Security Journey
Security Journey is a private SaaS company that delivers secure coding training and application security education to enterprise software development teams through a subscription-based platform with AI-assisted guardrails, compliance reporting, and developer engagement tools.
- Company typePrivate
- Founded2016
- HeadquartersPittsburgh, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Security Journey does
Security Journey, operated as a brand under the legal entity HackEDU, Inc. (following a 2022 merger between Security Journey and HackEDU), is a privately held application security education company headquartered in Pittsburgh, PA, with additional offices in Raleigh, NC and Charlotte, NC. The company delivers a SaaS-based AppSec Education Platform that provides secure coding training to enterprise software development teams, with named enterprise customers including HackerOne, Zoom, and Optimal Workshop. The platform spans five interconnected modules: a Training Library of 800+ lessons across 40+ programming languages and frameworks; Program Administration for learner management, automated assignments, and compliance reporting; Developer Insights incorporating Developer Profiles, Security Knowledge Assessments, and Aspen: Adapt for personalization; Developer Engagement featuring tournaments, leaderboards, and the Security Champion Passport; and Aspen: Guardian AI, an autonomous guardrail system that uses real scanner findings to prevent AI coding assistants from generating insecure patterns.
The company operates an enterprise sales-led go-to-market motion targeting CISOs, VPs of Engineering, and AppSec program managers, supplemented by a reseller channel and a self-serve trial option. Revenue is generated through annual subscription contracts on a per-user licensing basis with volume discounts, supported by SOC 2 Type 2 compliance and alignment with PCI-DSS 4.0 Requirements 6.2.2-6.2.4, NIST SSDF, and OWASP Top 10 standards. The platform is positioned for the AI-assisted development era, with a February 2026 platform reimagination introducing the Developer Manifesto framework, an AI-Readiness Assessment, and GitHub integration for CWE detection in real code commits. Marketing channels include the Security Champions Podcast, blog content, RSA Conference presence, and the annual Security Champions Summit, which drew 500+ registrants from 30 countries in 2025.
Security Journey firmographics
Firmographics- Name
- Security Journey
- Legal name
- HackEDU, Inc.
- Website
- https://securityjourney.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Security Journey is a private SaaS company that delivers secure coding training and application security education to enterprise software development teams through a subscription-based platform with AI-assisted guardrails, compliance reporting, and developer engagement tools.
- Ownership category
- akta.pro rank
Security Journey industry classification
Industry- Product category
- Application Security Training Software
- NAICS
- Computer Training (611420), Professional and Management Development Training (611430)
- SIC
- Services-Prepackaged Software (7372), Services-Educational Services (8200)
- akta.pro primary industry
- Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
- akta.pro secondary industries
- Application Security & Secure Software (DevSecOps) (EDAOAIAK), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI), Application Security & DevSecOps Services (BPAKAHAJ), Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF)
Keywords
Where Security Journey is headquartered
LocationHeadquarters
- HQ city
- Pittsburgh
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Security Journey business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Subscription-based Software Services: Limited, non-exclusive, non-transferable, worldwide right to access and use the Services on a per-User basis during a defined Subscription Period. Renews automatically unless terminated with 30 days notice. Fees invoiced in U.S. dollars with Net 30 payment terms.
- Per-Seat Licensing: Per-user licensing model where each authorized individual receives a unique identifier that cannot be transferred or reassigned. Number of users specified in Order Form. Supports enterprise-wide deployment with volume considerations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with per-user licensing |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels8 records
Security Journey product offering
Product offeringCore offering
Security Journey delivers an AppSec Education Platform that provides hands-on secure coding training to development teams through full-application sandbox environments, video lessons, and interactive assessments. The platform helps enterprises reduce software vulnerabilities through developer-first security education, with five core modules: Training Library (800+ lessons across 40+ languages), Program Administration, Developer Insights, Aspen: Guardian AI, and Developer Engagement.
Product overview
Security Journey offers an integrated AppSec Education Platform focused on secure code training for developers. The platform consists of a core ecosystem with five interconnected modules: Training Library (800+ lessons on OWASP, AI/LLM security, and secure development), Program Administration (assignment automation and reporting), Developer Insights (skills benchmarking and personalized recommendations), Aspen: Guardian AI (autonomous code guardrails for AI assistants), and Developer Engagement (tournaments, leaderboards, and Security Champion Passport). Additional specialized offerings include a PCI Compliance Learning Path aligned to PCI DSS v4.0 requirements, AI-Readiness Assessment, GitHub integration for CWE detection, and the Developer Manifesto framework. The platform personalizes learning by role and experience level, delivers content monthly, and supports compliance with PCI-DSS and NIST standards.
Differentiator
Problem solved
Functional benefit
Quantifiable outcome
- Development teams can increase their security knowledge by up to 85% through Security Journey coding lessons
- +2 more outcomes
Companies that use Security Journey
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
Security Journey technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability5 records
Feature8 records
Security Journey partnerships and signals
Strategic signalScale indicators7 records
Recent moves5 records
Expansion highlights5 records
Security Journey competitors and assessment
Company assessmentDirect peers
- OffSec (Offensive Security): OffSec is known for hands-on offensive security training (OSCP, etc.) and now enterprise learning paths. It overlaps with Security Journey on practical security skills development and shares similar buyer personas in security-aware engineering organizations.
- Hack The Box: Hack The Box delivers hands-on cybersecurity and hacking training via labs, challenges, and academies. It overlaps with Security Journey on gamified, hands-on developer security learning and shares a similar developer/hacker community positioning.
- SecureFlag: SecureFlag provides hands-on secure coding and DevSecOps training with sandbox environments and per-seat licensing. It is explicitly named in Security Journey's G2 comparison pages, indicating direct buyer overlap in the AppSec training category.
- Secure Code Warrior: Secure Code Warrior is a direct competitor offering a developer-focused secure coding training platform with hands-on labs, tournaments, and language-specific learning paths, competing head-to-head with Security Journey in the same buyer persona (AppSec leaders and developers).
- Cybrary: Cybrary is an online cybersecurity training platform offering courses, hands-on labs, and certification prep for security and development audiences. It is comparable as a subscription training provider serving AppSec-adjacent buyers.
Broad incumbents
- Pluralsight: Pluralsight (now part of Vista Equity-backed operations) provides broad technical skills training, including cybersecurity and secure-development content. It is a broader incumbent that competes for enterprise training budgets though with less depth in secure-coding-specific labs.
- KnowBe4: KnowBe4 is a broad security awareness and training incumbent that has expanded into secure-coding and compliance content. While its core is phishing/social engineering, its expansion creates overlap with Security Journey's compliance-driven training use case.
- Checkmarx: Checkmarx offers an enterprise AppSec platform (SAST, SCA, IaC) and a Checkmarx Learning product for secure-coding education. It is a broader incumbent that competes for the same AppSec program budget.
- Snyk: Snyk is a developer security platform (SCA, SAST, container, IaC) with growing investment in AI-code security and developer education. It represents a broad incumbent that could bundle secure-coding training against a standalone platform like Security Journey.
- Veracode: Veracode is a broad AppSec incumbent offering static and dynamic analysis plus eLearning/secure-coding training as part of a wider portfolio. It competes with Security Journey on the training component while leveraging a much larger scanning install base.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Security Journey social profiles
Digital presenceSecurity Journey compliance and trust
Trust signalCompliance4 records
Security Journey financial estimates
Financial estimateRevenue estimate
Valuation estimate
Security Journey leadership team
Management profileNumber of profiles
Profiles2 records
Security Journey funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Security Journey M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Security Journey
What does Security Journey do?
Security Journey delivers an AppSec Education Platform that provides hands-on secure coding training to development teams through full-application sandbox environments, video lessons, and interactive assessments. The platform helps enterprises reduce software vulnerabilities through developer-first security education, with five core modules: Training Library (800+ lessons across 40+ languages), Program Administration, Developer Insights, Aspen: Guardian AI, and Developer Engagement.
Is Security Journey a public or private company?
Security Journey is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Security Journey founded?
Security Journey was founded in 2016. It employs 11 to 50 people.
Where is Security Journey based?
Security Journey is headquartered in Pittsburgh, United States, in the North America region.
How does Security Journey make money?
Two revenue lines are on record. Subscription-based Software Services are the primary driver. The others are per-Seat Licensing.
Who are Security Journey's main competitors?
Direct peers on record are OffSec (Offensive Security), Hack The Box, SecureFlag, Secure Code Warrior and Cybrary. Broad incumbents are Pluralsight, KnowBe4, Checkmarx, Snyk and Veracode.
Does Security Journey have an API?
Yes. Security Journey provides an API that enables integrations with external systems. The API has been used by customers to build custom workflows, including a Slack workflow that announced training completions (as documented in the HackerOne case study). Admin features include APIs for user provisioning. Details on API type (REST/GraphQL), authentication method, rate limits, and public documentation URL are not specified in available sources.
What industry is Security Journey in?
Security Journey's product category is Application Security Training Software. Its primary akta.pro industry code is EDABAGAN, Secure Software & DevOps Awareness (Secure Coding Basics), with a secondary code of EDAOAIAK, Application Security & Secure Software (DevSecOps). Its NAICS code is 611420 and its SIC code is 7372.