GrammaTech
GrammaTech is a privately held U.S. software-assurance vendor founded in 1988 as a Cornell spin-off, selling static analysis (CodeSonar), automated vulnerability remediation (Proteus), OT firmware security (REAFFIRM), container debloating (Dykondo), and C++ to Rust migration (CRAM) to the DoD, intelligence agencies, aerospace primes, and embedded-systems manufacturers.
- Company typePrivate
- Founded1988
- HeadquartersIthaca, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What GrammaTech does
GrammaTech, Inc. is a privately held U.S. software-assurance and cybersecurity vendor founded in 1988 as a Cornell University spin-off by Thomas Reps and Tim Teitelbaum to commercialize their work on The Synthesizer Generator. The company builds tools that analyze, harden, and remediate software at both source and binary levels, addressing vulnerability detection, supply-chain integrity, DevSecOps automation, and firmware/OT security for U.S. government, defense, aerospace, and embedded-systems customers. Its product portfolio centers on CodeSonar (whole-program, interprocedural static analysis for C/C++, Java, and binaries), Proteus (automated vulnerability discovery and remediation on Linux/Windows binaries using fuzzing, symbolic execution, and exploitability analysis), CodeSurfer (program-slicing code browser), REAFFIRM (OT firmware analysis and FBOM generation), Dykondo (container debloating), and CRAM (C++ to Rust assisted migration), underpinned by the open-source GTIRB intermediate representation and DDisasm disassembler. CodeSonar is certified for ISO 26262, IEC 61508, and EN 50128 safety standards, and Proteus holds an Authorization to Operate (ATO) enabling air-gapped, classified-environment deployment.
GrammaTech monetizes through a hybrid of software licenses (perpetual and term), annual subscriptions covering updates and support, and professional services for training, integration, and specialized security assessments, with quote-based enterprise pricing. Go-to-market is sales-led, combining direct enterprise field sales targeting DoD and federal buyers with inside sales for smaller commercial accounts and marketplace listings on DoD Platform One and Tradewinds Solutions Marketplace. Revenue and bookings are anchored by long-standing relationships with the U.S. Navy, U.S. Air Force, NASA, DARPA, AFRL, DHS, and defense primes such as Raytheon, complemented by commercial customers including Sypris Electronics and an unspecified Fortune 500 base. The company has received multiple multi-million-dollar U.S. government contracts over its history, including a $12.9M AFRL STONESOUP award (2010), $8.25M across multiple agencies (2013), a $9M Navy contract (2017), and a $1M DARPA AI Cyber Challenge prize (2024), reflecting deep R&D funding from federal sources rather than traditional venture capital. The company maintains offices in Ithaca, NY (headquarters), Madison, WI, and New York City, and is led by CEO Dan Goodwin alongside co-founder/Chairman Tim Teitelbaum and co-founder/President Thomas Reps.
GrammaTech firmographics
Firmographics- Name
- GrammaTech
- Legal name
- GrammaTech, Inc.
- Website
- https://grammatech.com
- Company type
- Private
- Founded year
- 1988
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- GrammaTech is a privately held U.S. software-assurance vendor founded in 1988 as a Cornell spin-off, selling static analysis (CodeSonar), automated vulnerability remediation (Proteus), OT firmware security (REAFFIRM), container debloating (Dykondo), and C++ to Rust migration (CRAM) to the DoD, intelligence agencies, aerospace primes, and embedded-systems manufacturers.
- Ownership category
- akta.pro rank
GrammaTech industry classification
Industry- Product category
- Application Security Software
- NAICS
- Computer Systems Design and Related Services (5415), Custom Computer Programming Services (541511)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- Patch & Remediation Orchestration (HDADAHAB)
Keywords
Where GrammaTech is headquartered
LocationHeadquarters
- HQ city
- Ithaca
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
GrammaTech business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Software Licenses: GrammaTech generates revenue through perpetual and term software licenses for CodeSonar and other tools. Customers purchase licenses based on team size, usage requirements, and deployment configuration.
- Subscriptions: Annual subscription plans providing access to software updates, support services, and maintenance. Subscriptions offer continuous access to new features and security updates.
- Professional Services: Consulting and specialized services including training, custom integration, and specialized security assessments delivered by GrammaTech's expert research team.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Hybrid | Annual | Custom enterprise pricing based on requirements |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels4 records
GrammaTech product offering
Product offeringCore offering
GrammaTech develops and sells software-assurance and cybersecurity tools that detect and remediate vulnerabilities in source code, binaries, and firmware. Its flagship product CodeSonar performs whole-program static analysis on C/C++, Java, and binary code, while Proteus automates vulnerability discovery and remediation directly on Windows and Linux executables using fuzzing, symbolic execution, and exploitability analysis. Specialized offerings address operational-technology firmware (REAFFIRM), container attack-surface reduction (Dykondo), and migration of C++ code to memory-safe Rust (CRAM), serving government, defense, aerospace, and embedded-systems customers.
Product overview
GrammaTech offers a portfolio of software assurance and cybersecurity products. The core platform includes CodeSonar (static analysis for C/C++, Java, and binaries), CodeSurfer (code browsing and slicing), and Proteus (automated vulnerability discovery and remediation). Specialized tools address specific security needs: REAFFIRM for OT firmware vulnerability detection, Dykondo for container debloating, and CRAM for C++ to Rust migration. These products work together—CodeSurfer provides the underlying analysis substrate for CodeSonar, Proteus operates on binaries, REAFFIRM secures firmware, and Dykondo optimizes container deployments. All products support government and mission-critical deployments with certifications including ISO 26262, IEC 61508, and EN 50128.
Differentiator
Problem solved
Functional benefit
Brands
- CodeSonar: GrammaTech's flagship static analysis tool that performs whole-program, interprocedural analysis on C/C++, Java, and binary code, identifying complex programming bugs.
- CodeSurfer
- Proteus
- REAFFIRM
- Dykondo
- CRAM
Products and services
- CodeSonar CodeSonar is a sophisticated static analysis tool that performs whole-program, interprocedural analysis on C/C++, Java, and binary code to identify complex programming bugs and security vulnerabilities. It is certified for ISO 26262 (automotive), IEC 61508 (industrial), and EN 50128 (railway) functional-safety standards and is used by government agencies, defense contractors, and embedded-systems manufacturers to detect defects early in development.
- CodeSurfer CodeSurfer is an interactive code browser that supports C, C++, and x86 machine code and provides precise interprocedural program slicing. It is used by organizations conducting manual software review for critical applications and underpins CodeSonar's bug-finding capabilities.
- Proteus Proteus is an automated software testing platform that finds and fixes vulnerabilities in binary executables without false alarms by fusing fuzzing, symbolic execution, crash reporting, and exploitability analysis. It operates directly on Windows and Linux binaries, integrates into CI/CD pipelines, and has achieved DoD Tradewinds Awardable status and ATO for classified environments.
- REAFFIRM REAFFIRM (Reverse Engineer and Fuzz Firmware for Operational Technology Environments) is an OT firmware vulnerability detection and Firmware Bill of Materials (FBOM) generation tool. It uses AI-enabled extraction to inventory firmware components and link them to CVEs/CWEs, supports IA32/X64, ARM, PPC, and MIPS architectures, and offers a Python API plus Jupyter Notebook integration.
- Dykondo Dykondo (DYnamic KONtainer Debloater/Optimizer) automatically removes unnecessary software, libraries, and files from container images to reduce attack surface, image size, and overhead for edge deployments. Achieved 87% image-size reduction in tested cases and is available on Platform One.
- CRAM (Migration to Memory Safe Code) CRAM is a near-automatic C++ to Rust Assisted Migration tool that converts C++ source code into idiomatic, human-maintainable Rust code to support migration to memory-safe languages. It targets legacy modernization and memory-safety compliance for government and commercial users and is available on Platform One.
Quantifiable outcome
- CodeSonar certified for ISO 26262, IEC 61508, EN 50128 safety standards
- +1 more outcomes
Companies that use GrammaTech
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles4 records
GrammaTech technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability7 records
Feature5 records
GrammaTech partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and minor.
- Raytheon CompanycoreGrammaTech serves as subcontractor to Raytheon on the DARPA STONESOUP program, contributing software assurance and analysis capabilities for defense systems development.
- U.S. NavycoreMajor government customer for software assurance and vulnerability detection services for naval defense systems.
- U.S. Air ForcecoreGovernment customer for software security analysis services supporting Air Force systems development and procurement.
- NASAcoreNASA uses GrammaTech tools for software verification and security of space systems, demonstrating credibility in mission-critical aerospace applications.
- University of VirginiaminorResearch partnership with University of Virginia for collaborative software security research.
- Georgia Institute of TechnologyminorAcademic research partnership with Georgia Tech for software analysis and security research.
Scale indicators3 records
Recent moves7 records
Expansion highlights6 records
GrammaTech competitors and assessment
Company assessmentBroad incumbents
- Synopsys: Synopsys's Software Integrity Group (Coverity, Black Duck, Code Dx) is the dominant SAST/static analysis vendor. Directly comparable to GrammaTech's CodeSonar and broader software assurance portfolio, but at vastly larger scale and with broader DevSecOps bundling.
- GitHub Advanced Security: GitHub's CodeQL-based Advanced Security offering bundles SAST, dependency scanning, and secret scanning into the developer workflow. Competes with CodeSonar on integrated DevSecOps economics and free pricing tiers for open-source projects.
- GitLab: GitLab's built-in SAST and container/security scanning compete with GrammaTech's offerings as part of an integrated DevSecOps platform. Particularly relevant for federal customers consolidating tooling under single platforms.
- Snyk: Snyk's developer security platform spans SAST, SCA, container, and IaC scanning. Competes with GrammaTech on supply chain security and developer-first GTM, with significantly larger commercial presence.
Direct peers
- Veracode: Veracode provides enterprise static analysis, dynamic analysis, and software composition analysis as SaaS. Direct competitor to CodeSonar in the SAST market, particularly for enterprise and regulated-industry buyers.
- Checkmarx: Checkmarx CxSAST is a leading SAST platform for enterprise application security. Direct competitor to GrammaTech in source code vulnerability detection, with broader language coverage and commercial GTM reach.
- SonarSource (SonarQube): SonarSource provides static analysis for code quality and security across many languages. Direct competitor to CodeSonar, with strong open-source/community presence and growing enterprise footprint.
- ForAllSecure (Mayhem): ForAllSecure won the DARPA Cyber Grand Challenge with its Mayhem autonomous vulnerability discovery platform — a direct parallel to GrammaTech's Proteus and AIxCC win. Highly comparable in autonomous binary fuzzing/exploit reasoning.
Emerging players
- Semgrep: Semgrep offers fast, developer-friendly static analysis with a code-as-rules paradigm. Competes with CodeSonar for the modern application security buyer segment, especially in tech-forward enterprises.
- Claroty: Claroty provides OT/ICS cybersecurity including asset discovery and vulnerability management. Overlaps with GrammaTech's REAFFIRM for OT firmware vulnerability detection in industrial environments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
GrammaTech social profiles
Digital presenceGrammaTech compliance and trust
Trust signalCompliance4 records
GrammaTech financial estimates
Financial estimateRevenue estimate
Valuation estimate
GrammaTech leadership team
Management profileNumber of profiles
Profiles8 records
GrammaTech funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GrammaTech M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GrammaTech
What does GrammaTech do?
GrammaTech develops and sells software-assurance and cybersecurity tools that detect and remediate vulnerabilities in source code, binaries, and firmware. Its flagship product CodeSonar performs whole-program static analysis on C/C++, Java, and binary code, while Proteus automates vulnerability discovery and remediation directly on Windows and Linux executables using fuzzing, symbolic execution, and exploitability analysis. Specialized offerings address operational-technology firmware (REAFFIRM), container attack-surface reduction (Dykondo), and migration of C++ code to memory-safe Rust (CRAM), serving government, defense, aerospace, and embedded-systems customers.
Is GrammaTech a public or private company?
GrammaTech is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was GrammaTech founded?
GrammaTech was founded in 1988. It employs 51 to 100 people.
Where is GrammaTech based?
GrammaTech is headquartered in Ithaca, United States, in the North America region.
How does GrammaTech make money?
Three revenue lines are on record. Software Licenses are the primary driver. The others are subscriptions and professional Services.
Who are GrammaTech's main competitors?
Broad incumbents on record are Synopsys, GitHub Advanced Security, GitLab and Snyk. Direct peers are Veracode, Checkmarx, SonarSource (SonarQube) and ForAllSecure (Mayhem). Emerging players are Semgrep and Claroty.
Does GrammaTech have an API?
Yes. REAFFIRM provides a Python API for workflow integration, allowing users to automate analysis, extraction, and fuzzing operations. CodeSonar also offers API bindings in C++, Python, Java, and C# for programmatic access and integration.
What industry is GrammaTech in?
GrammaTech's product category is Application Security Software. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADAHAB, Patch & Remediation Orchestration. Its NAICS code is 5415 and its SIC code is 7372.