Latka logo

Top 7 Static Application Security Testing Software Companies Under $1M Revenue (September 2026)

As of September 2026, Latka tracks 7 static application security testing software companies under $1M in annual revenue. They have combined revenues of $3M and employ 29 people. They have raised $36.5K.

Every company below sells static application security testing software to other businesses and is ranked by its most recent annual revenue. Revenue, funding, headcount and customer figures come from CEO interviews on the Latka podcast, public company filings, and Latka estimates where a company has not disclosed a number.

What Static Application Security Testing Software Companies do

Static Application Security Testing (SAST) software refers to tools and methodologies that analyze source code, bytecode, or binary code to identify security vulnerabilities within applications prior to deployment. This approach, often described as white-box testing, enables developers to detect and resolve potential security flaws early in the development lifecycle, thereby reducing the risk of vulnerabilities in production environments. The primary use cases of SAST software include scanning the source code for issues such as input validation errors, insecure coding practices, and dependencies that may pose security risks. Typical features of SAST tools encompass automated scanning, detailed reporting on vulnerabilities, integration with continuous integration/continuous deployment (CI/CD) pipelines, and support for various programming languages. The common buyer personas for SAST solutions typically include software developers, security teams, and DevOps engineers who seek to enhance application security while maintaining development efficiency.

Companies
7
Revenue
$3M
Funding
$36.5K
Employees
29

Filters

Sorting: Highest -> Lowest

Filters

Top Static Application Security Testing Software Companies Under $1M Revenue

Showing 7 of 7 companies ranked by annual revenue.

1CodeThreat logo
CodeThreat

Dover, Delaware, United States

CodeThreat is a security SAST solution. It uses scientifically proven techniques with approximation to analyze a codebase at rest, collects security related information, calculates data flows, searches for various well-known security weaknesses and as a result produce claims. These claims are usually whether the targeted codebase is vulnerable to scoped weaknesses or not.

Revenue
$770K
Year founded
2020
Team size
7
2Attify Inc. logo
Attify Inc.

India

Provider of mobile security services. The company provides mobile security services to enterprises and developers via application security auditing, code review and on-demand security scans.

Revenue
$673.6K
Year founded
2013
Team size
5
3Amplify Security logo
Amplify Security

San Jose, California, United States

Amplify Security has created a dual AI Agent platform that fixes insecure code before its deployed into production. This eliminates the work developers had to do around security. Now developers can focus on building products without slowing down for security issues or worse, causing a breach.

Revenue
$660K
Year founded
2022
Team size
6
4Corgea logo
Corgea

San Francisco, California, United States

Fix vulnerable code using AI

Revenue
$440K
Year founded
2023
Team size
4
5LunaSec logo
LunaSec

Seattle, Washington, United States

An Open Source dependency security tool that is smarter than the rest

Revenue
$330K
Year founded
2019
Team size
3
6Appsec360 logo
Appsec360

Melbourne, Victoria, Australia

Appsec360 is a cloud agnostic SaaS platform to build & run high performing application security programs

Revenue
$80.4K
Year founded
2020
Funding
$36.5K
Team size
3
7Secutils.dev logo
Secutils.dev

Germany

An open-source toolbox for application security engineers

Revenue
$1K
Year founded
2023
Team size
1

Frequently asked questions about Static Application Security Testing Software Companies Under $1M Revenue

How many static application security testing software companies under $1M in annual revenue are there?

Latka tracks 7 static application security testing software companies under $1M in annual revenue. Together they generate $3M in annual revenue and employ 29 people.

Which static application security testing software company under $1M in annual revenue is the largest?

CodeThreat is the largest, with $770K in annual revenue, founded in 2020.

How much revenue does a typical static application security testing software company under $1M in annual revenue make?

The average static application security testing software company in this list makes $422.2K a year, across 7 companies with reported revenue.

Who are the leading Static Application Security Testing software vendors under $1M in annual revenue?

Ranked by annual revenue, the leaders are CodeThreat, Attify Inc., Amplify Security, Corgea and LunaSec.

How much funding have static application security testing software companies under $1M in annual revenue raised?

The 7 static application security testing software companies under $1M in annual revenue tracked here have raised $36.5K in disclosed funding between them.

Related Security Software categories

Inclusion Criteria

- Must offer automated scanning of source code, bytecode, or binaries for security vulnerabilities - Should provide detailed reporting on identified vulnerabilities and remediation guidance - Must integrate with CI/CD workflows to facilitate continuous security testing - Should support multiple programming languages and development frameworks - Not just focused on dynamic analysis; must also include static code analysis capabilities - Should offer features for prioritizing vulnerabilities based on severity