Longbow
Longbow is an Austin-based SaaS company (founded 2019, 11-50 employees) whose platform helps organizations identify Best Next Actions to reduce application and cloud security risk.
- Company typePrivate
- Founded2019
- HeadquartersAustin, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Longbow does
Longbow is an Austin, Texas-based for-profit SaaS company founded in 2019 that sells a platform enabling organizations to identify the Best Next Actions to reduce application and cloud risk. The platform operates in the application security posture management (ASPM) and cloud risk reduction category, providing a tool-agnostic approach to prioritizing risk reduction effort. Longbow is privately held, with no public ticker, and is led by CEO Dayne Myers and Founder & Chief Product Officer Derek Maki. The company has maintained a headcount in the 11-50 employee range and is positioned as an early-to-growth-stage venture.
The company has raised approximately $10.5 million across three equity rounds between February 2020 and December 2023. Investors include Grafton Street Partners (participating in both 2022 and 2023 rounds, and leading the 2022 round alongside Security Leadership Capital), Top Corner Capital, and Security Leadership Capital. The 2022 round of $5 million represented the largest single capital event, while the December 2023 round of $3 million signals continued investor engagement.
The company operates a subscription-based recurring revenue model typical of enterprise SaaS, with detailed pricing, customer segmentation, and named logos not disclosed in the provided input. The available source material contains a substantial volume of detailed product, integration, and customer information; however, the firmographic and capital structure data is specific to Longbow, and the broader product-level detail is not directly attributable to Longbow without further verification. Limited public visibility into customer wins, channel motion, or specific product capabilities constrains deeper assessment of commercial traction.
Longbow firmographics
Firmographics- Name
- Longbow
- Legal name
- Veracode, Inc.
- Website
- https://longbow.security
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Longbow is an Austin-based SaaS company (founded 2019, 11-50 employees) whose platform helps organizations identify Best Next Actions to reduce application and cloud security risk.
- Ownership category
- akta.pro rank
Longbow industry classification
Industry- Product category
- Application Security Posture Management
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- SaaS Security Posture Management (SSPM) (HDABAHAE)
- akta.pro secondary industries
- SaaS Security Posture Management (SSPM) (HDADADAI), Cloud Security Posture Management (CSPM) (HDABAHAA)
Keywords
Where Longbow is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Markets served
Longbow business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Subscription-based SaaS Platform: Veracode offers its Application Security Posture Management platform and related security testing tools as a subscription-based SaaS solution with enterprise licensing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with personalized demo and consultation |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Longbow product offering
Product offeringCore offering
Longbow operates a SaaS platform that enables companies to identify the best next actions to reduce application and cloud security risk. The platform is positioned in the Application Security Posture Management (ASPM) category, helping security teams prioritize remediation across application and cloud environments.
Product overview
Veracode offers a unified application security platform with Risk Manager as the central ASPM (Application Security Posture Management) product that aggregates and deduplicates findings from multiple security tools. The platform includes core testing products: SAST for static code analysis, DAST for dynamic web application testing, SCA for open-source vulnerability management, Container Security for pre-production container protection, and Package Firewall for pipeline security. Add-on modules include Fix (AI-powered code remediation), PTaaS for penetration testing services, eLearning for secure coding training, and Security Labs for hands-on security practice. Risk Manager serves as the unified dashboard that brings together insights from all these tools with AI-driven prioritization and automated investigation capabilities.
Differentiator
Problem solved
Functional benefit
Products and services
- Longbow ASPM Platform
Quantifiable outcome
- 10X increase in remediated issues
- +3 more outcomes
Companies that use Longbow
Customer profileNamed customers3 records
Segments8 records
Ideal customer profiles1 record
Longbow technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability4 records
Feature7 records
Longbow partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and major.
- ServiceNowcoreTwo-way sync integration with ServiceNow for incident and request ticket creation, ensuring Risk Manager's remediation recommendations integrate into enterprise workflow management.
- JIRA (Atlassian)coreTwo-way sync integration with JIRA for ticket creation and status monitoring, enabling security teams to track remediation progress directly within their existing project management tools.
- GitLabmajorPopular repository integration with GitLab to scan files and logs and analyze data. Creates issues from Container and SAST findings within GitLab workflows.
Scale indicators3 records
Recent moves3 records
Expansion highlights3 records
Longbow competitors and assessment
Company assessmentDirect peers
- ArmorCode: ASPM-focused platform that aggregates and prioritizes findings across SAST, DAST, SCA, and cloud security tools. One of the closest pure-play ASPM competitors to Longbow's described capability set, targeting enterprise security teams with similar tool consolidation value propositions.
- Checkmarx: Application security testing platform offering SAST, SCA, DAST, and container security with ASPM capabilities. Listed as a comparison competitor in the data and serves the same CISO and AppSec leader personas in financial services, government, and large enterprise.
- Snyk: Developer security platform covering SAST, SCA, container, and IaC security with an emerging ASPM-like orchestration layer. Targets similar enterprise security leaders and developer personas, and is explicitly called out in the Longbow data as a competitor in the "Choose Veracode Over Snyk" comparison page.
- Apiiro: Application security posture management platform focused on code-to-runtime risk prioritization and auto-remediation. Competes in the same ASPM category with similar AI-driven prioritization and root-cause analysis capabilities.
Broad incumbents
- Black Duck (Synopsys): Application security platform from Synopsys offering SAST, SCA, and container security. Listed as a comparison competitor and represents an established enterprise alternative in the same application security buyer segment.
- Veracode: Established application security platform with its Risk Manager ASPM product that unifies findings across SAST, DAST, SCA, and Container Security. Veracode is referenced extensively in the Longbow data and represents the incumbent Longbow would compete with in the ASPM/orchestration layer for enterprise security buyers.
- Wiz: Cloud security platform expanding from CNAPP into adjacent application and code security territory. While primarily cloud-focused, Wiz's broader posture management ambitions overlap with Longbow's stated "application and cloud risk" value proposition at large enterprises.
- GitHub Advanced Security: Native application security offering from GitHub covering code scanning, secret scanning, and dependency review. Listed as a competitor in the data and represents a major bundling threat because it comes embedded in the GitHub platform many developers already use.
- OpenText (Application Security): Fortify application security portfolio acquired by OpenText, offering SAST, DAST, and runtime security. Listed as a comparison competitor in the data and targets similar large enterprise security buyers.
Emerging players
- Jit: Application security orchestration platform that consolidates multiple open-source and commercial security scanners into a unified pipeline. Smaller and earlier-stage than Longbow but addresses similar tool consolidation and prioritization pain points for security teams.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat3 records
Key risks5 records
Key highlights5 records
Customer concentration
Longbow social profiles
Digital presenceLongbow compliance and trust
Trust signalCompliance1 record
Longbow financial estimates
Financial estimateRevenue estimate
Valuation estimate
Longbow leadership team
Management profileNumber of profiles
Profiles2 records
Longbow funding detail
Funding detailFunding overview
Funding rounds3 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Longbow M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Longbow
What does Longbow do?
Longbow operates a SaaS platform that enables companies to identify the best next actions to reduce application and cloud security risk. The platform is positioned in the Application Security Posture Management (ASPM) category, helping security teams prioritize remediation across application and cloud environments.
Is Longbow a public or private company?
Longbow is a private company. It is classified as venture growth investor backed and is currently operating.
When was Longbow founded?
Longbow was founded in 2019. It employs 11 to 50 people.
Where is Longbow based?
Longbow is headquartered in Austin, United States, in the North America region.
How does Longbow make money?
One revenue line is on record: subscription-based SaaS Platform.
Who are Longbow's main competitors?
Direct peers on record are ArmorCode, Checkmarx, Snyk and Apiiro. Broad incumbents are Black Duck (Synopsys), Veracode, Wiz, GitHub Advanced Security and OpenText (Application Security). Jit is listed as an emerging player.
Does Longbow have an API?
Yes. Longbow exposes a public API. Developer documentation is at docs.veracode.com/r/c_gettingstarted.
What industry is Longbow in?
Longbow's product category is Application Security Posture Management. Its primary akta.pro industry code is HDABAHAE, SaaS Security Posture Management (SSPM), with a secondary code of HDADADAI, SaaS Security Posture Management (SSPM). Its NAICS code is 51821 and its SIC code is 7371.