Latka logo

Top 5 Static Application Security Testing Software Companies With $10M–$100M Revenue (September 2026)

As of September 2026, Latka tracks 5 static application security testing software companies with $10M–$100M in annual revenue. They have combined revenues of $107.6M and employ 824 people. They have raised $25.3M.

Every company below sells static application security testing software to other businesses and is ranked by its most recent annual revenue. Revenue, funding, headcount and customer figures come from CEO interviews on the Latka podcast, public company filings, and Latka estimates where a company has not disclosed a number.

What Static Application Security Testing Software Companies do

Static Application Security Testing (SAST) software refers to tools and methodologies that analyze source code, bytecode, or binary code to identify security vulnerabilities within applications prior to deployment. This approach, often described as white-box testing, enables developers to detect and resolve potential security flaws early in the development lifecycle, thereby reducing the risk of vulnerabilities in production environments. The primary use cases of SAST software include scanning the source code for issues such as input validation errors, insecure coding practices, and dependencies that may pose security risks. Typical features of SAST tools encompass automated scanning, detailed reporting on vulnerabilities, integration with continuous integration/continuous deployment (CI/CD) pipelines, and support for various programming languages. The common buyer personas for SAST solutions typically include software developers, security teams, and DevOps engineers who seek to enhance application security while maintaining development efficiency.

Companies
5
Revenue
$107.6M
Funding
$25.3M
Employees
824

Filters

Sorting: Highest -> Lowest

Filters

Top Static Application Security Testing Software Companies With $10M–$100M Revenue

Showing 5 of 5 companies ranked by annual revenue.

1Semgrep logo
Semgrep

San Francisco, California, United States

Semgrep is an application security platform that scans code for bugs and security vulnerabilities, helping developers to write secure code.

Revenue
$33.6M
Year founded
2017
Team size
210
2Secure Code Warrior logo
Secure Code Warrior

Sydney, New South Wales, Australia

Secure Code Warrior is a secure coding platform that sets the standards that keep our digital world safe. We do this by providing the world’s leading agile learning platform that delivers the most effective secure coding solution for developers to learn, apply, and retain software security principles. More than 600 enterprises trust Secure Code Warrior to implement agile learning security programs and ensure the applications they release are free of vulnerabilities.

Revenue
$25.2M
Year founded
2015
Team size
229
3Bright Security logo
Bright Security

San Rafael, California, United States

Bright Security is an AI -powered application security platform that integrates application security into SDLC.

Revenue
$17.9M
Year founded
2018
Funding
$25.3M
Team size
104
4Guardsquare logo
Guardsquare

Leuven, Belgium

Guardsquare offers the most complete approach to mobile application security on the market. Built on the open source ProGuard technology, Guardsquare’s software integrates seamlessly across the development cycle. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. More than 975 customers worldwide across all major industries rely on Guardsquare to help them identify security risks and protect their mobile applications against reverse engineering and tampering.

Revenue
$17.3M
Year founded
2014
Team size
157
5Endor Labs logo
Endor Labs

Palo Alto, California, United States

80% of code in modern applications is code your developers didn’t write, but “borrowed” from the internet. With over 3M Open Source Software (OSS) projects, 43M versions, and 3.1T downloads yearly, development teams can gain tremendous benefits from leveraging the OSS ecosystem, as long as organizations invest in the tooling to address the security, scalability and sustainability challenges that come with it.  At Endor Labs, we've created the first open source dependency lifecycle management platform to help OSS consumers select, secure and maintain dependencies effectively.

Revenue
$13.6M
Year founded
2021
Team size
124

Frequently asked questions about Static Application Security Testing Software Companies With $10M–$100M Revenue

How many static application security testing software companies with $10M–$100M in annual revenue are there?

Latka tracks 5 static application security testing software companies with $10M–$100M in annual revenue. Together they generate $107.6M in annual revenue and employ 824 people.

Which static application security testing software company with $10M–$100M in annual revenue is the largest?

Semgrep is the largest, with $33.6M in annual revenue, founded in 2017.

How much revenue does a typical static application security testing software company with $10M–$100M in annual revenue make?

The average static application security testing software company in this list makes $21.5M a year, across 5 companies with reported revenue.

Who are the leading Static Application Security Testing software vendors with $10M–$100M in annual revenue?

Ranked by annual revenue, the leaders are Semgrep, Secure Code Warrior, Bright Security, Guardsquare and Endor Labs.

How much funding have static application security testing software companies with $10M–$100M in annual revenue raised?

The 5 static application security testing software companies with $10M–$100M in annual revenue tracked here have raised $25.3M in disclosed funding between them.

Related Security Software categories

Inclusion Criteria

- Must offer automated scanning of source code, bytecode, or binaries for security vulnerabilities - Should provide detailed reporting on identified vulnerabilities and remediation guidance - Must integrate with CI/CD workflows to facilitate continuous security testing - Should support multiple programming languages and development frameworks - Not just focused on dynamic analysis; must also include static code analysis capabilities - Should offer features for prioritizing vulnerabilities based on severity