Codacy
Codacy is a cloud-native SaaS platform providing automated code quality, application security testing, and AI code governance across 49 programming languages, serving 15,000+ organizations and 200,000+ developers globally via a per-user subscription model targeting mid-market and enterprise engineering teams.
- Company typePrivate
- Founded2012
- HeadquartersLisbon, Portugal
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Codacy does
Codacy is a cloud-native SaaS platform headquartered in Lisbon, Portugal (legal entity Qamine Portugal S.A.) that provides automated code quality analysis, application security testing, and AI code governance for engineering organizations. Founded in 2012 by Jaime Jorge (CEO) and João Caxaria (CTO), the company serves over 15,000 organizations and 200,000 developers worldwide with a platform that supports 49 programming languages and integrates natively with GitHub, GitLab, Bitbucket, VS Code, IntelliJ, Cursor, and major AI coding agents via Git webhook — scans run in Codacy's cloud, requiring no CI/CD pipeline configuration. The platform spans three core modules (Quality, Security, Coverage) and four AI-native modules (AI Guardrails, AI Reviewer, AI Risk Hub, AI Inventory), addressing both traditional code quality and the emerging governance needs of AI-assisted software development.
Codacy's product portfolio consolidates SAST, SCA, secrets detection, IaC scanning, DAST, container scanning, code coverage enforcement, and AI policy management into a single managed platform. AI Guardrails runs inside AI coding agents (GitHub Copilot, Claude, Gemini) and IDEs to scan every line of AI-generated code against organizational policies before developers see it. AI Reviewer produces ready-to-commit fix suggestions and PR summaries using a hybrid of deterministic static analysis and OpenAI-powered language models. The platform is SOC 2 Type 2 certified, GDPR compliant, and generates audit-ready evidence for SOC 2, ISO 27001, ISO 42001, PCI DSS, HIPAA, HITRUST CSF, EU AI Act, and DORA.
Codacy operates a hybrid go-to-market combining product-led growth (free 14-day trial, free open-source tier, $18/developer/month per-seat pricing) with enterprise direct sales (one-month Proof of Value programs targeting VPs of Engineering, CTOs, and Heads of Platform at mid-market and enterprise organizations). Primary customer segments include AI-forward engineering teams managing AI-generated code volume, mid-market and enterprise software teams with 50–5,000 developers, regulated industries requiring continuous audit evidence, and organizations consolidating multiple point tools. Notable customers include NASA, Zalando, Delivery Hero, MPL, O.C. Tanner, Vevo, Green Flag, LSports, LOGEX, and historical customers PayPal, Adobe, Qlik, Deliveroo, and Cancer Research UK; the company reports that 80% of its customers migrated from SonarQube. Total funding raised is approximately $29.9 million across six rounds, with the most recent being a $15.4 million Series B in September 2022 led by Bright Pixel Capital.
Codacy firmographics
Firmographics- Name
- Codacy
- Legal name
- Qamine Portugal S.A.
- Website
- https://codacy.com
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Codacy is a cloud-native SaaS platform providing automated code quality, application security testing, and AI code governance across 49 programming languages, serving 15,000+ organizations and 200,000+ developers globally via a per-user subscription model targeting mid-market and enterprise engineering teams.
- Ownership category
- akta.pro rank
Codacy industry classification
Industry- Product category
- Code Quality & Application Security Platform
- NAICS
- Software Publishers (513210), Software Publishers (51321), Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industries
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Audit, Explainability & Accountability Tooling (traceability, reporting) (HDAAAKAL), AI Governance, Risk & Compliance (GRC) Platforms (HDAAAMAA)
Keywords
Where Codacy is headquartered
LocationHeadquarters
- HQ city
- Lisbon
- HQ country
- Portugal
- HQ region
- Europe
Offices1 record
Markets served
Codacy business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription: Per-user SaaS subscription model with unlimited lines of code and unlimited scans on every plan. Includes free trial period and open-source free tier. Enterprise pricing available with POV programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier for open-source projects |
| Per seat | Monthly | Per-user pricing starting at $18/developer/month |
| Subscription | Annual | Annual subscription with billing cadence |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels7 records
Codacy product offering
Product offeringCore offering
Codacy sells a unified cloud-native SaaS platform that performs automated code quality analysis, application security testing (SAST, SCA, secrets detection, IaC scanning, DAST), and code coverage tracking across 49 programming languages, delivered via one-click Git webhook integration. The platform also offers a set of AI code governance products (AI Guardrails, AI Reviewer, AI Risk Hub, AI Inventory) that scan AI-generated code in real time inside IDEs and AI coding agents, and generate audit-ready compliance evidence for SOC 2, ISO 27001, PCI DSS, HIPAA, EU AI Act, and other frameworks.
Product overview
Codacy is a unified SaaS platform for code quality, application security, and AI code governance. The platform is organized into seven product areas sold and used as a single integrated platform: Quality (automated code quality analysis across 49 languages), Security (SAST, SCA, secrets, IaC, DAST, container scanning), Coverage (code coverage tracking with merge gates), AI Guardrails (real-time scanning in AI agents and IDEs), AI Reviewer (AI-powered PR review), AI Risk Hub (centralized AI coding policies), and AI Inventory (AI usage discovery across codebases). The platform also includes Codacy AI for automated issue descriptions and recommendations powered by OpenAI. Codacy operates via one-click Git webhook integration with no CI/CD pipeline configuration required, scans run in Codacy's cloud infrastructure.
Differentiator
Problem solved
Functional benefit
Products and services
- Quality Automated code quality analysis across 49 programming languages. Detects error-prone patterns, code complexity, duplications, and best-practice violations. Includes configurable coding standards enforced at the pull request level across all repositories, designed for engineering organizations that want consistent standards at scale.
- Security Application security suite covering SAST (Static Application Security Testing), hardcoded secrets detection, Software Composition Analysis (SCA) with daily CVE database updates, Infrastructure-as-Code (IaC) scanning, malware detection in dependencies, license scanning, DAST (Dynamic Application Security Testing), and integrated penetration testing through partners. For security and engineering leaders in regulated industries.
- Coverage Code coverage tracking with configurable merge gates that enforce unit test coverage on critical code paths. Designed to ensure AI coding agents have the test context they need to fill coverage gaps reliably.
- AI Guardrails Real-time scanning layer that runs inside AI coding agents and IDEs. Silently scans every line of AI-generated code against the organization's policies while it is being generated, and lets the agent auto-fix issues before the developer sees the code. Available in VS Code, IntelliJ, Cursor, and via MCP for GitHub Copilot, Claude, and Gemini. For AI-forward engineering teams.
- AI Reviewer Hybrid AI-powered Pull Request reviewer combining deterministic static analysis with LLM-based context understanding. Produces ready-to-commit fix suggestions, PR summaries, and automated false-positive detection so reviews stay low-noise even as PR volume scales.
- AI Risk Hub Centralized place to define and enforce AI coding policies across the organization. Catches AI-specific risks like unapproved AI model calls, invisible prompt injections, and vulnerable libraries inherited from outdated training data.
- AI Inventory Discovers and inventories AI usage across an organization's codebase — config files (such as .cursorrules, .mcp.json), dependency manifests, commit metadata from AI tools, environment variables, and API endpoints. Designed for engineering and security leaders who need a real-time picture of where AI is being used in their software.
- Codacy AI Optional AI features integrated into the platform that optimize development workflows and elevate code quality standards through automated issue descriptions, actionable recommendations, and false-positive detection. Powered by OpenAI's text generation models. Customer code is not used to train AI models.
Quantifiable outcome
- Unit test coverage increased from 7% to 70% across 800+ repositories
- +5 more outcomes
Companies that use Codacy
Customer profileNamed customers10 records
Segments4 records
Ideal customer profiles4 records
Codacy technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability6 records
Feature7 records
Codacy partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered core and minor.
- GitHubcoreNative Git integration via one-click webhook with no CI/CD pipeline configuration required. GitHub Advanced Security competitor. IDE integration via MCP server.
- GitLabcoreNative Git integration via webhook. Supports both GitLab Cloud and GitLab self-managed deployments.
- BitbucketcoreNative Git integration via webhook supporting both Bitbucket Cloud and Bitbucket Data Center.
- OpenAIcoreCodacy AI leverages OpenAI's text generation models for AI-powered code review features, including issue descriptions and fix suggestions.
- BulletproofminorPartner for penetration testing services integrated into Codacy's security capabilities. Priced separately.
- Visual Studio CodecoreIDE plugin available on VS Code Marketplace for local scanning and AI Guardrails.
- IntelliJ IDEAcoreIDE plugin available on JetBrains Marketplace for local scanning and AI Guardrails across JetBrains family.
- CursorcoreIDE plugin for AI-first code editor with Codacy Guardrails for real-time scanning.
- JiracoreNative bidirectional Jira integration for ticket creation and remediation tracking of security issues.
- SlackcoreNative Slack alerts for critical security issues and notification workflows.
- Claude (Anthropic)coreAI agent integration via Codacy MCP server for context-aware code analysis and AI Guardrails.
- Gemini (Google)coreAI agent integration via Codacy MCP server for context-aware code analysis and AI Guardrails.
- GitHub CopilotcoreAI coding agent integration via Codacy MCP server for AI Guardrails and real-time code scanning.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Codacy competitors and assessment
Company assessmentMarket position
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Codacy social profiles
Digital presenceCodacy compliance and trust
Trust signalCompliance8 records
Codacy financial estimates
Financial estimateRevenue estimate
Valuation estimate
Codacy leadership team
Management profileNumber of profiles
Profiles8 records
Codacy funding detail
Funding detailFunding overview
Funding rounds5 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Codacy M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Codacy
What does Codacy do?
Codacy sells a unified cloud-native SaaS platform that performs automated code quality analysis, application security testing (SAST, SCA, secrets detection, IaC scanning, DAST), and code coverage tracking across 49 programming languages, delivered via one-click Git webhook integration. The platform also offers a set of AI code governance products (AI Guardrails, AI Reviewer, AI Risk Hub, AI Inventory) that scan AI-generated code in real time inside IDEs and AI coding agents, and generate audit-ready compliance evidence for SOC 2, ISO 27001, PCI DSS, HIPAA, EU AI Act, and other frameworks.
Is Codacy a public or private company?
Codacy is a private company. It is classified as venture growth investor backed and is currently operating.
When was Codacy founded?
Codacy was founded in 2012. It employs 51 to 100 people.
Where is Codacy based?
Codacy is headquartered in Lisbon, Portugal, in the Europe region.
How does Codacy make money?
One revenue line is on record: saaS Subscription.
Does Codacy have an API?
Yes. Codacy provides an API for integrating with its code quality and security platform. The API allows programmatic access to repository analysis, issues, coverage data, and pull request information. Documentation is available at docs.codacy.com. Codacy also offers an MCP (Model Context Protocol) server that allows MCP-compatible agents like GitHub Copilot, Claude, and Gemini to read and act on Codacy scan results. Developer documentation is at docs.codacy.com.
What industry is Codacy in?
Codacy's product category is Code Quality & Application Security Platform. Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies). Its NAICS code is 513210 and its SIC code is 7372.