Mayhem
Mayhem Security (formerly ForAllSecure) provides AI-powered automated security testing for application code, APIs, and software supply chains, serving enterprise and government customers in aerospace, automotive, federal, and healthcare with compliance-focused fuzzing and symbolic execution.
- Company typePrivate
- Founded2012
- HeadquartersPittsburgh, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Mayhem does
Mayhem Security (operating company ForAllSecure Inc., formerly known as ForAllSecure until a October 2024 rebrand) is a Pittsburgh-based security testing software vendor founded in 2012 by Carnegie Mellon professor David Brumley. The company offers an AI-powered automated security testing platform that combines fuzz testing, a native symbolic execution engine, and generative AI to identify and prove vulnerabilities across application code, APIs, and software supply chains, with a stated goal of delivering zero false positives through proof-of-vulnerability generation.
The product surface is organized into three offerings: Mayhem for Code (AI-powered fuzzing, symbolic execution, and intelligent triage), Mayhem for API (stateful, agentless, differential API pentesting against OWASP Top 10 API weaknesses), and Mayhem Dynamic SBOM (reachability-based SBOM noise reduction of 60-90%). The platform is delivered as a cloud service, integrates natively with the major CI/CD systems (GitHub Actions, Jenkins, GitLab, CircleCI, Azure DevOps, Travis CI), and emits vendor-neutral SARIF reports. Target customers are enterprise organizations in regulated verticals including aerospace (ED-203A/DO-356A), automotive (ISO 21434, UN 155/6, ISO 26262), federal and defense (NIST SSDF, EO 14028), and medical and healthcare (FDA/MDA guidance). Named enterprise and government logos include Cloudflare, Roblox, Roche, Deloitte, Motional, Rivian, and the U.S. Department of Defense.
Mayhem operates a hybrid go-to-market combining product-led growth (30-day free evaluation, self-service onboarding via CLI and API tokens) with enterprise field sales for regulated-industry and federal deployments. Revenue is generated through annual subscriptions on a tiered Account model with usage-based limits on Authorized Cores (Mayhem for Code) and Authorized Developers/Scans (Mayhem for API); pricing is not publicly disclosed. The company was acquired by Bugcrowd in November 2025 and now operates as a subsidiary within the Bugcrowd platform.
Mayhem firmographics
Firmographics- Name
- Mayhem
- Legal name
- ForAllSecure Inc.
- Website
- https://mayhem.security
- Company type
- Private
- Founded year
- 2012
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Mayhem Security (formerly ForAllSecure) provides AI-powered automated security testing for application code, APIs, and software supply chains, serving enterprise and government customers in aerospace, automotive, federal, and healthcare with compliance-focused fuzzing and symbolic execution.
- Ownership category
- akta.pro rank
Mayhem industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Security Analytics & Detection Engineering (HDADAGAE)
Keywords
Where Mayhem is headquartered
LocationHeadquarters
- HQ city
- Pittsburgh
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Mayhem business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales
Revenue model
- Cloud Services Subscription: ForAllSecure provides cloud-based security testing services under a subscription model with Account Tiers (Basic, Pro, Enterprise). Fees are based on Authorized Cores for Mayhem for Code and Authorized Developers/Scans for Mayhem for API. Subscriptions auto-renew annually.
- Mayhem for API - Scan-Based Limits: Mayhem for API is limited by Authorized Developer counts and Authorized Scan limits based on selected Account Tier.
- Mayhem for Code - Core-Based Limits: Mayhem for Code usage is limited by the number of Authorized Cores on which the service may be used per selected Account Tier.
- Evaluation/Trial License: Free 30-day evaluation licenses available for customers to trial the Cloud Services before committing to a paid Account Tier.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Account Tier-based subscription with varying Authorized Cores, Developers, and Scan limits |
| Freemium | Pay-as-you-go | Free 30-day evaluation available for all tiers |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
Mayhem product offering
Product offeringCore offering
Mayhem Security provides an AI-powered automated application security testing platform combining fuzz testing, symbolic execution, and generative AI to identify vulnerabilities in code, APIs, and software supply chains. The platform delivers zero false positives by generating proof-of-vulnerability for every defect and offers three core products: Mayhem for Code, Mayhem for API, and Mayhem Dynamic SBOM. It integrates directly into CI/CD pipelines to enable continuous security testing across the software development lifecycle.
Product overview
Mayhem Security is an automated code and API security testing platform built by hackers and powered by AI. The company offers three core products: Mayhem for Code (fuzz testing and symbolic execution for application security), Mayhem for API (continuous API pentesting), and Dynamic SBOM (SBOM noise reduction). The platform provides a unified dashboard for dynamic code, API, and SBOM security testing with vendor-neutral SARIF reports. Mayhem was acquired by Bugcrowd in November 2025.
Differentiator
Problem solved
Functional benefit
Products and services
- Mayhem for Code (Code Security) AI-powered code security testing platform that uses fuzz testing, symbolic execution, and intelligent triage to find vulnerabilities in applications. Generates proof of vulnerability for every defect, delivering zero false positives. Supports 11+ programming languages including C/C++, Go, Rust, Java, Python, and Ada, and integrates with GitHub, Jenkins, GitLab, CircleCI, Azure DevOps, and Travis CI.
- Mayhem for API (API Security) Continuous API security testing platform that validates and verifies APIs for OWASP Top 10 weaknesses using differential comparison, stateful, and agentless testing. Automates API pentesting with behavioral analysis at scale, designed for engineering and security teams running production APIs.
- Mayhem Dynamic SBOM Software Bill of Materials analysis tool that reduces SBOM/SCA noise by 60-90% through reachability analysis, identifying only exploitable vulnerabilities in the actual attack surface. Helps security and compliance teams cut through alert fatigue from traditional SBOM and software composition analysis tools.
Quantifiable outcome
- Up to 90% reduction in security alert volume through Dynamic SBOM false positive filtering
- +3 more outcomes
Companies that use Mayhem
Customer profileNamed customers7 records
Segments5 records
Ideal customer profiles3 records
Mayhem technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability5 records
Feature6 records
Mayhem partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- BugcrowdcoreBugcrowd acquired Mayhem Security in November 2025 to enhance its security testing platform with AI automation and human hacker community expertise. The acquisition aims to provide continuous, proactive vulnerability detection and remediation across the software development lifecycle.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
Mayhem competitors and assessment
Company assessmentDirect peers
- Veracode: Veracode offers SAST, DAST, and SCA application security testing targeted at enterprises in regulated industries. It competes head-to-head with Mayhem in aerospace, automotive, medical, and federal verticals where compliance frameworks overlap.
- Snyk: Snyk is a developer security platform offering SAST, SCA, IaC, and container security with native CI/CD integrations. It directly competes with Mayhem's code and SBOM testing in the same PLG/enterprise hybrid motion targeting engineering teams.
- Contrast Security: Contrast Security offers runtime application security (IAST/RASP) and API security testing. It overlaps with Mayhem's API security and behavioral testing capabilities, particularly for enterprise web applications.
- Checkmarx: Checkmarx provides SAST, SCA, and IaC security scanning for enterprises, with deep CI/CD integration. It is a direct incumbent competitor to Mayhem's code security and Dynamic SBOM offerings in regulated industries.
- CodeQL (GitHub): CodeQL is GitHub's semantic code analysis engine for security vulnerabilities, with deep integrations across the GitHub ecosystem. It is a direct SAST competitor that benefits from default-on distribution in repositories.
- Semgrep: Semgrep offers code static analysis with a developer-first, open-source-rooted approach and CI/CD integrations. It is a direct competitor to Mayhem for Code in the PLG-driven enterprise segment.
- Salt Security: Salt Security focuses on API security posture management and runtime API threat detection. It is a direct competitor to Mayhem for API in the OWASP Top 10 API testing category.
Emerging players
- Apiiro: Apiiro provides code-to-cloud application security risk analysis with ASPM capabilities. It is an emerging player overlapping with Mayhem's code risk and SBOM reachability narratives.
Broad incumbents
- GitHub Advanced Security: GitHub Advanced Security bundles CodeQL SAST, Dependabot SCA, and secret scanning natively into GitHub workflows. It is a broad incumbent default-on alternative to Mayhem's developer-integrated testing for any organization using GitHub.
- Synopsys (Code Sight / Coverity): Synopsys offers Coverity and Code Sight static analysis alongside a broader EDA/semiconductor portfolio. It is a broad incumbent in application security testing serving many of the same regulated enterprise accounts as Mayhem.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key highlights6 records
Customer concentration
Mayhem social profiles
Digital presenceMayhem compliance and trust
Trust signalCompliance7 records
Mayhem financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mayhem leadership team
Management profileNumber of profiles
Profiles2 records
Mayhem funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mayhem M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mayhem
What does Mayhem do?
Mayhem Security provides an AI-powered automated application security testing platform combining fuzz testing, symbolic execution, and generative AI to identify vulnerabilities in code, APIs, and software supply chains. The platform delivers zero false positives by generating proof-of-vulnerability for every defect and offers three core products: Mayhem for Code, Mayhem for API, and Mayhem Dynamic SBOM. It integrates directly into CI/CD pipelines to enable continuous security testing across the software development lifecycle.
Is Mayhem a public or private company?
Mayhem is a private company. It is classified as venture growth investor backed and is currently acquired.
When was Mayhem founded?
Mayhem was founded in 2012. It employs 11 to 50 people.
Where is Mayhem based?
Mayhem is headquartered in Pittsburgh, United States, in the North America region.
How does Mayhem make money?
Four revenue lines are on record. Cloud Services Subscription is the primary driver. The others are mayhem for API - Scan-Based Limits, mayhem for Code - Core-Based Limits and evaluation/Trial License.
Who are Mayhem's main competitors?
Direct peers on record are Veracode, Snyk, Contrast Security, Checkmarx, CodeQL (GitHub), Semgrep and Salt Security. Apiiro is listed as an emerging player. Broad incumbents are GitHub Advanced Security and Synopsys (Code Sight / Coverity).
Does Mayhem have an API?
Yes. Mayhem provides a CLI-based API for programmatic access to its security testing platform. Users can generate API tokens to authenticate and interact with the platform, run security scans, and retrieve results. The API supports integration with CI/CD pipelines and accepts OpenAPI specifications for API testing. Developer documentation is at docs.mayhem.security.
What industry is Mayhem in?
Mayhem's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5415 and its SIC code is 7372.