DryRun Security
DryRun Security is an Austin-based AI-native code security intelligence platform that uses contextual analysis and specialized agents to detect exploitable vulnerabilities, enforce natural-language policies, and integrate directly into GitHub, GitLab, and AI coding tool workflows for enterprise and mid-market engineering teams.
- Company typePrivate
- Founded2023
- HeadquartersAustin, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What DryRun Security does
DryRun Security is an Austin-based, AI-native code security intelligence platform founded in 2023 by James Wickett (CEO) and Ken Johnson (CTO). The company's core product is the Contextual Security Analysis (CSA) engine, which uses specialized AI agents to map a continuously updated knowledge graph of a codebase — covering architecture, authorization boundaries, data flow, and behavioral history — and then traces input, logic, permissions, and data movement across the application to identify exploitable security risks. Unlike traditional regex-based SAST, the platform validates exploitability and applies confidence scoring before raising findings, and ships supporting capabilities including PR code reviews, full-codebase DeepScan, Natural Language Code Policies (NLCP), secrets detection, infrastructure-as-code scanning, and Codebase Intelligence with an Insights AI assistant.
The product surface is distributed through native GitHub and GitLab applications that surface findings directly in pull requests, a public API and Code Insights MCP for programmatic integration, and a DryRun Skill that equips AI coding tools (Claude Code, Codex, Cursor, Windsurf, VS Code) with security context. The company sells via a hybrid product-led and field-sales motion targeting enterprise and mid-market engineering and security teams across verticals including e-commerce (Commerce), HR technology (BrightHR, Gusto), security automation (Tines, Defect Dojo), logistics and manufacturing (Flex, Dematic, PlanetArt), and AI-driven services (Invisible Technologies serving Fortune 50 clients). Pricing is SaaS subscription on a quote-based, sales-assisted basis for larger deployments, with SOC 2 Type 2 compliance in place to support enterprise procurement.
DryRun Security firmographics
Firmographics- Name
- DryRun Security
- Legal name
- DryRun Security Co.
- Website
- https://dryrun.security
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- DryRun Security is an Austin-based AI-native code security intelligence platform that uses contextual analysis and specialized agents to detect exploitable vulnerabilities, enforce natural-language policies, and integrate directly into GitHub, GitLab, and AI coding tool workflows for enterprise and mid-market engineering teams.
- Ownership category
- akta.pro rank
DryRun Security industry classification
Industry- Product category
- Application Security Testing (SAST)
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where DryRun Security is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
DryRun Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription - SAST Platform: The company operates on a SaaS subscription model providing access to its AI-native code security intelligence platform. Customers pay for the SAST platform, PR code reviews, repository scans, custom policies, and related security features. The platform is accessed through GitHub/GitLab integration with findings surfaced in pull requests.
Go-to-market motion2 records
Distribution channels5 records
Marketing channels5 records
DryRun Security product offering
Product offeringCore offering
DryRun Security sells an AI-native, agentic code security intelligence platform that performs static application security testing (SAST) by analyzing code in context within GitHub and GitLab workflows. It validates exploitability, applies confidence scoring, enforces custom natural-language policies, and guides developer and AI-coding-agent remediation before code ships. Standalone product surfaces include AI-Native SAST, pull-request code reviews, full-repo scans (DeepScan Agent), Natural Language Code Policies, Codebase Intelligence, Secrets Detection, and Infrastructure-as-Code Security, sold as a recurring SaaS subscription.
Product overview
DryRun Security offers an AI-native code security intelligence platform designed as a unified product with multiple integrated modules. The core platform centers on AI-Native SAST powered by the proprietary Contextual Security Analysis engine, which is complemented by PR Code Reviews, DeepScan Agent for full-repo scanning, Custom Code Policies (Natural Language Code Policies), Secrets Detection, and Infrastructure as Code Security. The platform includes supporting capabilities like Codebase Intelligence (Insights AI Assistant), Triage & Trends, Developer Activity tracking, and the Code Insights MCP integration. All capabilities share a common intelligence layer built on a continuously updated knowledge graph that maps codebase architecture, authorization boundaries, data flow, and behavioral history. The platform supports Python, JavaScript, TypeScript, Java, C#, Ruby, and Golang, and integrates with GitHub, GitLab, Slack, and various AI coding tools (Claude Code, Codex, Cursor, Windsurf, VS Code).
Differentiator
Problem solved
Functional benefit
Products and services
- AI-Native SAST Static Application Security Testing product powered by the Contextual Security Analysis engine. Understands code intent, detects injection, authentication, IDOR, and logic bugs, and is sold as part of the DryRun SaaS subscription for development and security teams.
- PR Code Reviews Automated security review capability that posts findings as comments on every pull request inside GitHub and GitLab, giving developers code context, security findings, and change summaries without leaving the PR workflow.
- DeepScan Agent Full-repository baseline scan product that locates structural risks and vulnerabilities across entire codebases, providing comprehensive security assessment beyond individual pull request changes.
- Custom Code Policies (Natural Language Code Policies, NLCP) Policy-as-code product enabling development and security teams to author security policies in plain natural language (or via the Custom Policy Agent) that are automatically enforced on every code change, removing the need to maintain regex rules or rule groups.
- Codebase Intelligence Intelligence layer on top of vulnerability findings that enables actionable security workflows across codebases and development organizations, including feature ship summaries, vulnerability trends, architecture risks, and incident response.
- Secrets Detection Code scanning capability that detects hardcoded credentials, API keys, and secrets in code to prevent security issues like the ones cited in customer testimonials.
- Infrastructure as Code (IaC) Security Security scanning product for infrastructure-as-code templates and configurations that identifies misconfigurations and security risks in IaC assets.
Quantifiable outcome
- 88% of seeded vulnerabilities detected in 2025 SAST Accuracy Report, outperforming five leading static analysis tools
- +4 more outcomes
Companies that use DryRun Security
Customer profileNamed customers9 records
Segments3 records
Ideal customer profiles3 records
DryRun Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability10 records
Feature8 records
DryRun Security partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and supporting.
- GitHubcorePrimary integration platform for the DryRun Security application. The app installs via GitHub giving customers control over permissions. Security findings are posted as comments on pull requests. Permissions can be revoked instantly through GitHub.
- GitLabcoreAlternative SCM integration platform for DryRun Security. Mirrors GitHub integration functionality including permission controls and PR comment posting.
- TinessupportingSecurity automation platform used as middleware to connect DryRun Security webhooks to Jira for automated ticket creation and deduplication. Enables enterprise workflow automation.
- ZapiersupportingNo-code automation platform alternative to Tines for connecting DryRun Security webhooks to Jira. Allows non-technical users to build DryRun-to-Jira workflows.
- Claude Code (Anthropic)coreAI coding assistant with dedicated DryRun Security Skill integration. Enables secure code authoring, PR review awareness, and contextual remediation guidance through the AI-native workflow.
- Codex (OpenAI)coreAI coding assistant integrated with DryRun Security Skill for secure development workflow support.
- CursorcoreAI-powered code editor integrated with DryRun Security Skill for secure development practices.
- SlacksupportingNotifications and team collaboration integration. Security findings and team activity can be surfaced in Slack channels.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
DryRun Security competitors and assessment
Company assessmentEmerging players
- Mobb: AI-powered SAST focused on automated vulnerability remediation. Emerging AI-native SAST peer with overlapping mission of reducing noise and providing contextual fixes for developers.
- Claude Code Security (Anthropic): Anthropic's native security review feature inside the Claude Code AI coding assistant. Emerging direct competitor explicitly named on DryRun's comparison page; threatens to disintermediate third-party SAST by embedding contextual security inside the AI coding tool itself.
- Aikido Security: All-in-one application security platform covering SAST, SCA, DAST, and cloud security with a developer-friendly GTM motion. Emerging competitor targeting the same mid-market and developer-led buyer as DryRun.
Direct peers
- Snyk Code: Snyk's SAST product offering developer security testing integrated with IDE and SCM workflows. Direct peer in the SAST category; DryRun publishes a direct comparison page against Snyk Code, and both target the same AppSec buyer with PR-based scanning.
- SonarQube (Sonar): Code quality and SAST platform with deep IDE and CI/CD integrations supporting 30+ languages. Direct SAST peer; DryRun publishes a direct comparison page, and Sonar's broader language matrix represents the main enterprise incumbent.
- Semgrep: Open-core SAST platform widely adopted by engineering teams for static analysis. Directly comparable to DryRun as both target developer-centric SAST with CI/CD integrations; DryRun publishes a direct head-to-head comparison page against Semgrep.
Broad incumbents
- Veracode: Enterprise AppSec platform offering SAST, DAST, SCA, and software composition analysis. Comparable as a broad incumbent in the same application security testing category, primarily serving large regulated enterprises rather than developer-led adoption.
- Checkmarx: Enterprise application security testing platform with SAST, SCA, IaC, and API security. Comparable broad incumbent serving large enterprise AppSec programs; represents the legacy regex/pattern-matching paradigm DryRun is positioned against.
- GitLab SAST: GitLab's native static analysis integrated into the broader DevSecOps platform. Comparable as a broad incumbent offering SAST within a wider portfolio; DryRun is a technology/integration partner via GitLab app install.
- GitHub Advanced Security: GitHub's native SAST, secret scanning, and dependency scanning suite bundled with GitHub Enterprise. As a distribution-platform incumbent, it represents both a partner (DryRun installs via GitHub) and a potential competitive threat with native AI features rolling out.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks7 records
Key highlights7 records
Customer concentration
DryRun Security social profiles
Digital presenceDryRun Security compliance and trust
Trust signalCompliance1 record
DryRun Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
DryRun Security leadership team
Management profileNumber of profiles
Profiles3 records
DryRun Security funding detail
Funding detailFunding overview
Funding rounds2 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DryRun Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DryRun Security
What does DryRun Security do?
DryRun Security sells an AI-native, agentic code security intelligence platform that performs static application security testing (SAST) by analyzing code in context within GitHub and GitLab workflows. It validates exploitability, applies confidence scoring, enforces custom natural-language policies, and guides developer and AI-coding-agent remediation before code ships. Standalone product surfaces include AI-Native SAST, pull-request code reviews, full-repo scans (DeepScan Agent), Natural Language Code Policies, Codebase Intelligence, Secrets Detection, and Infrastructure-as-Code Security, sold as a recurring SaaS subscription.
Is DryRun Security a public or private company?
DryRun Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was DryRun Security founded?
DryRun Security was founded in 2023. It employs 11 to 50 people.
Where is DryRun Security based?
DryRun Security is headquartered in Austin, United States, in the North America region.
How does DryRun Security make money?
One revenue line is on record: saaS Subscription - SAST Platform.
Who are DryRun Security's main competitors?
Emerging players on record are Mobb, Claude Code Security (Anthropic) and Aikido Security. Direct peers are Snyk Code, SonarQube (Sonar) and Semgrep. Broad incumbents are Veracode, Checkmarx, GitLab SAST and GitHub Advanced Security.
Does DryRun Security have an API?
Yes. DryRun Security provides a public API for programmatic access to its code security intelligence platform. The API allows developers to integrate DryRun Security into CI/CD pipelines, custom tooling, and automation workflows. Authentication is via API access keys using the Bearer scheme in the Authorization header. Rate limits apply and are displayed in the API Keys settings page. Developer documentation is at docs.dryrun.security/dryrun-api.
What industry is DryRun Security in?
DryRun Security's product category is Application Security Testing (SAST). Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 5132 and its SIC code is 7372.