Latka logo

Top 34 Software Supply Chain Security Tools Software SaaS Companies in May 2026

As of May 2026, there are 34 SaaS companies in Software Supply Chain Security Tools Software. They have combined revenues of $598.4M and employ 2.6K people. They have raised $1.8B and serve 6K customers combined.

Software Supply Chain Security Tools Software encompasses solutions designed to secure and manage the software supply chain throughout its lifecycle. These tools are primarily focused on identifying, monitoring, and mitigating risks associated with software components, whether they are proprietary or open-source. They allow organizations to maintain the integrity of their software by detecting vulnerabilities and ensuring compliance with security standards. Typical features of these tools include Software Composition Analysis (SCA), Software Bill of Materials (SBOM) generation, container security measures, and automated security testing. Users of these tools often include application security teams, DevOps professionals, and compliance officers who need robust solutions to safeguard their development processes and production environments from potential threats and vulnerabilities in the software supply chain.

Companies
34
Revenue
$598.4M
Funding
$1.8B
Employees
2.6K

Filters

Sorting: Highest -> Lowest

Filters

Top Software Supply Chain Security Tools Software Companies

Showing 10 of 15 companies ranked by annual revenue.

1
socket.dev

United States

Socket is a cybersecurity platform that protects companies from software supply chain attacks. Companies use Socket to protect their software applications and critical services from malware and security threats originating in open source code.

Revenue
$4.2M
Customers
-
Year founded
2020
Funding
-
Team size
38
Growth
-
2
DeepFactor

San Jose, California, United States

DeepFactor enables developers to ship secure code without sacrificing productivity by observing application telemetry events.

Revenue
$3.9M
Customers
-
Year founded
2019
Funding
$15M
Team size
39
Growth
22.67%
3
DefectDojo

Austin, Texas, United States

DefectDojo is the engine that powers DevSecOps, offering an open, scalable platform that connects security strategy to implementation. It helps security professionals eliminate repetitive tasks and integrates with over 180 security tools.

Revenue
$3.9M
Customers
-
Year founded
2017
Funding
-
Team size
22
Growth
-
4
StackHawk

Denver, Colorado, United States

Developer of a security platform designed for DevOps teams. The company's platform is security software which continuously scans and documents vulnerabilities, enabling engineers to find and remediate security problems in development and production.

Revenue
$3.8M
Customers
-
Year founded
2019
Funding
-
Team size
56
Growth
28.76%
5
Software House Access Control + Event Management

United States

Software House solutions include the innovative C•CURE 9000 security and event management system access control solution, and a wide-range of complementary hardware products. Through its access control software and hardware lines, Software House provides customers with complete, real-time control over their security systems whether large or small. Front and center in the access control portfolio, the scalable C•CURE 9000 security management platform allows users to meet security needs from entry to enterprise level. Installations range from simple door controls to enterprise integrations with thousands of doors spanning many geographical areas around the world. Software House continues to offer complete solutions, providing products that increase efficiency and fit any budget while maintaining the same high standards for performance and quality. Today, Software House operates as part of Johnson Controls, a world leader in smart buildings, creating safe, healthy and sustainable spaces. With a global team of 100,000 experts in more than 150 countries, Johnson Controls offers the world's largest portfolio of building technology and software as well as service solutions from some of the most trusted names in the industry.

Revenue
$3.4M
Customers
-
Year founded
-
Funding
-
Team size
31
Growth
-
6
Scribe - E2E Software Supply Chain Security

United States

Scribe is a holistic software supply chain platform for managing SDLC risk and securing your software factory and products from development to deployment. We implement zero trust, continuous assurance, attestation concepts, and SDLC-guardrails-as-code to enhance products’ security and trustworthiness while reducing friction with development teams and speeding up your time to market. • DISCOVER all software assets, lineage and risk posture and gain complete visibility to your AppSec risk by applying BI & AI to an evidence-based SSC-inclusive repository • MITIGATE preemptively SSC risks in your software factory and artifacts by auto-enforcement of SSC policy (SDLC guardrails) • PREVENT software tampering attacks by automating continuous code signing and Intoto attestations. • DEMONSTRATE compliance adherence with SSC frameworks (e.g. SLSA) and regulations (e.g. SSDF) by automatically generating and collecting signed evidence from CI/CD pipelines.

Revenue
$3.4M
Customers
-
Year founded
-
Funding
-
Team size
31
Growth
-
7
Blue Cedar

San Francisco, California, United States

Developer of a cloud-based application security platform intended to offer mobile application security services. The company's platform injects security directly into the applications, eliminating the need for container applications, agents and standalone security applications that can hinder productivity and compromise privacy, enabling developers to make applications easy to use, managable and available on any device.

Revenue
$3.1M
Customers
-
Year founded
2016
Funding
$27M
Team size
38
Growth
75.45%
8
Software Secured

Ottawa, Ontario, Canada

Developer of network security technology intended to integrate security earlier into software development lifecycle. The company's platform helps to bridge the gap between development teams and security by integrating open source security tools into SDLC, enabling organization's software development teams to identify vulnerabilities faster in their code, which reduces the cost of finding and fixing bugs.

Revenue
$2.9M
Customers
-
Year founded
2010
Funding
-
Team size
18
Growth
46.35%
9
Kondukto

United States

Kondukto is an AppSec orchestration and posture management platform that helps AppSec teams achieve instant visibility into the overall security posture by integrating all security data into one crystal clear view. It also enables faster triage and remediation of vulnerabilities with its orchestration, automation and vulnerability management capabilities.

Revenue
$2.1M
Customers
-
Year founded
2019
Funding
-
Team size
19
Growth
-
10
SOOS

Winooski, Vermont, United States

SOOS is the affordable, easy-to-integrate Software Composition Analysis and Dynamic Application Security Testing solution for your whole team. Scan your open source software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license-types, generate SBOMs, and fill out your compliance worksheets with confidence–all for one low monthly price.

Revenue
$2M
Customers
-
Year founded
2019
Funding
-
Team size
18
Growth
-

Inclusion Criteria

- Must provide features for identifying and managing risks in the software supply chain. - Must support Software Composition Analysis (SCA) to identify vulnerabilities in third-party libraries and components. - Should include capabilities for generating Software Bills of Materials (SBOM) to maintain an inventory of all components used in software. - Must facilitate compliance with security standards and best practices in software development. - Not just focused on vulnerability scanning; must also offer integration with CI/CD pipelines for real-time security management. - Should enable continuous monitoring of software dependencies for emerging threats. - Must provide actionable insights and remediation guidance for identified vulnerabilities.