Plexicus
Plexicus is an AI-native ASPM and Vibe Coding Security platform, built in Bilbao, that autonomously scans, filters, fixes, pentests, and explains vulnerabilities in AI-generated and legacy code for European enterprises, security vendors, and AI-coding teams.
- Company typePrivate
- Founded2025
- HeadquartersBilbao, Spain
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Plexicus does
Plexicus is an AI-native Application Security Posture Management (ASPM) and Vibe Coding Security platform that operates an autonomous five-stage loop — scan, filter, fix, pentest, and understand — across application, cloud, and container estates. The platform combines SAST, SCA, secrets detection, IaC analysis, and AI-powered auto-remediation; its proprietary Codex Remedium agent generates reviewer-ready fix pull requests in under 60 seconds, and Phase-0 AI filtering strips false positives before they reach human queues. The company is incorporated in Bilbao, Spain as Plexicus S.L. (EU data residency by default, ephemeral container processing for zero retention) and operates a North American regional headquarters in Santa Clara, California. Plexicus holds SOC 2 Type II certification, is the only AI-native ASPM on Spain's CPSTIC LINCE pathway (Q3 2026 target), and is a reference customer of Spain's Centro Criptológico Nacional (CCN).
The product surface spans AI Code Security (for code generated by Cursor, Copilot, Claude, Devin, Windsurf, Replit, Codex, Lovable, v0), ASPM as the central posture module, CSPM for AWS/Azure/GCP, and Container Security. Distribution is delivered through a GitHub App, Plexalyzer Action on GitHub Marketplace, IDE plugins for Cursor/VS Code/JetBrains, a Bun-built CLI, and a Microsoft Marketplace listing. Customer monetisation runs on a freemium-to-subscription model: a free tier with unlimited developers, a standard paid tier at €269/month annual with unlimited developers and repositories, Professional and Enterprise tiers with email/priority/24-7 support, and custom enterprise contracts — combined with inside sales, enterprise field sales, and self-hosted/air-gap deployment options.
The company is privately held, has 11–50 employees, and has raised approximately $317K across two early rounds (including a $117,465 round in July 2025 led by Startup Wise Guys). Named customers and partners include Prowler, HuMaIND, Puffin Security, Ontinet, Devtia, Quasar Cybersecurity, Wandari, Ironchip, Telefonica, Deloitte, Oesia, Barbara, Overxet, Soluciones480, and Vigsecdrone — predominantly small security vendors, agencies, and EU public-sector adjacent buyers.
Plexicus firmographics
Firmographics- Name
- Plexicus
- Legal name
- Plexicus S.L.
- Website
- https://www.plexicus.ai
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Plexicus is an AI-native ASPM and Vibe Coding Security platform, built in Bilbao, that autonomously scans, filters, fixes, pentests, and explains vulnerabilities in AI-generated and legacy code for European enterprises, security vendors, and AI-coding teams.
- Ownership category
- akta.pro rank
Plexicus industry classification
Industry- Product category
- Application Security Posture Management (ASPM)
- NAICS
- Computer Systems Design Services (541512)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industry
- Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA)
Keywords
Where Plexicus is headquartered
LocationHeadquarters
- HQ city
- Bilbao
- HQ country
- Spain
- HQ region
- Europe
Offices2 records
Markets served
Plexicus business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription - SaaS Platform: Annual subscription model at €269/month (billed annually) offering unlimited developers and unlimited repositories. No per-seat pricing. Includes fair-use AI actions for remediation and analysis.
- Enterprise Custom Plans: Custom enterprise tier with dedicated support, 24/7 support, dedicated account manager, custom SLA, and on-site training options
- Professional Plan: Mid-tier plan with email support offering response within 24 hours, technical assistance, and feature requests
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Free | Free tier - Real free tier, unlimited developers |
| Subscription | Monthly | Professional Plan - Email support with 24h response |
| Subscription | Monthly | Enterprise Plan - Priority support with dedicated engineer |
| Subscription | Multi-year contract | Custom Plan - 24/7 support with dedicated account manager |
| Subscription | Annual | Standard paid tier - €269/month annual |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels11 records
Plexicus product offering
Product offeringCore offering
Plexicus is an AI-native Application Security Posture Management (ASPM) platform that combines SAST, SCA, secrets detection, IaC analysis, and cloud/container security with AI-powered auto-remediation. Its Codex Remedium agent generates reviewer-ready fix pull requests in under 60 seconds, while Phase-0 AI filtering strips false positives before they reach human queues. The platform operates through a five-stage autonomous loop — scan, filter, fix, pentest, understand — and is built primarily for teams shipping AI-generated code.
Product overview
Plexicus is an AI-native ASPM (Application Security Posture Management) platform that combines application security, cloud security, and container security in a unified offering. The platform operates through five autonomous stages: scan, filter, fix, pentest, and understand. The core product portfolio consists of AI Code Security (for securing AI-generated code from tools like Cursor, Copilot, Claude, Devin, Windsurf, Replit, Codex, Lovable, and v0), ASPM as the central posture management module, CSPM for multi-cloud security across AWS/Azure/GCP, and Container Security for container vulnerability detection. Additional developer tools include the Plexicus CLI (terminal-based TUI), Plexalyzer Action (GitHub Action), and IDE plugins for Cursor, VS Code, and JetBrains. A free tier is available via the Free Vibe Coding Security Scan. The platform is incorporated in Bilbao, Spain with EU data residency and SOC 2 Type II certification.
Differentiator
Problem solved
Functional benefit
Brands
- Plexalyzer Action: GitHub Action runner for automated security scanning and remediation
Products and services
- AI Code Security
Quantifiable outcome
- 45% of AI-generated code ships with security flaws - Plexicus addresses this core problem
- +5 more outcomes
Companies that use Plexicus
Customer profileNamed customers8 records
Segments14 records
Ideal customer profiles3 records
Plexicus technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration22 records
AI capability4 records
Feature7 records
Plexicus partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- TelefonicacoreTelefonica logo appears in pioneering teams section, suggesting integration or customer partnership for telecommunications security solutions.
- IronchipcoreJose Fernando Dominguez, CISO at Ironchip, provided testimonial praising Plexicus's powerful vulnerability management for delivering advanced cybersecurity services.
- ProwlercoreToni de la Fuente, Founder of Prowler, provided testimonial calling Plexicus the most innovative AI-native remediation platform and noting category-defining pace of AI-powered fix automation.
- DeloittecoreDeloitte logo appears in trusted teams section, indicating partnership for enterprise security consulting and integration services.
- WandaricoreAlejandro Acosta, CTO at Wandari, provided testimonial praising Plexicus as the most innovative AI-native remediation platform.
Scale indicators13 records
Recent moves6 records
Expansion highlights6 records
Plexicus competitors and assessment
Company assessmentDirect peers
- Mend (formerly WhiteSource): Mend focuses on SCA and application security and is named in Plexicus's comparison roster. It competes for the same AppSec tooling budget with a more mature enterprise channel.
- Semgrep: Semgrep is a developer-first SAST platform with an open-source core and Code/Supply Chain/Guardrails products. It directly overlaps Plexicus's SAST/SCA capabilities and is named in Plexicus's comparison pages.
- Sonar (SonarQube): Sonar (SonarQube/SonarCloud) is a code quality and security platform widely embedded in CI pipelines. Plexicus competes against SonarQube for SAST-adjacent budgets in engineering organizations.
- Checkmarx: Checkmarx is an established enterprise SAST/ASPM platform. Plexicus explicitly publishes comparison pages against Checkmarx and competes for the same AppSec budget with a newer, AI-native angle.
- Veracode: Veracode is a long-standing SAST/ASPM incumbent serving large enterprises. It competes with Plexicus for the same application security budget and is similarly extending into AI-assisted remediation.
- Snyk: Snyk is the closest direct peer — a developer-first security platform spanning SAST, SCA, IaC, and container security with a PLG motion and per-seat/team pricing. Plexicus competes head-on against Snyk in SAST/SCA while attempting to differentiate on AI-native auto-remediation.
Emerging players
- Aikido Security: Aikido Security is an emerging ASPM vendor bundling SAST, SCA, DAST, and cloud security with a similar PLG flavor. It is the closest in stage and shape to Plexicus in the ASPM category.
- Apiiro: Apiiro is a code-to-cloud ASPM platform that pioneered risk-graph approaches to application security. It overlaps Plexicus's ASPM and code-to-risk-mapping capabilities at the enterprise tier.
Broad incumbents
- Wiz: Wiz leads the cloud security platform category and is expanding into ASPM with code-to-cloud correlation. It competes with Plexicus's CSPM and ASPM modules from a much larger enterprise footprint.
- GitHub Advanced Security: GitHub Advanced Security (GHAS) bundles code scanning, secret scanning, and Dependabot inside the GitHub platform where Plexicus installs via GitHub App. GHAS has the distribution advantage of being native to the SCM hosting most enterprise code.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Plexicus social profiles
Digital presencePlexicus compliance and trust
Trust signalCompliance3 records
Plexicus financial estimates
Financial estimateRevenue estimate
Valuation estimate
Plexicus leadership team
Management profileNumber of profiles
Profiles1 record
Plexicus funding detail
Funding detailFunding overview
Funding rounds2 records
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Plexicus M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Plexicus
What does Plexicus do?
Plexicus is an AI-native Application Security Posture Management (ASPM) platform that combines SAST, SCA, secrets detection, IaC analysis, and cloud/container security with AI-powered auto-remediation. Its Codex Remedium agent generates reviewer-ready fix pull requests in under 60 seconds, while Phase-0 AI filtering strips false positives before they reach human queues. The platform operates through a five-stage autonomous loop — scan, filter, fix, pentest, understand — and is built primarily for teams shipping AI-generated code.
Is Plexicus a public or private company?
Plexicus is a private company. It is classified as venture growth investor backed and is currently operating.
When was Plexicus founded?
Plexicus was founded in 2025. It employs 11 to 50 people.
Where is Plexicus based?
Plexicus is headquartered in Bilbao, Spain, in the Europe region.
How does Plexicus make money?
Three revenue lines are on record. Subscription - SaaS Platform is the primary driver. The others are enterprise Custom Plans and professional Plan.
Who are Plexicus's main competitors?
Direct peers on record are Mend (formerly WhiteSource), Semgrep, Sonar (SonarQube), Checkmarx, Veracode and Snyk. Emerging players are Aikido Security and Apiiro. Broad incumbents are Wiz and GitHub Advanced Security.
Does Plexicus have an API?
Yes. Plexicus provides a CLI tool (Plexicus CLI) for terminal-based workflows, described as a single-binary TUI for browsing findings, requesting AI remediations, and opening PRs without leaving the keyboard. The CLI is built with Bun (single static binary, no runtime needed) with Vim-style keybindings, fuzzy search, and AI chat sidebar. GitHub App enables installation directly on repositories. Plexalyzer Action is available on GitHub Marketplace as a GitHub Action runner. Documentation and API reference are available at docs.plexicus.ai. Developer documentation is at docs.plexicus.ai.
What industry is Plexicus in?
Plexicus's product category is Application Security Posture Management (ASPM). Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of HDAAAKAA, Model Governance, Risk & Compliance (GRC) Platforms. Its NAICS code is 541512 and its SIC code is 7372.