Application and Software Supply-Chain Security
Application security (AppSec) secures software close to where it is made. The domain has shifted from scanning the finished application to securing the whole build-and-release pipeline, and is now shaped by AI generating a rising share of code. Among its leaders, Snyk re-rated as growth decelerated, while supply-chain entrants such as Endor Labs and Chainguard grew quickly from a small base. A central question is which of these vendors are platforms and which are features.
Scope: application and software supply-chain security
This domain secures software across its life cycle — the code developers write, the open-source and third-party components they pull in, and the build/release pipeline that ships it. The historically separate tool categories are collapsing into "application security posture management" (ASPM) platforms:
- SAST (static analysis): scans source code for vulnerabilities before it runs. The original AppSec category — Checkmarx, Veracode, Fortify, Semgrep, Snyk Code.
- DAST/IAST (dynamic / interactive testing): tests the running application from the outside (DAST) or instruments it from the inside (IAST). Veracode, Invicti, HCL AppScan.
- SCA (software composition analysis): inventories open-source dependencies and flags known-vulnerable or malicious packages — the heart of supply-chain security. Snyk (its wedge product), Black Duck (Synopsys spinout), Endor Labs, Socket, Mend.
- Software supply-chain / pipeline security: secures the build system itself — CI/CD, artifacts, secrets, signing, SBOMs, and the provenance chain (SLSA). Chainguard (hardened/minimal container images), Palo Alto (Cider), GitLab/GitHub Advanced Security, Legit Security, Endor Labs.
- ASPM (the aggregation layer): correlates findings from all of the above, deduplicates, prioritizes by reachability/exploitability, and routes fixes to developers. This is the layer everyone is racing to own — Checkmarx One, Snyk, Cycode, ArmorCode, Apiiro.
Strategically, AppSec is where shift-left meets the developer. The vendor that owns the developer's trust and workflow — the IDE plug-in, the pull-request check, the single dashboard for all app risk — tends to own the buying decision. That makes ASPM the natural control point, with reachability and AI-triage the features that determine who wins it. The domain is also directly exposed to the AI-coding wave: AI assistants now generate a large and rising share of new code, which both creates more vulnerable code to scan and threatens to absorb security checks into the coding platform (GitHub, GitLab, Cursor) itself.
How the vendors differ
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| Snyk | Private (large) | Developer-first platform | Pioneered the developer-first, bottoms-up SCA/AppSec motion; ~$326M ARR (Feb 2026, est.) but growth decelerated to ~7% and valuation reset toward ~$3.7–7B; a category-definer that reached the platform ceiling. In 2026 the company entered an AI-security reorientation: CEO Peter McKay announced his departure in February (stating the next decade required "a leader with deep roots in product innovation and artificial intelligence") and left in April, with CFO Ken MacAskill as interim CEO; in June it cut ~90 roles (~6% of ~1,500 — its fourth reduction), including its Israel development center, to concentrate resources on the AI-security platform (The Register, Feb 2026 · Boston Globe, Jul 14 2026) |
| Checkmarx | TPG / Hellman & Friedman | Enterprise platform | Evolved from SAST into Checkmarx One (SAST+SCA+IaC+DAST+ASPM); top-down enterprise sales; sponsor-owned consolidator |
| Veracode | TA Associates | Enterprise platform | Binary-analysis SAST (no source access needed) + DAST/SCA; compliance-grade, regulated-industry install base; PE-owned, acquisitive (Longbow, Phylum) |
| Black Duck | Standalone (ex-Synopsys) | SCA incumbent | Synopsys spun out its Software Integrity Group (2024); the legacy SCA/audit franchise — open-source license + vulnerability compliance |
| GitHub Advanced Security | Microsoft | Bundler | Security folded into where code already lives; CodeQL SAST + Dependabot SCA + secret scanning bundled into the platform — the "free with the repo" threat |
| GitLab | GitLab (GTLB) | Bundler | DevSecOps suite with built-in SAST/DAST/SCA; security as a reason to consolidate the whole pipeline on one platform |
| Semgrep | Private (VC) | Developer-first challenger | Fast, open-core, rules-based SAST loved by engineers; bottoms-up adoption attacking legacy SAST on speed and price |
| Endor Labs | Private (VC) | Supply-chain specialist | Reachability-based SCA (only flags vulnerabilities the code can actually reach) — cuts false positives; ~$15M ARR end-2025 (+131%), $188M raised; a fast-growing supply-chain entrant |
| Chainguard | Private (VC) | Supply-chain / hardened images | Minimal, continuously-patched container images and dependencies ("secure by default" software factory); raised at a multi-billion valuation on near-zero-CVE distroless images |
| Socket | Private (VC) | Supply-chain specialist | Detects malicious open-source packages in real time at install — guards against the active-attack (typosquat, dependency-confusion) vector SCA misses |
| Cycode / ArmorCode / Apiiro | Private (VC) | ASPM aggregators | The pure-play ASPM layer — correlate/prioritize findings across tools; the consolidation layer that is itself consolidation supply |
| Salt / Traceable / Noname | various (Noname→Akamai) | API security | Secure the APIs apps expose at runtime — adjacent to AppSec; Akamai bought Noname (2024), Traceable went to Harness/Cisco-adjacent buyers |
The domain divides into three camps. The enterprise platforms (Checkmarx, Veracode, Black Duck) own the regulated, top-down install base and the compliance workflows; their value is breadth and the audit trail rather than developer adoption. The developer-first players (Snyk, Semgrep) won bottoms-up adoption inside engineering teams — strong distribution, but converting free or low-cost developer adoption into enterprise platform revenue is difficult, as Snyk's deceleration illustrates. The supply-chain specialists (Endor Labs, Chainguard, Socket) address a newer problem — the open-source and build-pipeline attack surface — with more focused technical approaches (reachability, hardened images, malicious-package detection); they are among the highest-growth and highest-multiple assets in the domain. The bundlers (GitHub/Microsoft, GitLab) can offer good-enough AppSec with the repository.
AppSec value pools and growth trajectory
Signature deals & events
- Synopsys → Black Duck spin-out (2024) — Synopsys separated its Software Integrity Group (rebranded Black Duck) to focus on chips; carved a standalone SCA/AppSec franchise into the market and a future consolidation target/acquirer.
- Akamai → Noname Security (~$450M, 2024) — a CDN/edge vendor buying its way into API security; the template for adjacents entering AppSec at the runtime/API layer (Akamai has since added LayerX for browser security, 2026).
- Cisco → various / Harness, and Traceable consolidation — API-security specialists (Salt, Traceable) being absorbed as runtime-protection features, validating that standalone API security is a feature, not a platform.
- Endor Labs Series B (~$93M, 2025; ~$188M total) — reachability-based SCA scaling fast (~$15M ARR end-2025, +131% YoY); the marquee independent supply-chain asset and a likely target for a platform that lacks credible SCA.
- Chainguard's multi-billion-dollar rounds (2024–2025) — "secure-by-default" hardened images re-rating as the supply-chain-security narrative goes mainstream after Log4Shell / SolarWinds / xz-utils; a category created from a CVE-fatigue pain point.
- The AI-coding inflection (2025–2026) — GitHub Copilot, Cursor, and agentic coding tools generating a rising share of code is the demand catalyst (more code, more vulnerabilities, "secure the AI-written code") and the disruption (security absorbed into the coding platform). See AI Security.
The bear case
The AppSec bull case is "all software must be secured before it ships, AI is writing exponentially more of it, and the ASPM layer that unifies app risk is durable, high-switching-cost real estate." The bear case is that AppSec is structurally exposed to being absorbed by the platforms that own the developer. From above, GitHub (Microsoft) and GitLab can bundle good-enough SAST/SCA/secret-scanning into the repository at near-zero marginal price — and the developer is already there. From the side, the AI-coding platforms (Copilot, Cursor) could make "secure as you write" a native feature, collapsing the standalone scanner. And the developer-first model has a demonstrated ceiling: Snyk built phenomenal bottoms-up distribution and still decelerated to single-digit growth and a valuation reset, showing how hard it is to convert developer adoption into durable enterprise platform economics. Falsifiable test: watch whether GitHub Advanced Security and GitLab take net-new AppSec budget from standalone vendors, and whether the high-growth supply-chain specialists (Endor, Chainguard) sustain triple-digit growth or get tucked in before reaching escape velocity. If the standalone AppSec vendors decelerate while the bundlers and AI-coding platforms take the net-new spend, the "AppSec is a durable independent platform" thesis is breaking — and the category is a feature war, not a platform war.
→ Cross-references: Vendors, Cloud Security, SecOps & SIEM, AI Security, Deals & Comps, Bear Case.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.