Ox Security
OX Security sells a unified application security platform covering code, build, and runtime to enterprise security and DevSecOps teams. Founded in 2021 in Tel Aviv, it uses proprietary Code Projection technology and a per-developer SaaS subscription model.
- Company typePrivate
- Founded2021
- HeadquartersTel Aviv, Israel
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Ox Security does
OX Security is a Tel Aviv-headquartered application security company founded in 2021 that sells a unified "Code-to-Cloud" platform to enterprise security and DevSecOps teams. The platform aggregates and correlates findings across SAST, SCA, DAST, IaC, CI/CD pipelines, container security, API security, and cloud runtime environments through a proprietary Code Projection technology that maps static findings to runtime reachability and exploitability, and through PBOM (Pipeline Bill of Materials), an open standard that extends SBOM to track pipeline provenance and build artifacts from commit to production. The product portfolio comprises four core modules—OX VibeSec (AI-native security guardrails embedded in AI coding assistants and IDEs), OX Code (SAST, SCA, secrets, IaC, container, CI/CD posture), OX Cloud (CSPM, KSPM, runtime security, drift detection), and OX Agentic Pentester (autonomous AI-driven penetration testing)—supported by AI-Powered Fixes for inline remediation, ASPM orchestration, API Exposure Management, compliance automation across 35+ frameworks, and IDE extensions for VS Code and JetBrains.
The company monetizes via per-developer SaaS subscription with a single unified license covering all capabilities, sold through direct enterprise field sales targeting CISOs and AppSec leaders, complemented by a freemium self-serve entry tier. Named customers span financial services (eToro, SoFi, AuditBoard), technology (IBM, Intel, Microsoft, 6sense, DoubleVerify), telecommunications (Swisscom), retail (Petco), hospitality (IHG), manufacturing (Bosch), gaming (888 Holdings), and video streaming (Kaltura), with strategic investors including Microsoft, IBM Ventures, Swisscom Ventures, Evolution Equity Partners, Team8, DTCP, and M12. As of the May 2025 Series B announcement, OX Security had reached $10 million in annual recurring revenue and tripled its customer base since the 2022 stealth exit; in June 2026 the company was named a Leader in Gartner's inaugural Magic Quadrant for Software Supply Chain Security.
Ox Security firmographics
Firmographics- Name
- Ox Security
- Legal name
- OX Security
- Website
- https://ox.security
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- OX Security sells a unified application security platform covering code, build, and runtime to enterprise security and DevSecOps teams. Founded in 2021 in Tel Aviv, it uses proprietary Code Projection technology and a per-developer SaaS subscription model.
- Ownership category
- akta.pro rank
Ox Security industry classification
Industry- Product category
- Application Security Posture Management (ASPM)
- NAICS
- Software Publishers (5132)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industry
- Prompt Security & Injection Defense (HDAAAKAE)
Keywords
Where Ox Security is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices2 records
Markets served
Ox Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Enterprise SaaS Subscription (Per Developer): OX Security operates a subscription-based SaaS model priced per developer seat with full support. The platform is sold as a unified license covering all capabilities (OX Code, OX Cloud, VibeSec, Agentic Pentester). Target buyers are enterprise security and DevOps teams, with pricing based on developer count.
- Free Tier / Self-Serve Onboarding: Platform offers a free entry tier allowing developers to start independently, supporting product-led growth motion that converts to paid seats.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Unified platform subscription priced per developer with full support coverage |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels9 records
Ox Security product offering
Product offeringCore offering
OX Security sells a unified, subscription-based application security platform that connects AI-driven code generation to runtime cloud environments. Its core capabilities include SAST, SCA, secrets/PII detection, IaC scanning, CI/CD posture management, container security, cloud runtime security (CSPM/KSPM), AI code generation guardrails, and autonomous penetration testing — all consolidated under a single per-developer license and correlated through proprietary Code Projection Technology.
Product overview
OX Security offers a unified platform-plus-modules architecture called the OX Platform, which secures applications from code to runtime. The core product portfolio consists of four integrated modules: OX VibeSec (AI code security preventing vulnerabilities at AI generation), OX Code (code-layer security covering SAST, SCA, secrets, and CI/CD), OX Cloud (cloud runtime security including CSPM and Kubernetes security), and OX Agentic Pentester (autonomous penetration testing). These are powered by AI capabilities including generative AI for AI coding guardrails, autonomous agents for continuous testing and remediation, and intelligent prioritization using Code Projection Technology. Supporting capabilities include AI-Powered Fixes for automated remediation, PBOM/SBOM for supply chain visibility, API Exposure Management, Compliance automation, and an IDE Extension for VS Code. The platform is priced per developer with full platform access.
Differentiator
Problem solved
Functional benefit
Brands
- VibeSec: AI-powered security platform that embeds security context directly into AI code editors to prevent vulnerabilities in AI-generated code from the first line.
- OX Code
- OX Cloud
- OX Agentic Pentester
- Active ASPM
Products and services
- OX Security Platform Enterprise-grade unified application security platform securing applications from AI code generation to runtime. Connects SAST, SCA, DAST, container security, and cloud security into a single correlated view, sold under a single per-developer license.
- OX VibeSec AI-powered security layer that embeds real-time, context-aware security guardrails directly into AI code editors and coding assistants (Cursor, Windsurf, GitHub Copilot, Claude AI, OpenAI). Prevents vulnerabilities at the point of AI code generation, claiming to reduce newly created production issues by up to 90%.
- OX Code Comprehensive code security module covering SAST, SCA, secrets/PII detection, IaC scanning, CI/CD security, and container security. Uses Code Projection Technology to correlate findings with runtime context, exploitability, and business impact for prioritized remediation.
- OX Cloud Cloud runtime security module providing CSPM, Kubernetes Security Posture Management (KSPM), Cloud Bill of Materials (CBOM), Infrastructure as Code scanning, API exposure analysis, attack path mapping, drift detection, and runtime security monitoring.
- OX Agentic Pentester AI-powered continuous penetration testing tool that validates real-world exploitability and traces vulnerabilities directly to source code. Autonomous AI agents simulate hacker behavior for continuous attack surface assessment with white-box visibility.
- AI-Powered Fixes / Agent OX AI-powered remediation capability delivering context-aware code fixes directly in developer workflows. Analyzes organizational-specific codebase to generate tailored fixes delivered as one-click remediations inline in PRs, IDEs, or CI/CD pipelines.
- Application Security Posture Management (Active ASPM) Active ASPM offering that unifies security signals from all sources, provides real-world risk scoring based on reachability, exploitability, and impact, automated remediation workflows, and developer language integrations.
- Software Supply Chain Security Comprehensive supply chain security covering PBOM (Pipeline Bill of Materials), SCA/SBOM, CI/CD posture security, continuous posture monitoring, and AI supply chain governance.
- API Exposure Management Automated API discovery, inventory, and vulnerability mapping. Detects shadow APIs, analyzes API exposure, and provides API BOM for comprehensive API security governance.
- Compliance Management Compliance automation and reporting aligned with CIS, NIST, PCI DSS, SOC 2, GDPR, and 35+ frameworks. Provides continuous compliance monitoring, automated evidence collection, and audit-ready reporting.
- IDE Extension (VS Code) Visual Studio Code extension enabling real-time vulnerability scanning, secrets detection, and misconfiguration identification directly within the developer environment. Available on the VS Code Marketplace.
Quantifiable outcome
- Reduces critical security findings by 95% (Swisscom: from baseline to zero critical vulnerabilities across 1,000 repositories)
- +6 more outcomes
Companies that use Ox Security
Customer profileNamed customers13 records
Segments4 records
Ideal customer profiles3 records
Ox Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration26 records
AI capability10 records
Feature8 records
Ox Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- AnthropiccoreOX Security joined Anthropic's Cyber Verification Program in June 2026, following OX's discovery of critical vulnerabilities in Anthropic's Model Context Protocol (MCP). The program validates OX Security's platform for securing AI-generated code and AI supply chains.
- CommitminorCommit, a software development company, partnered with OX Security and TWINGO to co-host an invite-only event at Ramat Hakovesh Winery focused on secure development in the AI era. Part of OX Security's thought leadership and ecosystem relationship-building.
- TWINGOminorTWINGO co-hosted an invite-only event with OX Security and Commit focused on secure development in the AI era, reflecting ongoing thought leadership and ecosystem relationship-building.
- TenablecoreOX Security announced a new integration with Tenable linking cloud security findings directly to code, build pipelines, and developers to enhance risk remediation across multi-cloud environments. Findings are delivered through developer workflow tools like Jira, GitHub Issues, and Slack. This integration connects Tenable's cloud risk detection with OX's application context and exploitability analysis.
Scale indicators12 records
Recent moves6 records
Expansion highlights6 records
Ox Security competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first security platform offering SAST, SCA, IaC, and container security with per-developer pricing and PLG motion. Direct competitor across OX's SAST/SCA/Code modules and comparable per-developer enterprise SaaS model.
- Checkmarx: Enterprise application security testing platform covering SAST, SCA, IaC, and API security. Direct peer in AppSec testing; OX's OX Code and OX VibeSec compete against Checkmarx's code security portfolio (Checkmarx also acquired Cycode, an ASPM/supply-chain peer).
- Veracode: Established enterprise AppSec platform for SAST, DAST, and SCA. Direct competitor in application security testing for large enterprises, with broader install base but overlapping product surface against OX Code and OX Cloud.
- Apiiro: Code-to-cloud application security platform emphasizing risk prioritization and code-to-runtime correlation — the same architectural philosophy OX markets via Code Projection. Acquired by Palo Alto Networks, increasing competitive pressure from a well-capitalized incumbent.
- Cycode: Application Security Posture Management (ASPM) and software supply chain security platform, directly overlapping OX's ASPM, PBOM, and Code-to-Cloud positioning. Now part of Checkmarx, making it a key head-to-head competitor in ASPM.
- ArmorCode: Application Security Posture Management (ASPM) vendor that aggregates and prioritizes findings across SAST, SCA, DAST, IaC, and container scanners — a near-overlapping value proposition with OX's ASPM and AppSec Data Fabric.
- Sonatype: Software supply chain security and SCA platform (Nexus/Repository + Lifecycle), directly overlapping OX's software supply chain, SBOM/PBOM, and dependency vulnerability modules for regulated enterprises.
- Mend (formerly WhiteSource): SCA and software supply chain security vendor focused on open-source dependency risk, SBOM, and license compliance. Direct competitor for OX's SCA, SBOM/PBOM, and dependency vulnerability use cases.
Broad incumbents
- GitHub Advanced Security: GitHub-native code security covering SAST, SCA, and secret scanning bundled into GitHub Enterprise. A broad incumbent dev-platform play competing with OX across SAST/SCA, with native distribution advantages inside GitHub repositories — and OX integrates tightly with it as well.
- JFrog: Binary/artifact management platform with JFrog Xray for software supply chain security and SCA. Broad incumbent in the artifact-level supply chain category OX also targets, with enterprise reach and Artifactory integration.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Ox Security social profiles
Digital presenceOx Security compliance and trust
Trust signalCompliance3 records
Ox Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Ox Security leadership team
Management profileNumber of profiles
Profiles8 records
Ox Security funding detail
Funding detailFunding overview
Funding rounds4 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Ox Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Ox Security
What does Ox Security do?
OX Security sells a unified, subscription-based application security platform that connects AI-driven code generation to runtime cloud environments. Its core capabilities include SAST, SCA, secrets/PII detection, IaC scanning, CI/CD posture management, container security, cloud runtime security (CSPM/KSPM), AI code generation guardrails, and autonomous penetration testing — all consolidated under a single per-developer license and correlated through proprietary Code Projection Technology.
Is Ox Security a public or private company?
Ox Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Ox Security founded?
Ox Security was founded in 2021. It employs 101 to 250 people.
Where is Ox Security based?
Ox Security is headquartered in Tel Aviv, Israel, in the Middle East region.
How does Ox Security make money?
Two revenue lines are on record. Enterprise SaaS Subscription (Per Developer) is the primary driver. The others are free Tier / Self-Serve Onboarding.
Who are Ox Security's main competitors?
Direct peers on record are Snyk, Checkmarx, Veracode, Apiiro, Cycode, ArmorCode, Sonatype and Mend (formerly WhiteSource). Broad incumbents are GitHub Advanced Security and JFrog.
Does Ox Security have an API?
Yes. OX Security offers a GraphQL API for integration and automation purposes. The API allows users to ingest third-party scan results, manage organizations, trigger posture scans, and automate security workflows. Authentication is via API key (created under Settings → API Keys with API Integration scope). The API endpoint is https://api.ox.security/graphql. The platform also supports webhooks and workflow integrations for automated ticket creation and remediation handoffs. Developer documentation is at docs.ox.security.
What industry is Ox Security in?
Ox Security's product category is Application Security Posture Management (ASPM). Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDAAAKAE, Prompt Security & Injection Defense. Its NAICS code is 5132 and its SIC code is 7371.