StackHawk
StackHawk is a Denver-based application and API security testing company whose DAST platform integrates into AI coding agents (Claude Code, Cursor, Copilot, Codex) and CI/CD pipelines to find, fix, and verify exploitable vulnerabilities before code is committed. It serves developers and enterprise security/AppSec teams via a $10/user/month self-serve tier and custom-priced enterprise contracts.
- Company typePrivate
- Founded2019
- HeadquartersDenver, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What StackHawk does
StackHawk, Inc. is a Denver-based application and API security testing company founded in 2019 that has built a Dynamic Application Security Testing (DAST) platform positioned for AI-accelerated software development. The platform combines three integrated pillars: (1) API Discovery from source code repositories (GitHub, GitLab, Bitbucket) to map the application and API attack surface; (2) HawkScan, a runtime security testing engine that runs inside CI/CD pipelines and AI coding agent loops (Claude Code, Cursor, GitHub Copilot, Codex, Antigravity) to surface exploitable vulnerabilities, generate fixes, and verify them before code is committed; and (3) Oversight, a program-level dashboard for security leaders tracking coverage, fix rates, and risk posture. Specialized capabilities include Business Logic Testing for BOLA/BFLA authorization flaws, LLM Security Testing for OWASP LLM Top 10 risks, and HawkScan for MCP server testing. The company is led by co-founders Joni Klippert (CEO) and Scott Gerlach (CSO), with Joe Sullivan (former CSO at Meta, Uber, Cloudflare) on the board since March 2026.
The company operates a hybrid go-to-market model. A self-serve product-led growth tier called Wingman is priced at $10 per user per month with a 14-day free trial, targeting individual developers and small teams using AI coding agents. An enterprise tier called Scale is sold via direct field sales at custom pricing based on team size, targeting security and AppSec teams at larger organizations and including attack surface discovery, sensitive data detection, program reporting, SSO, and unlimited scanning. In February 2026, StackHawk launched the SHARP channel partner program with security-focused VARs (Defy, GuidePoint, Myriad360, Optiv, Trace3, WWT) offering 30%+ margins. Total funding raised is $47.3 million across rounds in 2019, 2020, 2022, and 2025, led by Sapphire Ventures and Costanoa Ventures. The customer base spans financial services, healthcare, transportation, media, and technology, with named enterprise logos including Fortis (Fortune 100), British Airways, ITV, Hagerty, and Change.org. StackHawk maintains SOC 2 Type II certification and is G2-rated 4.6/5.0 with 68 reviews.
StackHawk firmographics
Firmographics- Name
- StackHawk
- Legal name
- StackHawk, Inc.
- Website
- https://stackhawk.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- StackHawk is a Denver-based application and API security testing company whose DAST platform integrates into AI coding agents (Claude Code, Cursor, Copilot, Codex) and CI/CD pipelines to find, fix, and verify exploitable vulnerabilities before code is committed. It serves developers and enterprise security/AppSec teams via a $10/user/month self-serve tier and custom-priced enterprise contracts.
- Ownership category
- akta.pro rank
StackHawk industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industry
- Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where StackHawk is headquartered
LocationHeadquarters
- HQ city
- Denver
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
StackHawk business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- Wingman Subscription: Per-user monthly subscription at $10/user/month for individuals and teams using AI coding agents. Includes unlimited apps, 50 scans/user/month, and core security testing capabilities. Billed monthly or annually.
- Scale Enterprise Subscription: Team-based unlimited subscription with unlimited apps and unlimited agentic scans. Includes attack surface discovery, sensitive data detection, program reporting, and enterprise support. Priced based on team size rather than usage.
- Usage-based Scanning: Wingman plan includes 50 scans/user/month. Additional scans can be purchased when limit is reached, or users can upgrade to Scale for unlimited scanning capacity.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Wingman - $10/user/month for individual developers and teams |
| Subscription | Multi-year contract | Scale - Contact sales for enterprise pricing |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels7 records
StackHawk product offering
Product offeringCore offering
StackHawk is an AI Coding Agent Security Platform that performs dynamic application security testing (DAST) of running applications and APIs. It integrates directly into CI/CD pipelines and AI coding agent workflows (Claude Code, Cursor, GitHub Copilot, Codex, Antigravity) to discover APIs from source code, run runtime security scans that surface exploitable vulnerabilities, and verify fixes before code is committed.
Product overview
StackHawk is an AI Coding Agent Security Platform organized as a unified platform with modular products. The core consists of three integrated pillars: (1) API Discovery — discovers application and API attack surface from source code repositories (GitHub, GitLab, Bitbucket); (2) HawkScan — the primary runtime security testing engine that runs within CI/CD pipelines and AI coding agent loops (Claude Code, Cursor, Codex, Antigravity, GitHub Copilot); and (3) Oversight — program-level intelligence tracking coverage, risk prioritization, and compliance posture. These are delivered across two product tiers: Wingman ($10/user/month) for developers and teams using AI coding agents, and StackHawk Scale for enterprise security teams covering the full organization. The platform is extended by specialized solutions including API Security Testing, gRPC Security Testing, GraphQL Security Testing, Remote MCP Server Security Testing (HawkScan for MCP), LLM Security Testing, Sensitive Data Identification, and Business Logic Testing (BLT). All capabilities are grounded in a DAST-first approach with YAML config-as-code, deterministic reproducible scan results, and developer-native remediation workflows that surface findings in PRs, Slack, and Jira.
Differentiator
Problem solved
Functional benefit
Products and services
- StackHawk AI Coding Agent Security Platform Unified AppSec Intelligence Platform combining attack surface discovery from source code, shift-left runtime testing (DAST), and program-level oversight. It integrates into AI coding agent loops to test running apps, surface exploitable vulnerabilities, and fix them before code is committed. Targeted at enterprise AppSec teams and developer organizations.
- HawkScan The primary runtime security testing engine. Runs security tests against running applications post-commit and pre-PR, identifying, remediating, and verifying exploitable vulnerabilities. Implemented as an agent skill for AI coding agents and as a CLI/Docker scanner for CI/CD pipelines.
- API Discovery Discovers the complete application attack surface directly from source code repositories by connecting to GitHub, GitLab, or Bitbucket to identify APIs, applications, and testable attack surface including REST, GraphQL, gRPC, WebSocket endpoints, and serverless functions. Continuously updates with every commit and surfaces sensitive data (PII, PCI, HIPAA) and change velocity insights.
- Oversight Program-level application security intelligence and oversight. Tracks testing coverage and risk in real time, prioritizes applications based on sensitive data and change velocity, monitors vulnerability lifecycle from detection to remediation, and provides dashboards for executives showing testing coverage, findings, and risk posture trends.
- HawkScan for MCP Automated runtime security testing tool specifically for Model Context Protocol (MCP) servers. Detects injection attacks, SSRF, broken authentication, and data exposure in MCP servers. Integrated into CI/CD pipelines for continuous validation as code and AI models evolve.
- Business Logic Testing (BLT) Automated multi-user authorization testing to find BOLA (Broken Object Level Authorization) and BFLA (Broken Function Level Authorization) vulnerabilities that traditional DAST tools miss. Uses context-aware test orchestration with Smart Crawl to automatically generate test sequences from OpenAPI specs. Supports multi-user role profiles (admin, standard member, guest) to simulate realistic authorization scenarios.
- Sensitive Data Identification Analyzes source code to discover which APIs handle sensitive data (PII, PCI, PHI) before deployment. Enables risk-based prioritization, focusing testing on APIs carrying the most compliance risk. Achieves 55% more applications under test through intelligent prioritization.
- LLM Security Testing Runtime security testing for LLM-integrated applications covering OWASP LLM Top 10 vulnerabilities: prompt injection, sensitive data disclosure, improper output handling, system prompt leakage, and unbounded consumption. Built into runtime testing with no additional configuration required when applications have LLM integrations.
- API Security Testing Automated API security testing for REST, GraphQL, gRPC, SOAP, and WebSocket endpoints integrated into CI/CD pipelines. Tests for injection attacks, broken authentication, data exposure, and authorization flaws. Includes CI/CD integrations with GitHub, automated OpenAPI spec generation, and developer-native remediation workflows.
- Modern DAST Dynamic Application Security Testing (DAST) solution built for modern development workflows. Runs in CI/CD pipelines on incremental code changes, finding exploitable vulnerabilities before production. Designed for APIs, microservices, and AI interfaces with YAML config-as-code. Differentiates from legacy DAST through pre-production testing, fast scan times, and business logic coverage.
Quantifiable outcome
- 55% more applications under test through intelligent prioritization
- +3 more outcomes
Companies that use StackHawk
Customer profileNamed customers15 records
Segments4 records
Ideal customer profiles3 records
StackHawk technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability7 records
Feature9 records
StackHawk partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core and minor.
- DefycoreChannel partner in SHARP (StackHawk Alliances & Resellers Program) offering security-focused reselling with 30%+ guaranteed margins and exclusive NFR licenses.
- GuidePointcoreChannel partner in SHARP (StackHawk Alliances & Resellers Program) offering security-focused reselling with 30%+ guaranteed margins and exclusive NFR licenses.
- Myriad360coreChannel partner in SHARP (StackHawk Alliances & Resellers Program) offering security-focused reselling with 30%+ guaranteed margins and exclusive NFR licenses.
- OptivcoreChannel partner in SHARP (StackHawk Alliances & Resellers Program) offering security-focused reselling with 30%+ guaranteed margins and exclusive NFR licenses.
- Trace3coreChannel partner in SHARP (StackHawk Alliances & Resellers Program) offering security-focused reselling with 30%+ guaranteed margins and exclusive NFR licenses.
- WWT (World Wide Technology)coreChannel partner in SHARP (StackHawk Alliances & Resellers Program) offering security-focused reselling with 30%+ guaranteed margins and exclusive NFR licenses.
- Joe SullivanminorFormer CSO at Meta, Uber, and Cloudflare joined StackHawk board of directors to help security teams keep pace with AI. Brings expertise from leading security at major tech companies.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
StackHawk competitors and assessment
Company assessmentDirect peers
- Snyk: Snyk is a developer security platform that bundles SAST, SCA, container, and IaC scanning, with growing DAST/API testing capabilities that overlap directly with StackHawk's runtime application security testing. Both target developer-led AppSec adoption inside CI/CD pipelines.
- Veracode: Veracode is an established application security vendor offering SAST, DAST, SCA, and API testing through a unified platform. It is a direct DAST competitor to StackHawk, particularly in the regulated enterprise segment where Veracode has deep installed base.
- Invicti (Netsparker & Acunetix): Invicti operates the Netsparker and Acunetix DAST brands, competing head-to-head with StackHawk in modern web app and API runtime scanning. Both target enterprise security teams seeking automated, low-false-positive DAST with CI/CD integration.
- PortSwigger (Burp Suite): PortSwigger's Burp Suite is the dominant commercial DAST/proxy tool used by security testers and penetration testers for web app and API testing. It overlaps with StackHawk's runtime testing capabilities but is more manual/tester-driven rather than CI/CD-automated.
- Detectify: Detectify offers crowdsourced DAST and attack surface monitoring aimed at modern web applications and APIs. It is a comparable DAST-first vendor targeting AppSec teams with continuous, automated testing, similar to StackHawk's positioning.
Broad incumbents
- GitHub Advanced Security: GitHub Advanced Security bundles Code Scanning (CodeQL), secret scanning, and Dependabot, and increasingly integrates DAST capabilities inside the GitHub platform. As the dominant developer platform, it represents both an integration partner and a competitive threat to StackHawk's CI/CD-native testing.
- Rapid7 InsightAppSec: Rapid7's InsightAppSec provides dynamic application security testing as part of its broader InsightConnect security platform. It competes with StackHawk in the enterprise segment where buyers want to consolidate AppSec with vulnerability management and SIEM.
- Akamai App & API Protector: Akamai's App & API Protector combines WAF runtime protection with API discovery and security testing capabilities delivered via its edge platform. As a broad cloud and security incumbent, Akamai overlaps with StackHawk's API security and runtime testing for enterprise buyers.
- Noname Security (now Akamai): Noname Security, acquired by Akamai, focuses on API posture management and runtime API security testing. It overlaps with StackHawk's API Security Testing and Sensitive Data Identification capabilities for enterprise API environments.
Emerging players
- Apiiro: Apiiro is an application security posture management (ASPM) platform with code-to-runtime risk analysis. It complements some of StackHawk's source-code-driven discovery and risk prioritization capabilities and competes for AppSec program oversight budgets.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
StackHawk social profiles
Digital presenceStackHawk compliance and trust
Trust signalCompliance2 records
StackHawk financial estimates
Financial estimateRevenue estimate
Valuation estimate
StackHawk leadership team
Management profileNumber of profiles
Profiles11 records
StackHawk funding detail
Funding detailFunding overview
Funding rounds5 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
StackHawk M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about StackHawk
What does StackHawk do?
StackHawk is an AI Coding Agent Security Platform that performs dynamic application security testing (DAST) of running applications and APIs. It integrates directly into CI/CD pipelines and AI coding agent workflows (Claude Code, Cursor, GitHub Copilot, Codex, Antigravity) to discover APIs from source code, run runtime security scans that surface exploitable vulnerabilities, and verify fixes before code is committed.
Is StackHawk a public or private company?
StackHawk is a private company. It is classified as venture growth investor backed and is currently operating.
When was StackHawk founded?
StackHawk was founded in 2019. It employs 11 to 50 people.
Where is StackHawk based?
StackHawk is headquartered in Denver, United States, in the North America region.
How does StackHawk make money?
Three revenue lines are on record. Wingman Subscription is the primary driver. The others are scale Enterprise Subscription and usage-based Scanning.
Who are StackHawk's main competitors?
Direct peers on record are Snyk, Veracode, Invicti (Netsparker & Acunetix), PortSwigger (Burp Suite) and Detectify. Broad incumbents are GitHub Advanced Security, Rapid7 InsightAppSec, Akamai App & API Protector and Noname Security (now Akamai). Apiiro is listed as an emerging player.
Does StackHawk have an API?
Yes. StackHawk offers an API skill that allows AI coding agents to communicate with the StackHawk platform to optimize how applications are tested and triaged, configure security tooling, manage scan history, and track findings and risk. The HawkScan MCP server integration enables GitHub Copilot to auto-discover StackHawk skills from repositories and wire directly into Copilot for scan-fix-rescan workflows within developer environments. The platform also generates OpenAPI specifications automatically from source code, bridging discovered APIs to configured DAST scans. Developer documentation is at docs.stackhawk.com/ai-security.
What industry is StackHawk in?
StackHawk's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAKAHAJ, Application Security & DevSecOps Services. Its NAICS code is 5415 and its SIC code is 7372.