Bearer
Bearer is a developer-first SAST company (acquired by Cycode) offering an open-source CLI and commercial cloud platform that scan source code for security vulnerabilities and sensitive data flows, serving security leaders and engineering teams at enterprises.
- Company typePrivate
- Founded2018
- HeadquartersCambridge, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Bearer does
Bearer is a developer-first Static Application Security Testing (SAST) company that helps security and engineering teams identify vulnerabilities and sensitive data exposures in source code. Its product line consists of two offerings: Bearer CLI, a free and open-source SAST engine written in Go that performs static code analysis and tracks sensitive data flows (PII, PHI, etc.) across applications; and Bearer Cloud, a commercial SaaS platform that extends the CLI with enterprise features such as a native GitHub App with in-pull-request AI remediation suggestions, false-positive management, and centralized reporting. The engine supports 10+ programming languages (including Java, Python, Ruby, JavaScript, TypeScript, PHP, Go, Kotlin, Elixir, and VB.Net), ships with 473+ security rules aligned to OWASP Top 10 and CWE Top 25, detects 122 data types, and ships a recipes library of 400+ third-party API/service detections.
The company sells to a hybrid set of buyers, primarily CISOs/security leaders, product security teams, and software engineering teams, with additional traction in regulated verticals (healthcare, fintech, crypto). Its go-to-market is product-led and community-led: Bearer CLI is distributed free via GitHub for self-serve developer adoption, while Bearer Cloud is sold through enterprise direct sales with quote-based pricing and deep CI/CD integrations (GitHub, GitLab, BitBucket, Jenkins, CircleCI). The company was founded in 2018 by Guillaume Montard (CEO) and Cédric Fabianski (CTO), raised approximately $11.6M in total outside capital (notably an $8M seed round in October 2022 led by Alven), and was acquired by Cycode in 2024–2025, where it now operates as a product line within Cycode's Application Security Posture Management (ASPM) platform. Named customers include Shopify, Datadog, Databricks, Kraken, Doctolib, Eventbrite, Catawiki, and Typeface.
Bearer firmographics
Firmographics- Name
- Bearer
- Legal name
- Bearer Inc.
- Website
- https://bearer.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Bearer is a developer-first SAST company (acquired by Cycode) offering an open-source CLI and commercial cloud platform that scan source code for security vulnerabilities and sensitive data flows, serving security leaders and engineering teams at enterprises.
- Ownership category
- akta.pro rank
Bearer industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Custom Computer Programming Services (541511)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Bearer is headquartered
LocationHeadquarters
- HQ city
- Cambridge
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Bearer business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Bearer Cloud: Commercial SaaS platform offering cloud-based code security scanning at scale with additional enterprise features beyond the free CLI.
- Bearer CLI (Open Source): Free and open-source SAST engine available on GitHub, serving as the primary developer acquisition channel.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Bearer CLI - Free and open source SAST tool |
| Subscription | Annual | Bearer Cloud - Enterprise code security platform |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Bearer product offering
Product offeringCore offering
Bearer provides developer-first static application security testing (SAST) tools that scan source code to detect security vulnerabilities and sensitive data flows (PII, PHI). It operates two products: Bearer CLI, a free open-source SAST engine for individual developers and small teams, and Bearer Cloud, a commercial SaaS platform that scales code security scanning with GitHub, GitLab, and BitBucket integrations and AI-powered remediation suggestions for enterprise customers.
Product overview
Bearer offers a developer-first SAST (Static Application Security Testing) solution consisting of two core products: Bearer Cloud (commercial SaaS platform for enterprise code security at scale) and Bearer CLI (free, open-source SAST engine). Bearer CLI provides the foundational static analysis engine that scans source code across multiple programming languages (Go, Python, PHP, JavaScript, TypeScript, Ruby, Java, C#, Kotlin, Elixir, VB.Net) to discover security risks and privacy concerns. Bearer Cloud extends this capability with a cloud-based platform featuring GitHub App integration with AI-powered remediation suggestions and false positive management, enabling enterprises to manage security risks at the earliest stage of development. The company was acquired by Cycode in 2025, becoming part of the complete Application Security Posture Management (ASPM) platform.
Differentiator
Problem solved
Functional benefit
Brands
- Bearer CLI: Free and open-source SAST engine for code security scanning
- Bearer Cloud
Products and services
- Bearer Cloud Bearer Cloud is a commercial SaaS platform providing code security at scale, enabling enterprises to detect and prioritize application security risks and sensitive data exposures through GitHub, GitLab, and BitBucket integrations, with AI-powered in-PR remediation suggestions and false positive management.
- Bearer CLI Bearer CLI is a free, open-source static application security testing (SAST) engine that scans source code across multiple programming languages and analyzes data flows to discover, filter, and prioritize security and privacy risks. It is targeted at individual developers, engineering teams, and small teams for self-service adoption.
Quantifiable outcome
- Deploy in minutes with CI/CD integration
- +2 more outcomes
Companies that use Bearer
Customer profileNamed customers8 records
Segments4 records
Ideal customer profiles3 records
Bearer technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability2 records
Feature5 records
Bearer partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and supporting.
- CycodecoreBearer has been acquired by Cycode, the complete Application Security Posture Management (ASPM) platform. This acquisition enables the combined entity to deliver the industry's most complete ASPM solution with the mission to deliver safe code, faster.
- GitHubcoreNative integration with GitHub for code security scanning directly in pull requests, including AI remediation suggestions and false positive management.
- GitLabcoreIntegration with GitLab for security scanning in CI/CD pipelines and merge requests.
- BitbucketcoreIntegration with Bitbucket for security scanning in pull requests and pipelines.
- JenkinssupportingCI/CD integration with Jenkins for automated security scanning in build pipelines.
- Circle CIsupportingCI/CD integration with CircleCI for automated security scanning in continuous integration workflows.
- JirasupportingIntegration with Jira for tracking and managing security findings as tickets.
- SlacksupportingIntegration with Slack for notifications and alerts on security findings.
- DefectDojosupportingIntegration with DefectDojo for vulnerability management and security finding aggregation.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
Bearer competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first security platform offering SAST, SCA, and IaC scanning to enterprise engineering teams — directly competes with Bearer Cloud on shift-left application security.
- Mend (formerly WhiteSource): Application security platform combining SAST, SCA, and container security — competes with Bearer for enterprise AppSec consolidation deals.
- Sonar (SonarQube): Code quality and security platform with open-source SonarQube and commercial SonarCloud — overlaps Bearer's static analysis and developer-workflow positioning.
- Semgrep: Open-source SAST engine with commercial Code/Supply Chain products targeting the same developer-first workflow as Bearer CLI and Cloud.
Broad incumbents
- Veracode: Long-standing enterprise AppSec vendor with SAST, DAST, and software composition analysis — competes with Bearer for enterprise security budget.
- GitLab: Integrated DevSecOps platform with built-in SAST, DAST, and container scanning — competes with Bearer as a default platform-level alternative.
- Checkmarx: Established enterprise application security testing platform offering SAST, SCA, and IAST — competes with Bearer in larger enterprises with broader suites.
- GitHub Advanced Security: Native code scanning, secret scanning, and dependency review built into GitHub — the most direct free/bundled alternative to Bearer for GitHub-centric teams.
Others
- Cycode: Application Security Posture Management (ASPM) platform and Bearer's acquirer; directly comparable as the parent platform now distributing Bearer's technology.
Emerging players
- Aikido Security: Developer-first all-in-one security platform with SAST, SCA, and cloud security — emerging competitor targeting the same shift-left developer audience as Bearer.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Bearer social profiles
Digital presenceBearer financial estimates
Financial estimateRevenue estimate
Valuation estimate
Bearer leadership team
Management profileNumber of profiles
Profiles2 records
Bearer funding detail
Funding detailFunding overview
Funding rounds3 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Bearer M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Bearer
What does Bearer do?
Bearer provides developer-first static application security testing (SAST) tools that scan source code to detect security vulnerabilities and sensitive data flows (PII, PHI). It operates two products: Bearer CLI, a free open-source SAST engine for individual developers and small teams, and Bearer Cloud, a commercial SaaS platform that scales code security scanning with GitHub, GitLab, and BitBucket integrations and AI-powered remediation suggestions for enterprise customers.
Is Bearer a public or private company?
Bearer is a private company. It is classified as corporate owned and is currently acquired.
When was Bearer founded?
Bearer was founded in 2018. It employs 11 to 50 people.
Where is Bearer based?
Bearer is headquartered in Cambridge, United States, in the North America region.
How does Bearer make money?
Two revenue lines are on record. Bearer Cloud is the primary driver. The others are bearer CLI (Open Source).
Who are Bearer's main competitors?
Direct peers on record are Snyk, Mend (formerly WhiteSource), Sonar (SonarQube) and Semgrep. Broad incumbents are Veracode, GitLab, Checkmarx and GitHub Advanced Security. Cycode is listed as an others. Aikido Security is listed as an emerging player.
Does Bearer have an API?
No public API is recorded for Bearer.
What industry is Bearer in?
Bearer's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 541511 and its SIC code is 7371.