Coana (acquired by Socket)
Coana built Software Composition Analysis with proprietary reachability analysis to eliminate false positives in open-source vulnerability scanning for AppSec and developer teams, using static call-graph analysis spun out of Aarhus University; acquired by Socket in April 2025.
- Company typePrivate
- Founded2023
- HeadquartersAarhus, Denmark
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Coana (acquired by Socket) does
Coana is a developer-focused cybersecurity company that builds Software Composition Analysis (SCA) software with proprietary reachability analysis to cut false positives in open-source vulnerability scanning. Founded in 2022/2023 as a spinout from Aarhus University's programming languages research group, the company applies control-flow and call-graph static analysis to determine which vulnerabilities in direct and transitive dependencies are actually reachable from a project's entry points, claiming to eliminate over 80% of false positives and reduce vulnerability management burden by 80-95%. The platform supports JavaScript, TypeScript, Python, Java, Go, Ruby, .NET, PHP, Rust, Scala, and Kotlin, and is delivered as an offline CLI tool plus integrations with CircleCI, GitHub Actions, GitLab CI, Azure DevOps, Jira, Linear, Vanta, Slack, and GitHub Dependabot, with no agent installation required.
The company's revenue model is enterprise subscription SaaS with custom pricing accessed via a 'Book a demo' sales motion, supplemented by a self-serve live demo for product-led evaluation. The go-to-market targets AppSec teams and developer organizations — both startups (Maze, Watershed, Front, Gather, AppFarm, Januar) and regulated enterprises (GAN Integrity, Partisia) — across LegalTech, Financial Services, Privacy/Blockchain, Environmental/Sustainability, Customer Service, and Low-code verticals. The company achieved SOC 2 Type II compliance and received Horizon Europe EIC Transition programme funding alongside a $1.6M Sequoia-led pre-seed.
On April 23, 2025, Coana was acquired by Socket, a software supply chain security company serving 8,500+ organizations. The combined entity integrates Coana's reachability analysis into Socket's platform, with Coana's team joining Socket to scale impact. Pre-acquisition, the firm employed 11-50 people and was headquartered in Aarhus, Denmark, maintaining deep ties to the Aarhus University research community that continues to supply specialized talent.
Coana (acquired by Socket) firmographics
Firmographics- Name
- Coana (acquired by Socket)
- Legal name
- Coana
- Website
- https://coana.tech
- Company type
- Private
- Founded year
- 2023
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Coana built Software Composition Analysis with proprietary reachability analysis to eliminate false positives in open-source vulnerability scanning for AppSec and developer teams, using static call-graph analysis spun out of Aarhus University; acquired by Socket in April 2025.
- Ownership category
- akta.pro rank
Coana (acquired by Socket) industry classification
Industry- Product category
- Application Security Software
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Coana (acquired by Socket) is headquartered
LocationHeadquarters
- HQ city
- Aarhus
- HQ country
- Denmark
- HQ region
- Europe
Offices1 record
Markets served
Coana (acquired by Socket) business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SCA Subscription Licensing: Coana offers its SCA with reachability analysis as a subscription-based SaaS product. The product is marketed with enterprise pricing tiers and a 'Book a demo' sales approach, indicating subscription-based recurring revenue from security tooling licenses.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with custom pricing |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels6 records
Coana (acquired by Socket) product offering
Product offeringCore offering
Coana provides a Software Composition Analysis (SCA) platform with built-in reachability analysis that uses static call-graph analysis to identify which open-source dependency vulnerabilities are actually exploitable in an application's codebase. The platform reduces false-positive vulnerability alerts by over 80%, integrates directly into CI/CD pipelines without agents, and supports multiple programming languages including JavaScript, TypeScript, Python, Java, Go, Ruby, PHP, .NET, Rust, Scala, and Kotlin.
Product overview
Coana is a unified Software Composition Analysis (SCA) platform built around a proprietary reachability analysis engine. The core Coana platform serves as the central SCA tool, which incorporates multiple specialized modules: Reachability Analysis (the core technology that eliminates 80-95% of false positives by determining which vulnerabilities are actually exploitable), Assisted Triaging (AI-assisted vulnerability prioritization), Auto-Fixing (automated dependency upgrades via socket fix), SBOM/VEX (compliance documentation generation), and Workflow Integrations (CI/CD pipeline automation). The Coana CLI enables local and CI/CD-based scanning, while Guardrail (Beta) provides real-time monitoring. The platform supports scanning for JavaScript, TypeScript, Python, Java, Kotlin, Scala, Go, Ruby, C#, PHP, and Rust projects, analyzing both direct and transitive dependencies. Following acquisition by Socket in April 2025, Coana's technology is being integrated into Socket's supply chain security platform.
Differentiator
Problem solved
Functional benefit
Products and services
- Coana SCA Platform Software Composition Analysis platform with built-in reachability analysis that uses static call-graph analysis to determine which open-source dependency vulnerabilities are actually exploitable in the user's application. Targets AppSec teams and developers to reduce vulnerability management burden by 80-95%.
- Coana CLI Command-line interface tool for running reachability analysis and vulnerability scans locally or within CI/CD environments. Available as an npm package and supports JavaScript, TypeScript, Python, Java, Kotlin, Scala, Go, Ruby, C#, PHP, and Rust projects.
Quantifiable outcome
- Reduces vulnerability management burden by 80-95%
- +3 more outcomes
Companies that use Coana (acquired by Socket)
Customer profileNamed customers8 records
Segments3 records
Ideal customer profiles2 records
Coana (acquired by Socket) technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability3 records
Feature6 records
Coana (acquired by Socket) partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- SocketcoreSocket, a leader in software supply chain security, acquired Coana to integrate best-in-class reachability analysis into its platform. The acquisition aims to reduce false positives and improve vulnerability prioritization. Coana's team joined Socket to scale impact, bringing reachability analysis capabilities to Socket's 8,500+ organizational customer base.
- Aarhus UniversitycoreCoana was founded by researchers from Aarhus University's programming languages research group, which is led by Professor Anders Møller. The company maintains ongoing connection to academia with two first hires coming from the research group. This academic partnership provides access to world-leading static analysis research talent.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Coana (acquired by Socket) competitors and assessment
Company assessmentDirect peers
- Snyk: Snyk is a leading developer security platform with its own SCA product (Snyk Open Source). It competes directly with Coana in dependency vulnerability scanning and has begun adding reachability-style prioritization features, targeting the same AppSec and developer persona.
- Endor Labs: Endor Labs is a direct competitor in SCA with reachability analysis, focused on dependency graph analysis to identify reachable vulnerabilities. It targets the same enterprise AppSec and developer segments with a similar value proposition of reducing false positives.
- Mend (formerly WhiteSource): Mend offers an SCA platform that has historically focused on open source vulnerability detection. As an established player it competes with Coana for enterprise AppSec budgets, though it does not center its product on reachability analysis as deeply.
- Anchore: Anchore provides SBOM-based software supply chain security including vulnerability scanning and policy enforcement. It overlaps with Coana's SCA and SBOM/VEX functionality and serves similar compliance-focused enterprise customers.
Broad incumbents
- Socket: Socket is the company that acquired Coana and the broader developer-first supply chain security platform. It is a comparable broader incumbent combining SCA, malicious package detection, and dependency management — now incorporating Coana's reachability capabilities.
- JFrog Xray: JFrog Xray is part of the JFrog Platform providing SCA and security scanning integrated with artifact management. It competes in the same enterprise security segment with broader DevOps tooling, though reachability analysis is not its core differentiator.
- Sonatype Nexus: Sonatype operates Nexus Lifecycle, an established SCA product, and is the steward of the Central Repository. It competes in dependency vulnerability management at the enterprise tier, with broader portfolio offerings beyond Coana's reachability-focused scope.
- GitHub Dependabot: GitHub Dependabot is a free, widely adopted dependency vulnerability scanner native to GitHub. Coana integrates with Dependabot and competes on precision — Dependabot surfaces broad alerts while Coana filters to reachable vulnerabilities.
Emerging players
- Arnica: Arnica is an emerging developer security platform offering SCA plus reachability-style analysis with code-to-user behavioral risk scoring. It targets similar AppSec and developer personas with a focus on reducing false positives in dependency scanning.
- Aikido Security: Aikido Security is an emerging unified code security platform offering SCA alongside SAST and other scanning capabilities. It targets startups and mid-market with consolidated security tooling, partially overlapping with Coana's developer-focused vulnerability reduction story.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Coana (acquired by Socket) social profiles
Digital presenceCoana (acquired by Socket) compliance and trust
Trust signalCompliance1 record
Coana (acquired by Socket) financial estimates
Financial estimateRevenue estimate
Valuation estimate
Coana (acquired by Socket) leadership team
Management profileNumber of profiles
Profiles4 records
Coana (acquired by Socket) funding detail
Funding detailFunding overview
Funding rounds4 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Coana (acquired by Socket) M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Coana (acquired by Socket)
What does Coana (acquired by Socket) do?
Coana provides a Software Composition Analysis (SCA) platform with built-in reachability analysis that uses static call-graph analysis to identify which open-source dependency vulnerabilities are actually exploitable in an application's codebase. The platform reduces false-positive vulnerability alerts by over 80%, integrates directly into CI/CD pipelines without agents, and supports multiple programming languages including JavaScript, TypeScript, Python, Java, Go, Ruby, PHP, .NET, Rust, Scala, and Kotlin.
Is Coana (acquired by Socket) a public or private company?
Coana (acquired by Socket) is a private company. It is classified as corporate owned and is currently acquired.
When was Coana (acquired by Socket) founded?
Coana (acquired by Socket) was founded in 2023. It employs 11 to 50 people.
Where is Coana (acquired by Socket) based?
Coana (acquired by Socket) is headquartered in Aarhus, Denmark, in the Europe region.
How does Coana (acquired by Socket) make money?
One revenue line is on record: SCA Subscription Licensing.
Who are Coana (acquired by Socket)'s main competitors?
Direct peers on record are Snyk, Endor Labs, Mend (formerly WhiteSource) and Anchore. Broad incumbents are Socket, JFrog Xray, Sonatype Nexus and GitHub Dependabot. Emerging players are Arnica and Aikido Security.
Does Coana (acquired by Socket) have an API?
Yes. Coana provides API access for programmatic interaction with its SCA platform. The documentation section at /api-access/intro indicates an API is available, though specific details about endpoints, authentication methods, or rate limits are not explicitly stated in the provided sources. Users can access Coana through its CLI tool and integrate with their CI/CD pipelines. Developer documentation is at docs.coana.tech/api-access/intro.
What industry is Coana (acquired by Socket) in?
Coana (acquired by Socket)'s product category is Application Security Software. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 513210 and its SIC code is 7372.