Kodem Security
Kodem Security provides an enterprise application security platform that combines eBPF-based runtime intelligence with agentic AI to help CISOs and AppSec teams prioritize exploitable vulnerabilities, cut false positives, and automate remediation across code, pipeline, and production environments.
- Company typePrivate
- Founded2021
- HeadquartersTel Aviv-yafo, Israel
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Kodem Security does
Kodem Security is a Tel Aviv-based application security company founded in 2021 that builds an intelligent application security platform designed to help enterprise security teams prioritize vulnerabilities attackers can actually exploit rather than the full volume of theoretical findings produced by legacy SAST and SCA tools. The platform unifies runtime-powered Software Composition Analysis (SCA), runtime-powered Static Application Security Testing (SAST), and Application Detection & Response (ADR) on a shared architecture branded Kodem C.O.R.E., which combines code analysis, eBPF-based kernel-level runtime sensors (claimed under 0.1% CPU overhead, no agent or reboot required), and agentic AI through the Kai AI security engineer. Kai is positioned to review code and pull requests, eliminate false positives, generate ready-to-merge fixes, and operate as an AI SOC against live attacks, with extensions into AI supply chain governance (AI-BOM), adversarial testing (AI Red Teaming), and protection of AI agents (Agentic AI Security). The company reports that its runtime intelligence has been used to prove more than 90% of scanner-detected CVEs are not exploitable in customer environments and to reduce alert noise by 99.5% and MTTR by 74%.
Kodem Security firmographics
Firmographics- Name
- Kodem Security
- Legal name
- Kodem Security Ltd.
- Website
- https://kodemsecurity.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Kodem Security provides an enterprise application security platform that combines eBPF-based runtime intelligence with agentic AI to help CISOs and AppSec teams prioritize exploitable vulnerabilities, cut false positives, and automate remediation across code, pipeline, and production environments.
- Ownership category
- akta.pro rank
Kodem Security industry classification
Industry- Product category
- Application Security
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI), Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Security Analytics & Detection Engineering (HDADAGAE), Vulnerability Assessment & Scanning (HDADAHAA)
Keywords
Where Kodem Security is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv-yafo
- HQ country
- Israel
- HQ region
- Middle East
Offices1 record
Markets served
Kodem Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Platform Subscription: Cloud-delivered application security platform sold as subscription to enterprises. Customers pay for platform access based on usage scope, applications covered, and feature tiers. Revenue is recurring as customers renew annual or multi-year contracts for continuous security monitoring and protection.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with customized pricing based on scope and requirements |
Go-to-market motion3 records
Distribution channels2 records
Marketing channels6 records
Kodem Security product offering
Product offeringCore offering
Kodem Security sells an Intelligent Application Security Platform that combines runtime-powered Software Composition Analysis (SCA), runtime-powered Static Application Security Testing (SAST), and Application Detection & Response (ADR) into a single subscription-based SaaS. The platform uses eBPF-based runtime sensors and an agentic AI security engineer called Kai to identify and prioritize only the vulnerabilities that actually execute in production, generate ready-to-merge remediation fixes, and block live attacks in real time.
Product overview
Kodem Security offers an intelligent application security platform built on a unified architecture combining runtime-powered SCA, runtime-powered SAST, and Application Detection & Response (ADR). The platform's core technology is Kodem C.O.R.E., which integrates code analysis, runtime intelligence via eBPF sensors, and agentic AI through Kai. Key modules include Runtime-powered SCA for open-source risk management, Runtime-powered SAST for source code vulnerabilities, and ADR for blocking live attacks. The platform extends with AI-BOM for AI supply chain governance, CVE Archive for vulnerability tracking, and Exploit Trigger Defense for behavioral exploit detection. Kai serves as the AI-powered security engineer, providing autonomous code review, false positive elimination, and automated remediation. The platform differentiates through runtime intelligence that confirms which vulnerabilities actually execute in production, reducing alert noise by 99.5% and achieving 74% MTTR improvement.
Differentiator
Problem solved
Functional benefit
Products and services
- Runtime-powered SCA (Software Composition Analysis) Identifies and manages risks in third-party and open-source components by combining traditional SCA with runtime intelligence to filter out non-exploitable vulnerabilities, targeting enterprise security and AppSec teams running cloud-native applications.
- Runtime-powered SAST (Static Application Security Testing) Detects and fixes vulnerabilities directly in source code using AI-assisted static analysis validated against runtime execution evidence, eliminating false positives from static-only analysis, for enterprise development and AppSec teams.
- Application Detection & Response (ADR) Monitors and blocks live attacks across running applications and workloads using eBPF-powered runtime intelligence and exploit-trigger detection, providing real-time protection for enterprise cloud-native applications.
- Kai AI-powered security engineer that thinks like an attacker, reviews code and pull requests, eliminates false positives, generates ready-to-merge remediation fixes, and operates as an AI SOC for applications to mitigate and respond to threats in real time, for enterprise security and development teams.
Quantifiable outcome
- 99.5% reduction in alerts that don't matter
- +6 more outcomes
Companies that use Kodem Security
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles3 records
Kodem Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability10 records
Feature9 records
Kodem Security partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Google CloudcoreKodem Security joined Google Cloud Marketplace and GKE Autopilot Partner Ecosystem. Integration enables active scanning, analyzing, and responding to threats in real-time across all stages of the development lifecycle. Partnership supports cloud-native security workflows and developer efficiency through streamlined alert systems.
- Opengrep ConsortiumcoreIndustry alliance including Kodem, Aikido Security, Arnica, Amplify Security, Endor Labs, Jit, Legit Security, Mobb, and Orca Security launched Opengrep as a collaborative fork of Semgrep's code analysis engine. Kodem CTO Pavel Furman represents the company as co-founder of the initiative to preserve open-source security infrastructure.
Scale indicators11 records
Recent moves6 records
Expansion highlights6 records
Kodem Security competitors and assessment
Company assessmentDirect peers
- Snyk: Leading developer security platform offering SAST, SCA, and IaC scanning with overlapping enterprise AppSec buyers. Direct head-to-head competitor for Kodem's runtime-powered SAST and SCA.
- Veracode: Long-standing enterprise AppSec platform covering SAST, SCA, and DAST. Competes directly for Kodem's CISOs/AppSec buyer base in large enterprises.
- Checkmarx: Enterprise SAST and SCA vendor with comparable product breadth and enterprise go-to-market. Direct competitor in AppSec code analysis.
- Contrast Security: Runtime-based application security and ADR vendor using instrumentation inside applications. Closest direct competitor on the runtime intelligence / Application Detection & Response axis.
Broad incumbents
- GitHub Advanced Security: Broad incumbent offering SAST, SCA, and secret scanning as part of GitHub Enterprise. Bundles security with developer platform, posing a pricing and distribution threat to standalone AppSec vendors.
- Aqua Security: Established cloud-native application security platform spanning containers, workloads, and runtime protection. Overlaps with Kodem's ADR/runtime capabilities in cloud environments.
- Wiz: Cloud security platform with strong AppSec adjacencies (workload security, vulnerability prioritization). Explicitly benchmarked by Kodem customer Rapyd as a comparable 'easy' cloud security experience.
Emerging players
- Aikido Security: Emerging all-in-one AppSec platform (SAST, SCA, CSPM, AI security) targeting SMB/mid-market. Comparable horizontal AppSec positioning with similar developer-led motion.
- Arnica: Developer-centric application security focused on SCA and software supply chain risks. Co-founder of the Opengrep consortium alongside Kodem, signaling overlapping technical community.
- Endor Labs: Software supply chain security vendor focused on SCA, dependency selection, and reachability. Comparable in Opengrep consortium and overlapping in dependency-graph analysis.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Kodem Security social profiles
Digital presenceKodem Security compliance and trust
Trust signalCompliance1 record
Kodem Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kodem Security leadership team
Management profileNumber of profiles
Profiles3 records
Kodem Security funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kodem Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kodem Security
What does Kodem Security do?
Kodem Security sells an Intelligent Application Security Platform that combines runtime-powered Software Composition Analysis (SCA), runtime-powered Static Application Security Testing (SAST), and Application Detection & Response (ADR) into a single subscription-based SaaS. The platform uses eBPF-based runtime sensors and an agentic AI security engineer called Kai to identify and prioritize only the vulnerabilities that actually execute in production, generate ready-to-merge remediation fixes, and block live attacks in real time.
Is Kodem Security a public or private company?
Kodem Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Kodem Security founded?
Kodem Security was founded in 2021. It employs 51 to 100 people.
Where is Kodem Security based?
Kodem Security is headquartered in Tel Aviv-yafo, Israel, in the Middle East region.
How does Kodem Security make money?
One revenue line is on record: saaS Platform Subscription.
Who are Kodem Security's main competitors?
Direct peers on record are Snyk, Veracode, Checkmarx and Contrast Security. Broad incumbents are GitHub Advanced Security, Aqua Security and Wiz. Emerging players are Aikido Security, Arnica and Endor Labs.
Does Kodem Security have an API?
No public API is recorded for Kodem Security.
What industry is Kodem Security in?
Kodem Security's product category is Application Security. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAEAFAI, Application Security Engineering (DevSecOps, AppSec Remediation). Its NAICS code is 5415 and its SIC code is 7372.