Maze
- Company typePrivate
- Founded2024
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
Maze firmographics
Firmographics- Name
- Maze
- Legal name
- Maze AI Limited
- Website
- https://mazehq.com
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
Maze industry classification
Industry- Product category
- Cloud Security / AI Vulnerability Management
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
- akta.pro secondary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
Keywords
Where Maze is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Maze business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Cloud-Infrastructure-Sized Subscription: Maze sells B2B SaaS subscriptions to enterprise security teams. Pricing is quote-based and tied to the size of the customer's cloud infrastructure; the company states it is "unlikely to be the most expensive tool in your stack." Both Maze Cloud and Maze Code can be bought separately, with the combined deployment offering additional value through unified context.
- Usage/Scaled Pricing Component: Pricing scales with the size of the customer's cloud infrastructure and the volume of vulnerabilities/agents investigated, functioning as a usage-based dimension layered on top of the subscription.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Annual | Quote-based enterprise subscription, priced on cloud infrastructure size |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels10 records
Maze product offering
Product offeringCore offering
Maze is an AI-native security platform that deploys AI agents to investigate every vulnerability across customer code, cloud, and runtime environments, prove exploitability, and route verified fixes to the responsible developer. The platform is sold as Maze Cloud (container and VM CVE triage) and Maze Code (AI-SCA dependency and AI-SAST custom code analysis) modules that share a unified code-and-cloud context, delivered as multi-tenant or single-tenant SaaS on AWS to enterprise security and platform engineering teams.
Product overview
Maze is an AI-native security platform delivered as a single core platform (Maze Platform) with two interoperable modules — Maze Cloud and Maze Code — designed to share a unified context model. Maze Cloud investigates and fixes vulnerabilities across cloud and container environments (ingesting findings from existing scanners), while Maze Code combines AI-SCA (dependencies) and AI-SAST (first-party code) to investigate vulnerabilities in source code and third-party libraries. Together, the modules deduplicate findings across code and cloud, and share context so a finding in one informs the other. Underlying the platform are AI agents for investigation, exploitability reasoning, prioritization, remediation (including code-fix generation and routing), and asset ownership determination.
Differentiator
Problem solved
Functional benefit
Brands
- Maze Cloud: Cloud-vulnerability product line of the Maze platform that investigates and triages CVEs in containers and VMs.
- Maze Code
- the Exploit
Products and services
- Maze Platform The unified AI-native security platform that hosts Maze's investigation, prioritisation, remediation, and ownership agents across both code and cloud environments. It assembles context from code, runtime, cloud, and controls, trains agents on millions of real investigations, validates outputs through multiple layers, and balances frontier-model usage with cost-efficient techniques for scale. It is sold to enterprise security and platform engineering teams.
- Maze Cloud The cloud-vulnerability module of the Maze platform that ingests findings from existing scanners, deduplicates them across assets, deploys AI agents to investigate exploitability in containers and VMs, catches zero-days before scanners, and routes verified fixes or mitigations to the owning developer. Designed for enterprise security teams responsible for cloud and container vulnerability management.
- Maze Code The code-security module of the Maze platform that combines AI-SCA (vulnerability investigation in third-party dependencies) and AI-SAST (first-party code analysis that surfaces novel and business-logic flaws). It runs in CI/CD pipelines and routes verified fixes into coding agents like Claude, Cursor, and Windsurf. Can be purchased standalone or combined with Maze Cloud for richer cross-context investigations.
Quantifiable outcome
- 90% of vulnerabilities analyzed are not exploitable when investigated by Maze
- +5 more outcomes
Companies that use Maze
Customer profileNamed customers6 records
Segments4 records
Ideal customer profiles2 records
Maze technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability9 records
Feature11 records
Maze partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core infrastructure provider, core developer-tooling integration, secondary developer-tooling integration, core ci/cd integration, broad integration ecosystem and strategic expansion partnership (counterparties not named in source).
- AWS Bedrockcore infrastructure providerMaze uses AWS Bedrock as an LLM orchestrator guaranteeing customer data is not shared with model providers for training. Maze is also cloud-hosted in AWS, with multi-tenant or single-tenant options.
- Google Vertex AIcore infrastructure providerMaze uses Google Vertex AI as an LLM orchestrator that guarantees customer data is not shared with the model provider for training.
- Claude (Anthropic)core developer-tooling integrationMaze routes verified fixes and surfaces findings directly inside Claude (coding agent). Maze's research also uses Claude internally to build PoC scanners and reasoning tools (e.g., 79-gadget CVE-2026-25632 research).
- Cursorcore developer-tooling integrationMaze Code integrates with the Cursor coding agent to deliver AI-flagged findings and verified fixes in real time during development.
- Windsurfsecondary developer-tooling integrationMaze Code integrates with the Windsurf coding agent to surface findings and fixes to developers in their existing coding environment.
- GitHub Actionscore ci/cd integrationMaze Code runs in the GitHub Actions CI/CD pipeline and surfaces findings directly at the pull request, including blocking merges on confirmed critical/high vulnerabilities.
- GitLab CIcore ci/cd integrationMaze Code integrates with GitLab CI to surface findings and fixes inside the pipeline.
- CircleCIcore ci/cd integrationMaze Code integrates with CircleCI to surface findings and fixes inside the CI pipeline.
- Third-Party Vulnerability Scanners (ecosystem)broad integration ecosystemMaze ingests and deduplicates findings from customers' existing vulnerability scanners and builds new integrations on request. Maze Code can also operate as the scanner itself.
- Unnamed Japan/Global Counterparties (Tripartite MOU)strategic expansion partnership (counterparties not named in source)In April 2026, Maze signed a tripartite MOU for offline AI solution expansion in Japan and globally as part of its business development activities. Counterparty names were not disclosed in the source.
Scale indicators7 records
Recent moves7 records
Expansion highlights7 records
Maze competitors and assessment
Company assessmentEmerging players
- Arnica: Arnica is an emerging AI-native application security platform offering code scanning, secrets detection, and software supply-chain security. It is an emerging player with meaningful overlap with Maze Code's developer-focused AI security positioning.
Direct peers
- Wiz: Wiz is a leading cloud security platform covering CSPM, CWPP, vulnerability management, and CIEM across AWS/Azure/GCP. It is the most direct competitor to Maze Cloud for cloud-vulnerability triage at Fortune 100 scale.
- Snyk: Snyk is a developer security platform offering SCA, SAST, container, and IaC scanning. It is the most direct competitor to Maze Code (AI-SCA + AI-SAST) and overlaps on dependency and custom-code vulnerability management for enterprise engineering teams.
- Aqua Security: Aqua Security provides cloud-native application protection including container vulnerability scanning and runtime protection. It overlaps with Maze Cloud on container/CVE triage and remediation for enterprise platform teams.
- Semgrep: Semgrep is a code security platform combining open-source and managed SAST/SCA with developer workflow integration. It is the closest open-code-scanning peer to Maze Code's AI-SAST module and competes for engineering-team budgets.
- Orca Security: Orca Security is an agentless cloud security platform that ingests cloud configuration and workload data to prioritize vulnerabilities and misconfigurations. It competes directly with Maze's agentless, sensorless cloud-investigation approach.
Broad incumbents
- Veracode: Veracode is a long-standing enterprise application security vendor offering SAST, SCA, and DAST at scale. It is a broad incumbent that Maze Code competes against in enterprise AppSec procurement.
- Checkmarx: Checkmarx is an enterprise application security platform spanning SAST, SCA, IaC, and API security. It is a broad incumbent that competes with both Maze Code (SAST/SCA) and adjacent cloud-security offerings.
- Palo Alto Prisma Cloud: Prisma Cloud is Palo Alto Networks' broad CNAPP offering CSPM, CWPP, CIEM, and code security. It is a broad incumbent that competes with the unified Maze Platform across cloud and code.
- Tenable: Tenable is a broad vulnerability-management incumbent spanning cloud, infrastructure, and application security. It is an incumbent competitor to Maze's enterprise vulnerability-management positioning at Fortune 100 scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Maze social profiles
Digital presenceMaze compliance and trust
Trust signalCompliance2 records
Maze financial estimates
Financial estimateRevenue estimate
Valuation estimate
Maze leadership team
Management profileNumber of profiles
Profiles5 records
Maze funding detail
Funding detailFunding overview
Funding rounds3 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Maze M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Maze
What does Maze do?
Maze is an AI-native security platform that deploys AI agents to investigate every vulnerability across customer code, cloud, and runtime environments, prove exploitability, and route verified fixes to the responsible developer. The platform is sold as Maze Cloud (container and VM CVE triage) and Maze Code (AI-SCA dependency and AI-SAST custom code analysis) modules that share a unified code-and-cloud context, delivered as multi-tenant or single-tenant SaaS on AWS to enterprise security and platform engineering teams.
Is Maze a public or private company?
Maze is a private company. It is classified as venture growth investor backed and is currently operating.
When was Maze founded?
Maze was founded in 2024. It employs 11 to 50 people.
Where is Maze based?
Maze is headquartered in London, United Kingdom, in the Europe region.
How does Maze make money?
Two revenue lines are on record. Cloud-Infrastructure-Sized Subscription is the primary driver. The others are usage/Scaled Pricing Component.
Who are Maze's main competitors?
Arnica is listed as an emerging player. Direct peers are Wiz, Snyk, Aqua Security, Semgrep and Orca Security. Broad incumbents are Veracode, Checkmarx, Palo Alto Prisma Cloud and Tenable.
Does Maze have an API?
No public API is recorded for Maze.
What industry is Maze in?
Maze's product category is Cloud Security / AI Vulnerability Management. Its primary akta.pro industry code is HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation), with a secondary code of HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII). Its NAICS code is 54151 and its SIC code is 7371.