVER and SLIDE review models, deployment and compliance, supported languages](https://www.dryrun.security/faqs) “How is DryRun Security priced? Pricing is aligned with the size of your engineering and security teams. It focuses on the number of developers and security team members using DryRun Security and owners requiring codebase visibility.” | official | 2026-08-25 |
| s9 | [DryRun Security code-safety page: permissions, private model, ephemeral processing, what the product stores](https://www.dryrun.security/code-safety) “Our app installs via GitHub or GitLab which allows us to access your code base and respond to your developer’s security questions. This gives you control over what we have access to and our permissions can be revoked instantly by you at any time through GitHub or GitLab .” | official | 2026-08-25 |
| s10 | [DryRun Security documentation index: scanning, platform, integrations](https://docs.dryrun.security/) “DryRun Security is an AI-native application security platform that reviews every pull request and repository scan for vulnerabilities in real time.” | official | 2026-08-25 |
| s11 | [IT Brief US: DryRun launches DeepScan Agent for repository-wide review](https://itbrief.news/story/dryrun-unveils-ai-deepscan-agent-for-faster-code-risk) “DryRun Security has launched DeepScan Agent, an AI-based tool that reviews entire software repositories and produces a risk-ranked security report within hours.” | press | 2026-08-25 |
| s12 | [The New Stack: interview on DryRun's contextual security analysis in GitHub](https://thenewstack.io/root-out-vulnerabilities-in-github-as-you-merge-code-changes/) “It maintains that a process called contextual security analysis run in GitHub takes only 10 seconds.” | press | 2026-08-25 |
| s13 | [USENIX SREcon20 Americas speaker page: James Wickett biography](https://www.usenix.org/conference/srecon20americas/speaker-or-organizer/james-wickett-vericaio) “James is the creator and founder of the Lonestar Application Security Conference, which is the largest annual security conference in Austin, TX. He also runs DevOps Days Austin and Serverless Days Austin. He previously served on the global DevOps Days board.” | other | 2026-08-25 |
| s14 | [Absolute AppSec: podcast hosts and episode list](https://absoluteappsec.com/) “Seth Law (@sethlaw) & Ken Johnson (@cktricky) host an informal discussion of all things application security.” | other | 2026-08-25 |
| s15 | [SC Media: Firebase misconfiguration brief quoting DryRun's chief executive](https://www.scworld.com/brief/nearly-300m-chat-ask-ai-user-messages-spilled-by-firebase-misconfiguration) “Mounting AI integration into various products has made such data leaks inevitable, noted DryRun Security CEO James Wickett.” | press | 2026-08-25 |
| s16 | [IT Brief Asia: DryRun appoints Andrew Peterson to its board](https://itbrief.asia/story/dryrun-security-adds-andrew-peterson-to-drive-ai-shift) “DryRun Security has appointed Andrew Peterson to its Board of Directors, adding an executive and investor known for building and backing application and AI security firms.” | press | 2026-08-25 |
| s17 | [DryRun Security capability matrix site: comparison framing, usage and rating figures, SOC2 Type II Certified label](https://matrix.dryrun.security/index.html) “How Your AppSec Stack Compares to DryRun Security” | official | 2026-08-25 |
| s18 | [OWASP Foundation: LASCON event page](https://owasp.org/www-revent-lascon/) “The LASCON (Lonestar Application Security Conference) is an annual conference held in Austin, TX. It is a gathering of 400+ web app developers, security engineers, mobile developers and information security professionals.” | other | 2026-08-25 |
| s19 | [DryRun Security about page: positioning and founders](https://www.dryrun.security/about) “DryRun Security is the industry’s first AI-native, agentic code security intelligence solution.” | official | 2026-08-25 |
| s20 | [DryRun Security agentic coding security report page: study findings](https://www.dryrun.security/the-agentic-coding-security-report) “87% of pull requests introduced at least one security vulnerability” | official | 2026-08-25 |
| s21 | [DryRun trust-surface probe: /security /trust /compliance 404, no trust. or security. subdomain, control subdomain absent](https://www.dryrun.security/security) | official | 2026-08-25 |
| s22 | [DryRun Security custom code policies product page: how natural-language policies are written and enforced](https://www.dryrun.security/product/custom-code-policies) “With DryRun Security, you describe in natural language how code should behave. The Custom Policy Agent turns those statements into enforceable checks on every PR, going far beyond brittle rules and regex.” | official | 2026-08-25 |
| s23 | [DryRun Security codebase intelligence product page: Code Insights questions over the codebase](https://www.dryrun.security/product/codebase-intelligence) “DryRun Security gives you an always-on view of your codebase through the Code Insights MCP. Instead of stitching together dashboards and exports, you ask real questions in natural language and get precise, contextual answers about risk, trends, and exposure across your repositories.” | official | 2026-08-25 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [DryRun Security homepage: platform description, how it works, usage and patent claims, customer testimonials, comparison links](https://www.dryrun.security/) “The AI-native code security verification platform that understands your code, validates exploitable risk, guides remediation, and enforces policies across human and AI-generated code.” | official | 2026-08-25 |
| s2 | [SecurityWeek: DryRun raises 8.7 million dollar seed, launched from stealth in 2023](https://www.securityweek.com/application-security-firm-dryrun-raises-8-7-million-in-seed-funding/) “The company raised seed funding from LiveOak Ventures, Work-Bench and Cannage Capital. The investment will be used to grow its engineering team and for go-to-market initiatives.” | press | 2026-08-25 |
| s3 | [SecurityBrief UK: DryRun reports more than 250,000 monthly code reviews after its first year out of stealth](https://securitybrief.co.uk/story/dryrun-raises-usd-8-7m-to-secure-ai-driven-coding) “The Austin-based company said it has completed its first year out of stealth. It reported more than 250,000 code reviews run each month by customers.” | press | 2026-08-25 |
| s4 | [Work-Bench investor post: why the firm invested in DryRun Security, with founder backgrounds](https://www.work-bench.com/post/announcing-our-investment-in-dryrun-security) “James brings deep expertise from his time as an early engineer at Signal Sciences, where he built out the initial product infrastructure before moving into developer advocacy as Head of Research.” | official | 2026-08-25 |
| s5 | [FinSMEs: Austin-based DryRun Security raises 8.7 million dollar seed](https://www.finsmes.com/2025/01/dryrun-security-raises-8-7m-in-seed-funding.html) “DryRun Security , an Austin, TX-based AI-native company delivering application security (AppSec) for development and security teams, raised $8.7M in Seed funding.” | press | 2026-08-25 |
| s6 | [DryRun Security newsroom: awards, recognition, and press index](https://www.dryrun.security/newsroom) “We were thrilled to be counted among the four finalists in the BlackHat Startup Spotlight 2024 competition, one of the most prestigious security competitions in the world.” | official | 2026-08-25 |
| s7 | [DryRun Security customers page: customer names published in logo image alt text, customer stories, review rating, monthly review count](https://www.dryrun.security/customers) “Trusted with 350,000+ Code Reviews a Month” | official | 2026-08-25 |
| s8 | [DryRun Security FAQ: pricing drivers, DeepScan Agent, COVER and SLIDE review models, deployment and compliance, supported languages](https://www.dryrun.security/faqs) “How is DryRun Security priced? Pricing is aligned with the size of your engineering and security teams. It focuses on the number of developers and security team members using DryRun Security and owners requiring codebase visibility.” | official | 2026-08-25 |
| s9 | [DryRun Security code-safety page: permissions, private model, ephemeral processing, what the product stores](https://www.dryrun.security/code-safety) “Our app installs via GitHub or GitLab which allows us to access your code base and respond to your developer’s security questions. This gives you control over what we have access to and our permissions can be revoked instantly by you at any time through GitHub or GitLab .” | official | 2026-08-25 |
| s10 | [DryRun Security documentation index: scanning, platform, integrations](https://docs.dryrun.security/) “DryRun Security is an AI-native application security platform that reviews every pull request and repository scan for vulnerabilities in real time.” | official | 2026-08-25 |
| s11 | [IT Brief US: DryRun launches DeepScan Agent for repository-wide review](https://itbrief.news/story/dryrun-unveils-ai-deepscan-agent-for-faster-code-risk) “DryRun Security has launched DeepScan Agent, an AI-based tool that reviews entire software repositories and produces a risk-ranked security report within hours.” | press | 2026-08-25 |
| s12 | [The New Stack: interview on DryRun's contextual security analysis in GitHub](https://thenewstack.io/root-out-vulnerabilities-in-github-as-you-merge-code-changes/) “It maintains that a process called contextual security analysis run in GitHub takes only 10 seconds.” | press | 2026-08-25 |
| s13 | [USENIX SREcon20 Americas speaker page: James Wickett biography](https://www.usenix.org/conference/srecon20americas/speaker-or-organizer/james-wickett-vericaio) “James is the creator and founder of the Lonestar Application Security Conference, which is the largest annual security conference in Austin, TX. He also runs DevOps Days Austin and Serverless Days Austin. He previously served on the global DevOps Days board.” | other | 2026-08-25 |
| s14 | [Absolute AppSec: podcast hosts and episode list](https://absoluteappsec.com/) “Seth Law (@sethlaw) & Ken Johnson (@cktricky) host an informal discussion of all things application security.” | other | 2026-08-25 |
| s15 | [SC Media: Firebase misconfiguration brief quoting DryRun's chief executive](https://www.scworld.com/brief/nearly-300m-chat-ask-ai-user-messages-spilled-by-firebase-misconfiguration) “Mounting AI integration into various products has made such data leaks inevitable, noted DryRun Security CEO James Wickett.” | press | 2026-08-25 |
| s16 | [IT Brief Asia: DryRun appoints Andrew Peterson to its board](https://itbrief.asia/story/dryrun-security-adds-andrew-peterson-to-drive-ai-shift) “DryRun Security has appointed Andrew Peterson to its Board of Directors, adding an executive and investor known for building and backing application and AI security firms.” | press | 2026-08-25 |
| s17 | [DryRun Security capability matrix site: comparison framing, usage and rating figures, SOC2 Type II Certified label](https://matrix.dryrun.security/index.html) “How Your AppSec Stack Compares to DryRun Security” | official | 2026-08-25 |
| s18 | [OWASP Foundation: LASCON event page](https://owasp.org/www-revent-lascon/) “The LASCON (Lonestar Application Security Conference) is an annual conference held in Austin, TX. It is a gathering of 400+ web app developers, security engineers, mobile developers and information security professionals.” | other | 2026-08-25 |
| s19 | [DryRun Security about page: positioning and founders](https://www.dryrun.security/about) “DryRun Security is the industry’s first AI-native, agentic code security intelligence solution.” | official | 2026-08-25 |
| s20 | [DryRun Security agentic coding security report page: study findings](https://www.dryrun.security/the-agentic-coding-security-report) “87% of pull requests introduced at least one security vulnerability” | official | 2026-08-25 |
| s21 | [DryRun trust-surface probe: /security /trust /compliance 404, no trust. or security. subdomain, control subdomain absent](https://www.dryrun.security/security) | official | 2026-08-25 |
| s22 | [DryRun Security custom code policies product page: how natural-language policies are written and enforced](https://www.dryrun.security/product/custom-code-policies) “With DryRun Security, you describe in natural language how code should behave. The Custom Policy Agent turns those statements into enforceable checks on every PR, going far beyond brittle rules and regex.” | official | 2026-08-25 |
| s23 | [DryRun Security codebase intelligence product page: Code Insights questions over the codebase](https://www.dryrun.security/product/codebase-intelligence) “DryRun Security gives you an always-on view of your codebase through the Code Insights MCP. Instead of stitching together dashboards and exports, you ask real questions in natural language and get precise, contextual answers about risk, trends, and exposure across your repositories.” | official | 2026-08-25 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
