High-Level Overview
Nokod Security is a cybersecurity startup founded in 2023 that builds a security platform tailored for low-code/no-code (LCNC) applications and Robotic Process Automation (RPA).[1][2] It automatically discovers, maps, and monitors apps built on platforms like Microsoft Power Platform, UiPath, Salesforce, ServiceNow, and OutSystems, detecting vulnerabilities, compliance issues, misconfigurations, data leaks, secrets, and supply chain risks while providing remediation guidance for citizen developers and security teams.[1][2] The company serves enterprises undergoing digital transformation, addressing security gaps in no-code environments that traditional AppSec tools overlook, with $8M raised in a Seed VC round and headquarters in Tel Aviv, Israel.[1] Its growth includes recent events like hosting a Capture the Flag competition at OWASP Global AppSec EU 2025 and thought leadership on RPA and CTEM risks.[1][2]
Origin Story
Nokod Security was co-founded in 2023 by Yair Finzi (CEO), previously co-founder and CEO of SecuredTouch, and Amichai Shulman (CTO), former co-founder and CTO of Imperva, both cybersecurity veterans bringing deep expertise in application security and behavioral analytics.[2][3] The idea emerged amid the rapid rise of LCNC platforms and RPA, which enable "citizen developers" to build apps quickly but introduce unmonitored risks like injection attacks, public exposures, and supply chain vulnerabilities not covered by legacy tools.[2] Early traction built on the founders' track record—Imperva pioneered web app security, while SecuredTouch focused on touch-based behavioral biometrics—positioning Nokod to secure the "no-code revolution" from day one, backed by elite investors and quick $8M funding.[1][3]
Core Differentiators
Nokod stands out in the AppSec market by focusing exclusively on LCNC and RPA environments, unlike generalist competitors like Snyk, Veracode, or Checkmarx that prioritize traditional codebases.[1][2]
- No-Code Native Platform: Automatically inventories apps/automations across platforms (e.g., PowerApps, UiPath), detects unique risks like client-side data access and marketplace supply chain attacks, and offers real-time remediation—making security an "enabler, not a bottleneck."[2]
- Citizen Developer Focus: Provides simple guidance for non-experts while empowering SecOps with CTEM-aligned continuous monitoring, compliance checks, and malicious activity detection.[1][2]
- Comprehensive Coverage: Handles visibility, governance, and protection for no-code, automations, and AI apps, filling gaps in traditional stacks amid Gartner's CTEM push.[2]
- Proven Leadership: Backed by founders from Imperva/SecuredTouch and a team of industry vets (e.g., VPs in engineering, sales), with demos emphasizing speed and ease over manual processes.[3]
Role in the Broader Tech Landscape
Nokod rides the explosive growth of LCNC platforms, projected to power 70% of new apps by 2025, as enterprises accelerate digital transformation but face surging risks from citizen-led development.[2] Timing is ideal: post-pandemic automation booms (e.g., RPA via UiPath) coincide with rising supply chain attacks and regulations like GDPR, where no-code marketplaces amplify threats—Nokod's platform aligns with Gartner's Continuous Threat Exposure Management (CTEM) for real-time oversight.[1][2] It influences the ecosystem by enabling secure innovation, reducing SecOps overload, and hosting events like OWASP challenges to highlight Power BI vulnerabilities, positioning it as a pioneer in "future-proofing" no-code security.[1][2]
Quick Take & Future Outlook
Nokod is poised for rapid scaling with its Seed funding, targeting enterprise adoption amid LCNC's dominance and AI-augmented automations.[1][2] Expect expansion into more platforms, deeper AI risk detection, and potential Series A as CTEM mandates grow, shaped by trends like zero-trust for citizen dev and marketplace scrutiny.[2] Its influence could evolve from niche protector to LCNC security standard, much like Imperva defined web AppSec—securing the no-code era without slowing innovation, true to its mission of "digital transformation without regrets."[3]