Defectdojo
DefectDojo is an open-source DevSecOps platform that aggregates and prioritizes vulnerability findings from over 200 security tools, serving CISOs, AppSec leaders, security engineers, pen testers, and MSPs via a free open-source edition and a quote-based Pro Edition subscription.
- Company typePrivate
- Founded2017
- HeadquartersAustin, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Defectdojo does
DefectDojo is an Austin-based DevSecOps and vulnerability management platform company founded in 2017 by Greg Anderson. The company operates an open-source-first model, with its GitHub-hosted vulnerability management platform achieving over 38 million downloads and recognized as one of the most popular open-source security projects on GitHub. The platform aggregates, deduplicates, and prioritizes vulnerability findings from over 200 integrated security tools (including SAST, DAST, container, cloud, and SOC sources) into a single pane of glass, automating triage and reporting for security teams. DefectDojo serves CISOs, AppSec leaders, security engineers, pen testers, and MSPs across enterprise and mid-market segments, including multiple Fortune 50 clients.
The company generates revenue through a commercial Pro Edition subscription sold on a quote-based (not per-seat or per-app) license model, complemented by premium support and SLAs. Pro Edition adds an automation rules engine, tunable deduplication, background imports, CLI integrations, customizable dashboards, a cloud-hosted option, MFA, tenant isolation, and MCP integration for connecting to any LLM. In 2024-2025, DefectDojo extended its product surface with DefectDojo Sensei, an AI cybersecurity agent in alpha (GA targeted end of 2025) that leverages self-training evolution algorithms for risk prioritization and tool recommendations. DefectDojo raised a $7 million Series A in September 2024 led by Iolar Ventures and Aspenwood Ventures, and operates with 11-50 employees.
Defectdojo firmographics
Firmographics- Name
- Defectdojo
- Legal name
- DefectDojo, Inc.
- Website
- https://defectdojo.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- DefectDojo is an open-source DevSecOps platform that aggregates and prioritizes vulnerability findings from over 200 security tools, serving CISOs, AppSec leaders, security engineers, pen testers, and MSPs via a free open-source edition and a quote-based Pro Edition subscription.
- Ownership category
- akta.pro rank
Defectdojo industry classification
Industry- Product category
- Application Security Posture Management (ASPM) / Vulnerability Management
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industries
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI), Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
Keywords
Where Defectdojo is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Markets served
Defectdojo business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- DefectDojo Pro Edition Subscription: DefectDojo operates a freemium model with a free open-source tier and a commercial Pro Edition subscription. The Pro Edition includes enhanced features such as automation rules engine, tunable deduplication, background imports, CLI integrations, customizable dashboards, cloud-hosted option, MFA, premium support & SLAs, SOC & AppSec integration, MCP integration, and tenant isolation. Pricing is quote-based rather than per-seat or per-app.
- Open Source (Free Tier): The open-source edition provides core finding import, deduplication, authentication, RBAC, REST API, and basic dashboard/reporting at no cost. This serves as a user acquisition channel for Pro conversion.
- Professional Services / Support: Premium support and SLAs are included in the Pro Edition, representing a service component to the revenue model.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free Open-Source Edition |
| Subscription | Annual | Pro Edition |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
Defectdojo product offering
Product offeringCore offering
DefectDojo provides a vulnerability management and DevSecOps platform that aggregates, deduplicates, normalizes, and prioritizes security findings from over 200 security tools (SAST, DAST, container, cloud, SOC) into a unified view. It is offered as a free open-source edition and a commercial Pro Edition with advanced automation, customizable dashboards, MCP integration, and premium support, plus DefectDojo Sensei, an AI cybersecurity agent for risk prioritization and security insights.
Product overview
DefectDojo is a DevSecOps and vulnerability management platform offered as both an open-source free edition and a commercial Pro edition. The open-source platform provides core vulnerability management capabilities including import, deduplication, authentication, and basic reporting. The Pro edition builds on this with advanced automation, tunable deduplication, customizable dashboards, and premium features. The company also offers DefectDojo Sensei, an AI cybersecurity agent for automated risk prioritization and security insights. DefectDojo integrates with over 200 security tools and is designed for security teams of all sizes, from pen testers to CISOs.
Differentiator
Problem solved
Functional benefit
Brands
- DefectDojo Pro: The commercial Pro edition of the DefectDojo platform offering enhanced features including automation, tunable deduplication, CLI integrations, customizable dashboards, cloud-hosted options, MFA, premium support, SOC & AppSec integration, MCP integration, and tenant isolation.
- DefectDojo Sensei
Products and services
- DefectDojo Open Source Free open-source vulnerability management platform providing core finding import, deduplication, authentication (username, LDAP, SAML, OAuth), role-based access control, REST API and Swagger UI, manual import/reimport, and basic dashboard/reporting. Targeted at security teams, developers, and individual practitioners who want to self-host and consolidate vulnerability findings from multiple security tools.
- DefectDojo Pro Commercial subscription upgrade to the DefectDojo platform offering a rules engine automation, tunable deduplication, background imports, CLI integrations (Snyk, SonarQube, AWS, etc.), Universal Parser (CSV/JSON), customizable dashboards with dark mode, cloud-hosted option, MFA, premium support with SLAs, SOC and AppSec integration, MCP integration for LLM connectivity, and tenant isolation with encryption at rest. Sold via quote-based licensing to enterprise customers and security teams that need scalable, managed vulnerability management.
- DefectDojo Sensei AI cybersecurity agent that leverages self-training evolution algorithms to deliver advanced risk prioritization, tool recommendations, and security insights while keeping data within the DefectDojo environment. Targeted at security teams that want autonomous, AI-driven assistance in triaging and prioritizing vulnerabilities from multiple tools.
Quantifiable outcome
- 840% increase in testing throughput
- +3 more outcomes
Companies that use Defectdojo
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles4 records
Defectdojo technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration7 records
AI capability6 records
Feature9 records
Defectdojo partnerships and signals
Strategic signalScale indicators5 records
Recent moves5 records
Expansion highlights5 records
Defectdojo competitors and assessment
Company assessmentDirect peers
- Snyk: Developer security platform covering SAST, SCA, and container scanning. Directly comparable to DefectDojo in addressing application security and developer workflows, with overlapping integration ecosystems including SonarQube and AWS.
- Sonar (SonarQube): Code quality and security platform whose findings DefectDojo imports via CLI integration. Highly comparable as both target security engineers and AppSec leaders, often deployed together in enterprise AppSec stacks.
- Cycode: ASPM platform focused on software supply chain security and vulnerability aggregation across SDLC stages. Directly comparable to DefectDojo's positioning as a vulnerability aggregation layer with strong enterprise focus.
- ArmorCode: ASPM platform providing unified vulnerability management, risk prioritization, and remediation workflows. Closely comparable product surface to DefectDojo Pro, targeting similar CISO and AppSec buyer personas.
- Invicti (formerly Netsparker): Application security testing platform combining DAST and IAST with vulnerability management workflows. Overlaps with DefectDojo's pen tester and AppSec leader segments and integrates with similar scanner ecosystems.
Broad incumbents
- Tenable: Large incumbent in vulnerability management with Nessus and Tenable One ASPM platform. Overlaps significantly with DefectDojo's vulnerability aggregation and risk prioritization capabilities but serves a broader enterprise portfolio including cloud and OT security.
- Qualys: Cloud-native vulnerability management and security platform with VMDR and ASPM offerings. Competes in the same enterprise vulnerability aggregation category as DefectDojo Pro, with broader asset discovery and compliance coverage.
- Rapid7: Security analytics and vulnerability management platform including InsightVM and InsightAppSec. Competes with DefectDojo on enterprise vulnerability prioritization and AppSec visibility, with deeper SIEM/SOAR adjacencies.
Emerging players
- Wiz: Cloud security platform rapidly expanding into ASPM. While cloud-first rather than open-source, Wiz's full-stack security vision and massive funding base position it as a key competitor for enterprise ASPM budgets that DefectDojo targets.
- HackerOne: Vulnerability disclosure and bug bounty platform whose findings flow into vulnerability management programs. Adjacent but increasingly competing for the AppSec program budget that DefectDojo targets through its HackerOne integrations.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Defectdojo social profiles
Digital presenceDefectdojo compliance and trust
Trust signalCompliance3 records
Defectdojo financial estimates
Financial estimateRevenue estimate
Valuation estimate
Defectdojo leadership team
Management profileNumber of profiles
Profiles1 record
Defectdojo funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Defectdojo M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Defectdojo
What does Defectdojo do?
DefectDojo provides a vulnerability management and DevSecOps platform that aggregates, deduplicates, normalizes, and prioritizes security findings from over 200 security tools (SAST, DAST, container, cloud, SOC) into a unified view. It is offered as a free open-source edition and a commercial Pro Edition with advanced automation, customizable dashboards, MCP integration, and premium support, plus DefectDojo Sensei, an AI cybersecurity agent for risk prioritization and security insights.
Is Defectdojo a public or private company?
Defectdojo is a private company. It is classified as venture growth investor backed and is currently operating.
When was Defectdojo founded?
Defectdojo was founded in 2017. It employs 11 to 50 people.
Where is Defectdojo based?
Defectdojo is headquartered in Austin, United States, in the North America region.
How does Defectdojo make money?
Three revenue lines are on record. DefectDojo Pro Edition Subscription is the primary driver. The others are open Source (Free Tier) and professional Services / Support.
Who are Defectdojo's main competitors?
Direct peers on record are Snyk, Sonar (SonarQube), Cycode, ArmorCode and Invicti (formerly Netsparker). Broad incumbents are Tenable, Qualys and Rapid7. Emerging players are Wiz and HackerOne.
Does Defectdojo have an API?
Yes. DefectDojo offers a REST API with Swagger UI for automation and integration purposes. The API supports features like importing vulnerability findings, creating Jira tickets, and automating security workflows. MCP (Model Context Protocol) integration is available in the Pro edition to connect any LLM. Developer documentation is at defectdojo.com/docs.
What industry is Defectdojo in?
Defectdojo's product category is Application Security Posture Management (ASPM) / Vulnerability Management. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 5415 and its SIC code is 7370.