Loading organizations...
Based in Tel Aviv, Israel, Cycode provides a subscription-based enterprise software platform that combines application security testing, posture management, and software supply chain security to protect development lifecycles. The cybersecurity company operates across three main global locations and currently employs a workforce of more than 150 industry professionals. Its software-as-a-service offering provides DevOps teams with comprehensive visibility, control, and threat detection capabilities across distributed source code repositories to mitigate code-related vulnerabilities. Cycode has raised over $81 million in total funding across multiple financing rounds, including a $20 million Series A and a $4.6 million initial seed round. The enterprise security startup is backed by prominent venture capital firms and angel investors, including Insight Partners, YL Ventures, Mike Fey, and Eyal Gruner. Cycode was founded in 2019 by technology executives Lior Levy and Ronen Slavin.
Cycode has raised $81.0M across 3 funding rounds.
Cycode has raised $81.0M in total across 3 funding rounds.
Cycode has raised $81.0M in total across 3 funding rounds.
Cycode's investors include Insight Partners, John Brennan, YL Ventures, Yoav Andrew Leitersdorf, Citi Ventures, Cyberstarts VC, General Catalyst, Mayfield, Owl Rock Capital Partners, Vertex Ventures Israel, Frederic Kerrest, Noa Wolfson.
Cycode has raised $81.0M across 3 funding rounds. Most recently, it raised $56.0M Series B in November 2021.
| Date | Round | Lead Investors | Other Investors | Status |
|---|---|---|---|---|
| Nov 1, 2021 | $56M Series B | Insight Partners | John Brennan | Announced |
| May 1, 2021 | $20M Series A | Insight Partners | YL Ventures | Announced |
| Sep 1, 2019 | $5M Seed | Yoav Andrew Leitersdorf | Citi Ventures, Cyberstarts VC, General Catalyst, Mayfield, OWL Rock Capital Partners, Vertex Ventures Israel, Frederic Kerrest, NOA Wolfson, Sohaib Abbasi, Andy Grolnick, Eyal Gruner, Justin Somaini, Michael FEY | Announced |
Cycode is an AI-native Application Security Platform (ASPM) that secures software development from code to runtime, particularly for AI-generated code, by providing unified visibility, risk prioritization, and remediation across the software supply chain.[1][3][4] It builds tools for detecting secrets, vulnerabilities via SAST/SCA/IaC scanning, CI/CD security, code leaks, and container security, serving enterprises in finance, software, retail, banking, telecom, healthcare, and more by solving AppSec chaos in DevOps—reducing developer friction and MTTR with contextual AI fixes.[2][3][4][5] Growth momentum includes recent innovations like Technologies Inventory for SDLC visibility, AI/ML asset cataloging to tackle shadow AI, and eBPF-based CI monitoring (Cimon), positioning it as a comprehensive replacement or integrator for legacy tools.[6][7][9]
Cycode was founded in 2019 by three developers—experienced in software engineering—who identified the security burdens placed on developers amid the DevOps revolution and AppSec tool sprawl.[1][5] Headquartered in New York, NY, with primary R&D in Tel Aviv, Israel, the idea emerged from their realization that existing tools lacked unified visibility and context from code to runtime, especially as AI accelerated development.[1][2][3] Early traction came from building proprietary scanners for secrets detection and supply chain security, evolving into a full ASPM platform that correlates data across eight top AppSec tools for capabilities like Pipeline Composition Analysis.[1][7]
Cycode rides the AI-driven DevSecOps wave, where generative AI floods pipelines with unvetted code, amplifying supply chain risks amid rising breaches (e.g., code leaks, vulnerable dependencies).[1][3][9] Timing is ideal post-2019 founding, aligning with cloud-native shifts, eBPF maturity, and regulations demanding SBOMs/ASPM—market forces like tool sprawl and shadow AI favor its unified platform over siloed competitors like Veracode or GitGuardian.[2][7] It influences the ecosystem by enabling "security that works like devs do," boosting efficiency in high-stakes sectors and setting standards for contextual, AI-accelerated AppSec.[3][4][5]
Cycode is poised to dominate AI-era ASPM as genAI adoption explodes, expanding via innovations like AI/ML inventories and runtime agents to preempt shadow risks in hybrid human-AI workflows.[6][7][9] Trends like zero-trust SDLC, regulatory SBOM mandates, and eBPF ubiquity will propel growth, potentially through deeper AWS/enterprise integrations and global scaling from its US-Israel base.[1][5] Its influence may evolve into the de facto standard for securing "the software the world depends on," tying back to its dev-founders' vision of frictionless, fast security in chaotic DevOps landscapes.[3][5]