Mend.io
Mend.io is an Israel-based enterprise software company providing a unified application security and AI security platform combining SAST, SCA, container scanning, and AI-specific security capabilities (AI-BOM, system prompt hardening, red teaming) for large enterprises developing traditional and AI-powered applications.
- Company typePrivate
- Founded2011
- HeadquartersBoston, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Mend.io does
Mend.io (legally White Source Ltd.) is a unified application security and AI security platform company founded in 2011 and headquartered in Israel, with U.S. operations based in Boston. The company serves enterprise software development organizations through two primary product pillars: Mend AppSec, which integrates SAST, SCA, container scanning, and dependency management under shared policy and remediation workflows, and Mend AI, which secures AI models, agents, system prompts, and AI-generated code through discovery, AI-BOM generation, system prompt hardening, and automated red teaming. The platform is differentiated by a proprietary reachability analysis engine that claims to eliminate up to 95% of false positives, AI-powered code fixes claimed at 46% higher accuracy than competitors, and 10x faster SAST scanning.
The company generates revenue through enterprise SaaS subscriptions with quote-based pricing, selling primarily to large enterprises via direct field sales with quote-based contracts, dedicated customer success teams, and defined SLAs. Pricing is structured in tiers including Mend AI Core, Mend AI Premium, Mend AppSec, and Mend Renovate Enterprise, with annual billing cadence. The customer base includes named enterprises such as Microsoft, Google, Yahoo, Vodafone, Siemens, Seagate, Ping Identity, WTW, Vonage, Texthelp, FINOS, Trimble, WorkVision, Sportradar, and GPI across technology, telecommunications, insurance, and education verticals. Go-to-market combines direct enterprise sales with a channel partner program that is actively being expanded under CMO Stephanie Broyles, and ecosystem partnerships with Docker (Hardened Images integration), Invicti (DAST/API security), and HeroDevs (EOL support).
Mend.io is led by co-founder and CEO Azi Cohen following a February 2026 leadership restructuring that transitioned former CEO Rami Sass to General Manager of Mend AI. The company has raised approximately $121M across five funding rounds, with the most recent being a $75M Series C in April 2021 led by Pitango VC with participation from 83North, M12 (Microsoft's venture fund), and Susquehanna Growth Equity. Recent growth metrics include a 20% year-over-year revenue increase and 25% expansion in new customer logos.
Mend.io firmographics
Firmographics- Name
- Mend.io
- Legal name
- White Source Ltd.
- Website
- https://mend.io
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Mend.io is an Israel-based enterprise software company providing a unified application security and AI security platform combining SAST, SCA, container scanning, and AI-specific security capabilities (AI-BOM, system prompt hardening, red teaming) for large enterprises developing traditional and AI-powered applications.
- Ownership category
- akta.pro rank
Mend.io industry classification
Industry- Product category
- Application Security Software
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industries
- Prompt Security & Injection Defense (HDAAAKAE), AI Application Enablement Platforms (Copilot/Agent Frameworks, SDKs) (HDAEANAJ)
Keywords
Where Mend.io is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Mend.io business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription: Enterprise software delivered as a subscription service with platform tiers including Mend AI Core, Mend AI Premium, Mend AppSec, and Mend Renovate Enterprise. Pricing is quote-based with dedicated customer success and engineering support with defined SLAs for enterprise customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise SaaS subscription with quote-based pricing |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Mend.io product offering
Product offeringCore offering
Mend.io provides a unified application security and AI security platform that combines SAST, SCA, DAST, container security, and AI-specific capabilities including system prompt hardening, automated AI red teaming, and AI-BOM generation. The platform is delivered as enterprise SaaS with deep integrations into IDEs, repositories, and CI/CD pipelines, supporting customers from 100 to 100,000+ repositories.
Product overview
Mend.io is a unified application security and AI security platform consisting of two primary pillars: Mend AI (AI Application Lifecycle Security) and Mend AppSec (Native AppSec Platform), supplemented by Mend Renovate Enterprise for dependency automation. Mend AppSec unifies SAST, SCA, container scanning, and dependency management under shared policy, prioritization, and remediation workflows. Mend AI secures AI models, agents, system prompts, and AI-generated code through discovery, risk assessment, red teaming, and runtime guardrails. Additional capabilities span DAST and API Security (via Invicti partnership), EOL Support (via HeroDevs partnership), SBOM/AI-BOM management, Docker Hardened Images integration, and compliance tooling mapped to EU AI Act, NIST, ISO 42001, and other frameworks. The platform supports SaaS, hybrid, and on-premises deployments.
Differentiator
Problem solved
Functional benefit
Brands
- Mend AI: AI security platform for securing AI models, prompts, and agents in applications
- Mend AppSec
- Mend Renovate
- Mend SCA
- Mend SAST
Products and services
- Mend AI Full lifecycle AI security platform for securing AI models and agents in codebases. It automates discovery, risk assessment, system prompt hardening, automated red teaming, AI-BOM generation, and policy enforcement across the AI software development lifecycle, targeting organizations building AI-powered applications.
- Mend AppSec Unified application security platform combining SAST, SCA, container scanning, dependency management, and AI visibility in a single product. It provides shared policy, prioritization, and remediation workflows across the full SDLC for enterprise security teams.
- Mend SCA Software composition analysis tool that identifies, prioritizes, and remediates security and license risks in open source components using reachability analysis, CVSS 4.0 and EPSS prioritization, SBOM generation, and automated policy enforcement. Sold as part of Mend AppSec.
- Mend SAST Static application security testing tool scanning source code (human-written and AI-generated) for vulnerabilities and hardcoded secrets directly in repositories and IDEs. Delivers scans up to 10x faster than traditional SAST tools with AI-powered fixes. Sold as part of Mend AppSec.
- Mend Renovate Enterprise Enterprise-grade automated dependency update platform that detects outdated dependencies across all projects and delivers updates as pull requests, with Merge Confidence ratings, CI gate integration, and auto-merge capabilities. Reduces security risk from outdated dependencies by up to 70%.
- DAST (Dynamic Application Security Testing) Dynamic application security testing solution provided through an Invicti partnership that extends Mend's AppSec platform coverage into runtime. Simulates real-world attacks on running applications and APIs to identify exploitable runtime vulnerabilities.
- API Security API security solution provided through an Invicti partnership covering REST, SOAP, and GraphQL APIs with built-in security checks, shadow API discovery, and API definition import capabilities.
- EOL Support End-of-life software support provided through a HeroDevs partnership, offering drop-in replacement packages for deprecated open source frameworks with SLAs and ongoing CVE remediation, ensuring compliance with PCI DSS, HIPAA, FedRAMP, and GDPR.
Quantifiable outcome
- Up to 95% reduction in false positives through reachability analysis
- +5 more outcomes
Companies that use Mend.io
Customer profileNamed customers15 records
Segments4 records
Ideal customer profiles3 records
Mend.io technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability13 records
Feature11 records
Mend.io partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Docker Hardened ImagescoreIntegration brings Docker's VEX (Vulnerability Exploitability eXchange) intelligence directly into Mend.io's application security platform. The integration automatically deprioritizes non-exploitable CVEs using DHI's VEX data combined with Mend.io's reachability analysis, enabling one-click SBOM exports for compliance with frameworks like SSDF and FedRAMP.
- HeroDevscorePartnership to provide drop-in replacements for deprecated open source packages. HeroDevs' Never-Ending Support extends Mend.io's EOL Support offering, backed by SLAs and ongoing CVE remediation for packages no longer maintained by original developers.
- InvicticoreMend.io and Invicti partnership extends AppSec coverage from code to runtime. Invicti provides DAST and API security capabilities that complement Mend.io's SAST and SCA, enabling comprehensive security across the application development lifecycle.
Scale indicators14 records
Recent moves6 records
Expansion highlights6 records
Mend.io competitors and assessment
Company assessmentDirect peers
- Checkmarx: Checkmarx is a long-established AppSec platform specializing in SAST, SCA, and IaC security for enterprise customers. It is a direct competitor to Mend SAST and Mend SCA in the same enterprise buyer accounts and is frequently named alongside Mend in SAST evaluations.
- Snyk: Snyk is a developer security platform offering SAST, SCA, container security, and IaC scanning — directly competing with Mend AppSec's core capabilities. Snyk is a leading peer because it serves the same enterprise developer audience with a similar product breadth and has overlapping reachability and AI-fix features.
- JFrog Xray: JFrog Xray is a software composition analysis and container security product, bundled with JFrog Artifactory for DevOps-centric supply chain security. It is a direct peer on SCA and container security where Mend AppSec and Mend SCA also compete.
- Sonar (SonarSource): Sonar provides code quality and security analysis (SAST) integrated into developer workflows with SonarQube and SonarCloud products. It is a direct competitor to Mend SAST and is increasingly overlapping on security testing for AI-generated code.
- Veracode: Veracode is an enterprise application security platform offering SAST, SCA, and DAST as a managed service — a directly comparable enterprise AppSec peer to Mend AppSec. Veracode is among the most established incumbents Mend competes against in regulated industries.
Broad incumbents
- Wiz: Wiz is a leading cloud security platform that has been expanding into application and code security (including code-to-cloud pipelines and AI workload security). It is a broad incumbent that competes for the same enterprise security budget and increasingly overlaps with Mend's code and AI security positioning.
- GitHub Advanced Security: GitHub Advanced Security is Microsoft's bundled code-scanning, secret-scanning, and dependency-graph security offering built into the GitHub platform. It is a broad incumbent that overlaps significantly with Mend's capabilities but is distributed as part of GitHub Enterprise rather than as a standalone platform.
Emerging players
- Apiiro: Apiiro is a code risk platform that uses code analysis to prioritize application and supply chain risks, with growing AI security capabilities. It is an emerging peer with overlapping reachability and risk-prioritization concepts that compete for the same AppSec buyer.
- Anchore: Anchore is a container security and software supply chain compliance platform with SBOM generation capabilities. It is an emerging player that overlaps with Mend's container security (post-Atom Security acquisition) and SBOM offerings, particularly in regulated industries.
- Cycode: Cycode is an application security posture management (ASPM) platform that aggregates SAST, SCA, secrets, and IaC scanning findings. It is an emerging player that overlaps with Mend's unified AppSec positioning but is earlier-stage and narrower in scope.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Mend.io social profiles
Digital presenceMend.io compliance and trust
Trust signalCompliance3 records
Mend.io financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mend.io leadership team
Management profileNumber of profiles
Profiles14 records
Mend.io subsidiaries and ownership
Company hierarchySubsidiaries1 record
Mend.io funding detail
Funding detailFunding overview
Funding rounds5 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mend.io M&A and investment
M&A and investmentM&A3 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mend.io
What does Mend.io do?
Mend.io provides a unified application security and AI security platform that combines SAST, SCA, DAST, container security, and AI-specific capabilities including system prompt hardening, automated AI red teaming, and AI-BOM generation. The platform is delivered as enterprise SaaS with deep integrations into IDEs, repositories, and CI/CD pipelines, supporting customers from 100 to 100,000+ repositories.
Is Mend.io a public or private company?
Mend.io is a private company. It is classified as venture growth investor backed and is currently operating.
When was Mend.io founded?
Mend.io was founded in 2011. It employs 251 to 500 people.
Where is Mend.io based?
Mend.io is headquartered in Boston, United States, in the North America region.
How does Mend.io make money?
One revenue line is on record: saaS Subscription.
Who are Mend.io's main competitors?
Direct peers on record are Checkmarx, Snyk, JFrog Xray, Sonar (SonarSource) and Veracode. Broad incumbents are Wiz and GitHub Advanced Security. Emerging players are Apiiro, Anchore and Cycode.
Does Mend.io have an API?
No public API is recorded for Mend.io.
What industry is Mend.io in?
Mend.io's product category is Application Security Software. Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of HDAAAKAE, Prompt Security & Injection Defense. Its NAICS code is 54151 and its SIC code is 7370.