Young security companies, mapped
The security industry, mapped by companies that are actually alive.
Vendor floors mix booths, vaporware, and quietly dead startups with the companies still shipping. This is a curated, independently verified directory of young security companies, organized by what they build, with a proof-of-life signal on every entry. No pay-for-rank.
148 verified companies across 12 categories.
We compete here too
Better ISMS builds Aevral, listed here under the same rules.
Aevral is a GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot. Coming soon. Alphabetical, no pin. Details on transparency and the Aevral listing.
Categories
By what they build
Application security
16Startups that find and fix weaknesses in application code: SAST, ASPM, authz and business-logic scanners, not the PR-comment bots.
Cloud security
16CNAPP, CSPM, and workload startups that map cloud attack surface for companies that do not want another console from a network-security incumbent.
Identity and access
15Workforce, customer, and ITDR startups. Identity is the control plane; these companies treat it as the product.
Detection and response
14Independent XDR, MDR, and detection-engineering startups. Not the public mega-cap EDR floor.
Offensive and exposure
13CTEM, attack-surface, pentest-platform, and continuous-exposure startups. Not a services firm with a PDF report.
Data security
12DSPM, data detection, and data-access startups that tell you where sensitive data actually lives.
AI security
12Startups securing models, agents, and LLM applications: red teaming, runtime guards, and agent identity.
Software supply chain
12SCA, SBOM, package, and pipeline-security startups that treat dependencies as the product surface.
Secrets and non-human identity
11Secrets, certificates, machine identity, and NHI startups. The credentials humans did not mean to ship.
Email and collaboration
10Email security, browser isolation, and collaboration-security startups built after the last generation of secure email gateways.
Endpoint and browser
9Independent endpoint, browser-security, and device startups. Not CrowdStrike-class public mega-caps.
API and runtime
8API security, runtime application protection, and service-mesh startups watching production, not just pull requests.
01 Founders and operators
For the field
One primary category per company, assigned by what it actually ships. Compare application-security startups against cloud CNAPP companies without wading through Black Hat booth copy.
02 Companies
For companies
Not listed, or miscategorized? Free submission with review. Every entry needs a 2024 to 2026 proof-of-life signal. Nothing buys rank or a better category.
03 Agents
For AI agents
The whole catalog is machine-readable: search API, full JSON dump, llms.txt, and an MCP server. Built to be quoted by agents doing security-market research.