Latka logo

Top 1 Static Application Security Testing Software Companies With $5M–$10M Revenue (September 2026)

As of September 2026, Latka tracks 1 static application security testing software companies with $5M–$10M in annual revenue. They have combined revenues of $5.9M and employ 54 people.

Every company below sells static application security testing software to other businesses and is ranked by its most recent annual revenue. Revenue, funding, headcount and customer figures come from CEO interviews on the Latka podcast, public company filings, and Latka estimates where a company has not disclosed a number.

What Static Application Security Testing Software Companies do

Static Application Security Testing (SAST) software refers to tools and methodologies that analyze source code, bytecode, or binary code to identify security vulnerabilities within applications prior to deployment. This approach, often described as white-box testing, enables developers to detect and resolve potential security flaws early in the development lifecycle, thereby reducing the risk of vulnerabilities in production environments. The primary use cases of SAST software include scanning the source code for issues such as input validation errors, insecure coding practices, and dependencies that may pose security risks. Typical features of SAST tools encompass automated scanning, detailed reporting on vulnerabilities, integration with continuous integration/continuous deployment (CI/CD) pipelines, and support for various programming languages. The common buyer personas for SAST solutions typically include software developers, security teams, and DevOps engineers who seek to enhance application security while maintaining development efficiency.

Companies
1
Revenue
$5.9M
Funding
-
Employees
54

Filters

Sorting: Highest -> Lowest

Filters

Top Static Application Security Testing Software Companies With $5M–$10M Revenue

Showing 1 of 1 companies ranked by annual revenue.

1Security Journey logo
Security Journey

Pittsburgh, Pennsylvania, United States

Security Journey offers robust application security education tools to help developers and the entire SDLC team recognize and understand vulnerabilities and threats and proactively mitigate these risks. The knowledge learners acquire in our programs goes beyond helping learners code more securely – it turns everyone in the SDLC into security champions. Our platform takes a unique level approach, transitioning learners from security basics to language-specific knowledge to the experiential learning required to become security champions. With lessons offered in multiple formats, including text, video, and hands-on sandbox environments, there is a modality that resonates with every learning style. Organizations with teams of security champions develop a security-first mindset that allows them to deliver safer, more secure applications.

Revenue
$5.9M
Year founded
2016
Team size
54

Frequently asked questions about Static Application Security Testing Software Companies With $5M–$10M Revenue

How many static application security testing software companies with $5M–$10M in annual revenue are there?

Latka tracks 1 static application security testing software companies with $5M–$10M in annual revenue. Together they generate $5.9M in annual revenue and employ 54 people.

Which static application security testing software company with $5M–$10M in annual revenue is the largest?

Security Journey is the largest, with $5.9M in annual revenue, founded in 2016.

How much revenue does a typical static application security testing software company with $5M–$10M in annual revenue make?

The average static application security testing software company in this list makes $5.9M a year, across 1 companies with reported revenue.

Who are the leading Static Application Security Testing software vendors with $5M–$10M in annual revenue?

Ranked by annual revenue, the leaders are Security Journey.

Related Security Software categories

Inclusion Criteria

- Must offer automated scanning of source code, bytecode, or binaries for security vulnerabilities - Should provide detailed reporting on identified vulnerabilities and remediation guidance - Must integrate with CI/CD workflows to facilitate continuous security testing - Should support multiple programming languages and development frameworks - Not just focused on dynamic analysis; must also include static code analysis capabilities - Should offer features for prioritizing vulnerabilities based on severity