The Business of Cyber Security

Application and Software Supply-Chain Security

Application security (AppSec) secures software close to where it is made. The domain has shifted from scanning the finished application to securing the whole build-and-release pipeline, and is now shaped by AI generating a rising share of code. Among its leaders, Snyk re-rated as growth decelerated, while supply-chain entrants such as Endor Labs and Chainguard grew quickly from a small base. A central question is which of these vendors are platforms and which are features.

Scope: application and software supply-chain security

This domain secures software across its life cycle — the code developers write, the open-source and third-party components they pull in, and the build/release pipeline that ships it. The historically separate tool categories are collapsing into "application security posture management" (ASPM) platforms:

Strategically, AppSec is where shift-left meets the developer. The vendor that owns the developer's trust and workflow — the IDE plug-in, the pull-request check, the single dashboard for all app risk — tends to own the buying decision. That makes ASPM the natural control point, with reachability and AI-triage the features that determine who wins it. The domain is also directly exposed to the AI-coding wave: AI assistants now generate a large and rising share of new code, which both creates more vulnerable code to scan and threatens to absorb security checks into the coding platform (GitHub, GitLab, Cursor) itself.

How the vendors differ

Vendor Owner Posture Differentiation / economics
Snyk Private (large) Developer-first platform Pioneered the developer-first, bottoms-up SCA/AppSec motion; ~$326M ARR (Feb 2026, est.) but growth decelerated to ~7% and valuation reset toward ~$3.7–7B; a category-definer that reached the platform ceiling. In 2026 the company entered an AI-security reorientation: CEO Peter McKay announced his departure in February (stating the next decade required "a leader with deep roots in product innovation and artificial intelligence") and left in April, with CFO Ken MacAskill as interim CEO; in June it cut ~90 roles (~6% of ~1,500 — its fourth reduction), including its Israel development center, to concentrate resources on the AI-security platform (The Register, Feb 2026 · Boston Globe, Jul 14 2026)
Checkmarx TPG / Hellman & Friedman Enterprise platform Evolved from SAST into Checkmarx One (SAST+SCA+IaC+DAST+ASPM); top-down enterprise sales; sponsor-owned consolidator
Veracode TA Associates Enterprise platform Binary-analysis SAST (no source access needed) + DAST/SCA; compliance-grade, regulated-industry install base; PE-owned, acquisitive (Longbow, Phylum)
Black Duck Standalone (ex-Synopsys) SCA incumbent Synopsys spun out its Software Integrity Group (2024); the legacy SCA/audit franchise — open-source license + vulnerability compliance
GitHub Advanced Security Microsoft Bundler Security folded into where code already lives; CodeQL SAST + Dependabot SCA + secret scanning bundled into the platform — the "free with the repo" threat
GitLab GitLab (GTLB) Bundler DevSecOps suite with built-in SAST/DAST/SCA; security as a reason to consolidate the whole pipeline on one platform
Semgrep Private (VC) Developer-first challenger Fast, open-core, rules-based SAST loved by engineers; bottoms-up adoption attacking legacy SAST on speed and price
Endor Labs Private (VC) Supply-chain specialist Reachability-based SCA (only flags vulnerabilities the code can actually reach) — cuts false positives; ~$15M ARR end-2025 (+131%), $188M raised; a fast-growing supply-chain entrant
Chainguard Private (VC) Supply-chain / hardened images Minimal, continuously-patched container images and dependencies ("secure by default" software factory); raised at a multi-billion valuation on near-zero-CVE distroless images
Socket Private (VC) Supply-chain specialist Detects malicious open-source packages in real time at install — guards against the active-attack (typosquat, dependency-confusion) vector SCA misses
Cycode / ArmorCode / Apiiro Private (VC) ASPM aggregators The pure-play ASPM layer — correlate/prioritize findings across tools; the consolidation layer that is itself consolidation supply
Salt / Traceable / Noname various (Noname→Akamai) API security Secure the APIs apps expose at runtime — adjacent to AppSec; Akamai bought Noname (2024), Traceable went to Harness/Cisco-adjacent buyers

The domain divides into three camps. The enterprise platforms (Checkmarx, Veracode, Black Duck) own the regulated, top-down install base and the compliance workflows; their value is breadth and the audit trail rather than developer adoption. The developer-first players (Snyk, Semgrep) won bottoms-up adoption inside engineering teams — strong distribution, but converting free or low-cost developer adoption into enterprise platform revenue is difficult, as Snyk's deceleration illustrates. The supply-chain specialists (Endor Labs, Chainguard, Socket) address a newer problem — the open-source and build-pipeline attack surface — with more focused technical approaches (reachability, hardened images, malicious-package detection); they are among the highest-growth and highest-multiple assets in the domain. The bundlers (GitHub/Microsoft, GitLab) can offer good-enough AppSec with the repository.

AppSec value pools and growth trajectory

AppSec value pools — where the growth is (directional, est.) flat Legacy SAST/DAST (Checkmarx/Veracode) → ↑↑ Supply-chain/SCA (Endor/Chainguard/Socket) ASPM layer (Cycode/ArmorCode/Apiiro)
Directional view (illustrative, not to scale): legacy application testing is a large, slow-growing pool; software-supply-chain (reachability SCA, hardened images, malicious-package detection) and the ASPM aggregation layer are the high-growth, high-multiple, most-acquirable pools. The broader application-security software market is widely projected to compound at a low-double-digit CAGR through the decade. Sources: Application Security Software Market Outlook 2026–2034; Sacra — Endor Labs.

Signature deals & events

The bear case

The AppSec bull case is "all software must be secured before it ships, AI is writing exponentially more of it, and the ASPM layer that unifies app risk is durable, high-switching-cost real estate." The bear case is that AppSec is structurally exposed to being absorbed by the platforms that own the developer. From above, GitHub (Microsoft) and GitLab can bundle good-enough SAST/SCA/secret-scanning into the repository at near-zero marginal price — and the developer is already there. From the side, the AI-coding platforms (Copilot, Cursor) could make "secure as you write" a native feature, collapsing the standalone scanner. And the developer-first model has a demonstrated ceiling: Snyk built phenomenal bottoms-up distribution and still decelerated to single-digit growth and a valuation reset, showing how hard it is to convert developer adoption into durable enterprise platform economics. Falsifiable test: watch whether GitHub Advanced Security and GitLab take net-new AppSec budget from standalone vendors, and whether the high-growth supply-chain specialists (Endor, Chainguard) sustain triple-digit growth or get tucked in before reaching escape velocity. If the standalone AppSec vendors decelerate while the bundlers and AI-coding platforms take the net-new spend, the "AppSec is a durable independent platform" thesis is breaking — and the category is a feature war, not a platform war.

Cross-references: Vendors, Cloud Security, SecOps & SIEM, AI Security, Deals & Comps, Bear Case.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.