Codebashing
Codebashing is a Checkmarx-owned cloud-based secure code training platform that delivers gamified, just-in-time AppSec micro-lessons to developer teams across 14+ languages, sold via enterprise subscription and a free developer tier.
- Company typePrivate
- Founded2015
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Codebashing does
Codebashing is a cloud-based secure code training platform that turns software developers into application-security ('AppSec') contributors through short, gamified, just-in-time micro-lessons. The product covers OWASP Top Ten and 30+ additional vulnerability types across 14+ programming languages (including Java, Python, Go, .NET, C++, Swift, Kotlin, Node.JS, and Ruby on Rails), and exposes a proprietary Triple-Loop Learning Methodology designed to produce lasting secure-coding habits rather than one-off knowledge transfer. Content is generated and continuously refreshed using application-security research and vulnerability data licensed from its parent company, Checkmarx, whose Checkmarx One AppSec platform Codebashing is designed to complement. The platform ships out-of-the-box integrations with Jenkins, Visual Studio, and Eclipse, plus LMS interoperability and is available on AWS Marketplace, with stated native support for both enterprise training programs and a free unlimited developer tier.
The company operates a hybrid SaaS go-to-market: a product-led growth motion through the free developer tier, paired with an enterprise subscription (annual or multi-year, quote-based) sold via Checkmarx's direct field-sales organization targeting CISOs, security teams, and dev-team leads. Pricing is not publicly disclosed; the customer base of 800+ enterprises and named logos including Apple, NASA, Tesla, Mastercard, NASDAQ, Sony, Mercedes-Benz, Target, Disney, KPMG, and Capgemini indicates a heavy concentration in Fortune-grade enterprises across financial services, automotive, retail, government, and technology verticals. Operationally, Codebashing is a wholly owned subsidiary of Checkmarx, headquartered on the Checkmarx campus in Ramat Gan, Israel (with a registered office in London and a sales/customer-engagement presence in Atlanta, USA), led by General Manager Ramon Herzlinger. It carries 1–10 direct employees per firmographic data, suggesting heavy reliance on shared parent-company resources for sales, marketing, and platform operations.
Revenue mechanics are enterprise subscription-led with a freemium conversion funnel. The company discloses no revenue, ARR, or pricing benchmarks in any source; the only quantified commercial signals are customer-outcome metrics (e.g., 104 hours saved per developer per year, 1.7 million EUR annual productivity savings at a European financial-services institution). No external funding rounds have been recorded after a small 2015–2016 CyLon Ventures-era raise, consistent with funding being absorbed and growth being funded by parent Checkmarx post-acquisition.
Codebashing firmographics
Firmographics- Name
- Codebashing
- Legal name
- Codebashing Ltd.
- Website
- https://codebashing.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Codebashing is a Checkmarx-owned cloud-based secure code training platform that delivers gamified, just-in-time AppSec micro-lessons to developer teams across 14+ languages, sold via enterprise subscription and a free developer tier.
- Ownership category
- akta.pro rank
Codebashing industry classification
Industry- Product category
- Application Security Training
- NAICS
- Computer Training (61142), Business Schools and Computer and Management Training (6114), Professional and Management Development Training (611430)
- SIC
- Services-Educational Services (8200), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
- akta.pro secondary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where Codebashing is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Codebashing business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Subscription-based SaaS Training: Annual or multi-year subscription model providing access to the full Codebashing secure code training platform, including all learning paths, certifications, and administrative dashboards for tracking team progress.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Developer Access |
| Subscription | Annual | Enterprise Subscription |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
Codebashing product offering
Product offeringCore offering
Codebashing provides a cloud-based secure code training e-learning platform that enables enterprise development teams to learn, refresh, and validate application security knowledge. The platform delivers gamified, just-in-time 5-minute lessons covering the OWASP Top Ten and 20+ vulnerability types across 14+ programming languages (Java, Go, .NET, PHP, Python, Scala, C, Swift UI, Ruby on Rails, Kotlin, Node.JS, C++, Android, iOS), paired with Basic, Advanced, and Expert certifications. It integrates directly with developer tools such as Jenkins, Visual Studio, and Eclipse, and supports organizational secure code adoption through predefined learning paths, team progress dashboards, tournaments, and weekly challenges.
Product overview
Codebashing is a unified secure code training platform that turns developers into AppSec champions. The platform offers a comprehensive learning experience with predefined learning paths in specialist security fields and programming languages, gamified just-in-time lessons, an always-updated training library, certifications (Basic, Advanced, Expert), personalized courses, live tournaments, and weekly challenges. Content covers the OWASP Top Ten and 30+ vulnerability types including SQL Injection, XSS, Command Injection, and more. The platform integrates with developer tools like Jenkins, Visual Studio, and Eclipse, and is available for purchase directly or through AWS Marketplace.
Differentiator
Problem solved
Functional benefit
Products and services
- Codebashing Platform A unified developer-focused secure code training SaaS platform offering gamified, just-in-time learning experiences to help software developers write secure code from the first line. The platform provides predefined learning paths, certifications at Basic, Advanced, and Expert levels, live tournaments, weekly challenges, manager dashboards for team progress, and coverage of the OWASP Top Ten and 20+ vulnerability types across multiple programming languages. Targeted at enterprise development teams, security champions, CISOs, and security team leads in industries such as banking, automotive, insurance, retail, e-commerce, technology, government, and professional services.
Quantifiable outcome
- 104 hours saved per developer per year in vulnerable code rewrites
- +3 more outcomes
Companies that use Codebashing
Customer profileNamed customers18 records
Segments1 record
Ideal customer profiles1 record
Codebashing technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability2 records
Feature7 records
Codebashing partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- CheckmarxcoreCodebashing is a Checkmarx company, powered by Checkmarx's AppSec platform Checkmarx One. The partnership provides access to Checkmarx's 17+ years of AppSec research, global vulnerability data, and comprehensive platform resources. Codebashing is designed to work seamlessly with other Checkmarx products including Checkmarx AST platform. Sandeep Johri, Checkmarx CEO, leads the company and Ramon Herzlinger serves as General Manager.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
Codebashing competitors and assessment
Company assessmentBroad incumbents
- Veracode: Established AppSec vendor offering SAST, DAST, and SCA alongside a developer eLearning curriculum. Competes with Codebashing on the training portion of enterprise AppSec deals, especially when bundled with testing tools.
- Pluralsight: Large-scale technology skills platform offering cloud, DevOps, and security content including secure coding paths. Competes for the same corporate L&D and developer upskilling budgets as Codebashing.
- Snyk: Developer-first security platform with SAST/SCA/IaC products and Snyk Learn for secure coding education. Competes with Codebashing for the developer-security training budget within the same buyer accounts.
- Synopsys (Software Integrity Group): Major AppSec testing vendor with a Secure Coding and Education portfolio; competes with Codebashing particularly in large enterprise and government accounts already using Synopsys AST tools.
Emerging players
- HackerRank: Developer skills assessment and learning platform increasingly used for hiring and upskilling. Adjacent rather than directly competing, but increasingly overlaps with Codebashing on coding skill benchmarking and team-based training.
Direct peers
- Secure Code Warrior: The most direct competitor in developer-focused secure code training, offering a gamified platform with language-specific learning paths, tournaments, and integration into developer workflows — overlapping almost entirely with Codebashing's value proposition.
- Immersive Labs: Enterprise cybersecurity skills platform with hands-on labs and exercises covering secure development and application security, serving a similar Fortune 500 buyer as Codebashing.
- Cybrary: Cybersecurity skills and certification training platform serving both individual practitioners and enterprise teams, with secure development content overlapping Codebashing's curriculum for engineering audiences.
- Security Journey: Specialist security education provider for developers and engineering teams with role-based learning paths and hands-on labs; competes head-to-head with Codebashing in the AppSec awareness and secure coding training category.
- AppSecEngineer (WeCP): Hands-on, cloud-based secure coding and AppSec training platform targeting enterprise engineering teams, with labs across multiple languages and vulnerability categories — a direct functional alternative to Codebashing.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Codebashing social profiles
Digital presenceCodebashing financial estimates
Financial estimateRevenue estimate
Valuation estimate
Codebashing leadership team
Management profileNumber of profiles
Profiles1 record
Codebashing funding detail
Funding detailFunding overview
Funding rounds2 records
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Codebashing M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Codebashing
What does Codebashing do?
Codebashing provides a cloud-based secure code training e-learning platform that enables enterprise development teams to learn, refresh, and validate application security knowledge. The platform delivers gamified, just-in-time 5-minute lessons covering the OWASP Top Ten and 20+ vulnerability types across 14+ programming languages (Java, Go, .NET, PHP, Python, Scala, C, Swift UI, Ruby on Rails, Kotlin, Node.JS, C++, Android, iOS), paired with Basic, Advanced, and Expert certifications. It integrates directly with developer tools such as Jenkins, Visual Studio, and Eclipse, and supports organizational secure code adoption through predefined learning paths, team progress dashboards, tournaments, and weekly challenges.
Is Codebashing a public or private company?
Codebashing is a private company. It is classified as corporate owned and is currently operating.
When was Codebashing founded?
Codebashing was founded in 2015. It employs 1 to 10 people.
Where is Codebashing based?
Codebashing is headquartered in London, United Kingdom, in the Europe region.
How does Codebashing make money?
One revenue line is on record: subscription-based SaaS Training.
Who are Codebashing's main competitors?
Broad incumbents on record are Veracode, Pluralsight, Snyk and Synopsys (Software Integrity Group). HackerRank is listed as an emerging player. Direct peers are Secure Code Warrior, Immersive Labs, Cybrary, Security Journey and AppSecEngineer (WeCP).
Does Codebashing have an API?
No public API is recorded for Codebashing.
What industry is Codebashing in?
Codebashing's product category is Application Security Training. Its primary akta.pro industry code is EDABAGAN, Secure Software & DevOps Awareness (Secure Coding Basics), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 61142 and its SIC code is 8200.