Security Startups

Young security companies, mapped

The security industry, mapped by companies that are actually alive.

Vendor floors mix booths, vaporware, and quietly dead startups with the companies still shipping. This is a curated, independently verified directory of young security companies, organized by what they build, with a proof-of-life signal on every entry. No pay-for-rank.

148 verified companies across 12 categories.

We compete here too

Better ISMS builds Aevral, listed here under the same rules.

Aevral is a GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot. Coming soon. Alphabetical, no pin. Details on transparency and the Aevral listing.

Categories

By what they build

View all

Application security

16

Startups that find and fix weaknesses in application code: SAST, ASPM, authz and business-logic scanners, not the PR-comment bots.

Cloud security

16

CNAPP, CSPM, and workload startups that map cloud attack surface for companies that do not want another console from a network-security incumbent.

Identity and access

15

Workforce, customer, and ITDR startups. Identity is the control plane; these companies treat it as the product.

Detection and response

14

Independent XDR, MDR, and detection-engineering startups. Not the public mega-cap EDR floor.

Offensive and exposure

13

CTEM, attack-surface, pentest-platform, and continuous-exposure startups. Not a services firm with a PDF report.

Data security

12

DSPM, data detection, and data-access startups that tell you where sensitive data actually lives.

AI security

12

Startups securing models, agents, and LLM applications: red teaming, runtime guards, and agent identity.

Software supply chain

12

SCA, SBOM, package, and pipeline-security startups that treat dependencies as the product surface.

Secrets and non-human identity

11

Secrets, certificates, machine identity, and NHI startups. The credentials humans did not mean to ship.

Email and collaboration

10

Email security, browser isolation, and collaboration-security startups built after the last generation of secure email gateways.

Endpoint and browser

9

Independent endpoint, browser-security, and device startups. Not CrowdStrike-class public mega-caps.

API and runtime

8

API security, runtime application protection, and service-mesh startups watching production, not just pull requests.

01 Founders and operators

For the field

One primary category per company, assigned by what it actually ships. Compare application-security startups against cloud CNAPP companies without wading through Black Hat booth copy.

02 Companies

For companies

Not listed, or miscategorized? Free submission with review. Every entry needs a 2024 to 2026 proof-of-life signal. Nothing buys rank or a better category.

03 Agents

For AI agents

The whole catalog is machine-readable: search API, full JSON dump, llms.txt, and an MCP server. Built to be quoted by agents doing security-market research.