SAFECode.org
SAFECode is a global nonprofit founded in 2007 that convenes software security leaders from major technology companies in an NDA-protected forum to publish guidance, deliver free training, and develop standards, funded by USD $10,000 annual memberships.
- Company typePrivate
- Founded2007
- HeadquartersWakefield, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What SAFECode.org does
SAFECode (Software Assurance Forum for Excellence in Code) is a global nonprofit organization founded in October 2007 and headquartered in Wakefield, Massachusetts. It operates as an industry forum in which software security leaders and practitioners from major technology companies collaborate inside an NDA-protected environment to share practices, develop guidance, and address software assurance challenges. The membership roster includes Microsoft, Adobe, Oracle, Google, Dell Technologies, Siemens Energy, and Raytheon Technologies, among others.
The organization's deliverables fall into three streams. First, published guidance documents led by the flagship Fundamental Practices for Secure Software Development and extended through more recent publications such as Threat Modeling at Scale (June 2023), guidance for the Executive Order 14028 era (February 2023), and the Secure by Design guide (October 2025). Second, a free training program comprising 18+ on-demand courses covering cryptography, threat modeling, and application security, distributed under Creative Commons to the public. Third, member-only working groups spanning DevSecOps, Post-Quantum Cryptography, Personal Data Privacy, and Fuzzing Techniques. In January 2026, the Secure by Design guide was formally adopted by ETSI as TS 104 219, the Software Security Development and Implementation Framework, mapped to EU Cyber Resilience Act and UK NCSC requirements.
SAFECode operates as a member-funded nonprofit. Annual membership dues are USD $10,000, open to any organization, granting access to working groups, the collaboration portal, and member-only brown bag sessions. All public guidance and training is provided free of charge. The organization is led by Executive Director Steven Lipner, widely recognized as the "Father of the Security Development Lifecycle" for his role creating Microsoft's SDL program, and a Member Academy of Engineering inductee. Operational support is provided by Virtual, Inc. There is no disclosed revenue, no fundraising rounds, and no traditional product monetization; SAFECode's value proposition is industry coordination rather than technology product.
SAFECode.org firmographics
Firmographics- Name
- SAFECode.org
- Legal name
- Software Assurance Forum for Excellence in Code (SAFECode)
- Website
- https://safecode.org
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SAFECode is a global nonprofit founded in 2007 that convenes software security leaders from major technology companies in an NDA-protected forum to publish guidance, deliver free training, and develop standards, funded by USD $10,000 annual memberships.
- Ownership category
- akta.pro rank
SAFECode.org industry classification
Industry- Product category
- Software Security Industry Forum
- NAICS
- Professional Organizations (81392)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
Keywords
Where SAFECode.org is headquartered
LocationHeadquarters
- HQ city
- Wakefield
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
SAFECode.org business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales
Revenue model
- Membership Dues: SAFECode generates revenue through annual membership dues. The organization operates as a nonprofit and relies on membership fees to fund its operations and activities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Annual Membership - USD $10,000 per year |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
SAFECode.org product offering
Product offeringCore offering
SAFECode is a global nonprofit industry forum that brings business leaders and technical experts together to exchange insights and ideas on creating, improving, and promoting scalable and effective software security programs. It publishes software security guidance documents, delivers free online security engineering training courses, facilitates member working groups, and contributes to international standards such as ETSI TS 104 219.
Product overview
SAFECode.org is a global nonprofit organization (not a traditional software product company) that serves as an industry forum for software security. The organization offers a portfolio of free community resources including software security training courses, published guidance documents, and secure development frameworks. The core offerings include the Fundamental Practices for Secure Software Development publication, the SAFECode Training Program with multiple security engineering courses, and collaborative working groups covering DevSecOps, Post Quantum Cryptography, Personal Data Privacy, and Fuzzing Techniques. All training content is free and published under Creative Commons license.
Differentiator
Problem solved
Functional benefit
Products and services
- Fundamental Practices for Secure Software Development SAFECode's flagship publication providing foundational guidance for organizations to initiate or improve software assurance programs, encouraging industry-wide adoption of fundamental secure development practices. Targeted at enterprise security leaders.
- SAFECode Training Program Free online community resource providing 18+ security engineering training courses via on-demand webcasts under a Creative Commons license. Topics include secure development, cryptography, threat modeling, and application security. Available to the public.
- Security Development Lifecycle 101 Self-paced course providing essential information about the security development lifecycle (SDL), its practices, and how to integrate security aspects into development methods. Targeted at software developers and application security professionals.
- Threat Modeling 101 Self-paced course enabling viewers to execute a basic threat model, understand threats and risk rankings, and interpret results of executed threat models. Targeted at software developers and security practitioners.
- Introduction to Cryptography Self-paced course providing insight into correct use of cryptography in applications, including encryption, hashing, and their correct uses. Targeted at software developers.
- Secure by Design Guide Comprehensive guide developed with CIS providing development organizations with actionable guidance on creating secure software and meeting NIST SSDF requirements. Covers design, configuration, supply chain security, and AI/ML risks.
- ETSI TS 104 219 Software Security Development and Implementation Framework International standard for Software Security Development and Implementation Framework adopted by ETSI, mapped to EU Cyber Resilience Act (CRA) and UK NCSC requirements.
- DevSecOps Working Group Member working group tackling DevSecOps issues in cloud environments, creating transparent software development and security management lifecycle guidance. Available to SAFECode members in the NDA-protected collaboration environment.
Companies that use SAFECode.org
Customer profileNamed customers8 records
Segments3 records
Ideal customer profiles3 records
SAFECode.org technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
SAFECode.org partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered flagship, core and minor.
- ETSI (European Telecommunications Standards Institute)flagshipCollaborated with ETSI Technical Committee Cyber to transform the Secure by Design guide into a formal standard: ETSI TS 104 219 V0.0.7 (2026-01), Software Security Development and Implementation Framework. The standard maps to EU Cyber Resilience Act and UK NCSC requirements.
- Center for Internet Security (CIS)flagshipSAFECode partnered with CIS to create the 'Secure by Design' guide providing actionable guidance on creating secure software and meeting NIST SSDF requirements. This partnership led to the development of ETSI TS 104 219 standard for software security development and implementation.
- Nonprofit Cyber CoalitionflagshipSAFECode is one of 22 founding members of Nonprofit Cyber, a coalition of global nonprofit cybersecurity organizations focused on coordinating implementation efforts, building awareness, and aligning work to improve cybersecurity globally.
- Cloud Security Alliance (CSA)coreJoint publication of 'DevSecOps – Pillar 4 Bridging Compliance and Development' providing framework to translate security and compliance requirements into development cycles.
- Cloud Security Alliance (CSA)coreCSA and SAFECode collaborated on 'The Six Pillars of DevSecOps: Automation' paper providing practical guidance for integrating automated security into software development lifecycle. Joint working group creates DevSecOps guidance.
- Open Source Security Foundation (OpenSSF)minorSAFECode is partnering with OpenSSF to explore problem statements and topics related to open source security for interested member companies.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
SAFECode.org competitors and assessment
Company assessmentBroad incumbents
- SANS Institute: SANS is a major provider of cybersecurity training and certifications; it overlaps with SAFECode's free-training mission area (though SANS operates as a paid commercial training provider) and shares the same practitioner audience.
- ISACA: ISACA is a global professional association for IT governance, risk, and cybersecurity professionals offering certifications, training, and guidance; comparable as a dues-funded membership body but with a broader scope than SAFECode's software-security focus.
- (ISC)²: (ISC)² is a nonprofit membership body for cybersecurity professionals offering credentials and training; overlap with SAFECode in security-training delivery and professional-development resources, though credentialing-led rather than guidance-led.
- Internet Security Alliance: ISA is an established nonprofit industry association covering cybersecurity across multiple domains with a similar dues-funded, member-driven model; broader in scope but comparable in operational structure to SAFECode.
Direct peers
- Center for Internet Security (CIS): CIS is a nonprofit that publishes security benchmarks and collaborated with SAFECode on the Secure by Design guide; comparable as a nonprofit producing standards-aligned software and system security guidance.
- OWASP Foundation: OWASP is a global nonprofit producing open-source software-security guidance, tools, and training; like SAFECode it operates via community contribution, free publications, and corporate sponsorship, directly overlapping on secure-development best practices.
- National Cybersecurity Alliance: NCA is a nonprofit cybersecurity awareness organization and a co-founding partner in the Nonprofit Cyber coalition alongside SAFECode, with overlapping outreach and awareness-building missions.
- Cloud Security Alliance (CSA): CSA is a nonprofit industry forum producing cloud-security guidance and certifications; it is explicitly a SAFECode working partner (joint DevSecOps papers) and overlaps on software supply chain and cloud SDLC guidance.
- Cyber Threat Alliance: CTA is a nonprofit industry forum where member cybersecurity vendors share threat intelligence under NDA — directly comparable to SAFECode's member-driven, NDA-protected collaboration model.
- OpenSSF (Open Source Security Foundation): OpenSSF is a cross-industry foundation focused on open-source software supply chain security and is an explicit SAFECode partner; comparable as a software-security-focused nonprofit forum with overlapping working groups (e.g., supply chain, SBOM).
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
SAFECode.org social profiles
Digital presenceSAFECode.org financial estimates
Financial estimateRevenue estimate
Valuation estimate
SAFECode.org leadership team
Management profileNumber of profiles
Profiles6 records
SAFECode.org funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SAFECode.org M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SAFECode.org
What does SAFECode.org do?
SAFECode is a global nonprofit industry forum that brings business leaders and technical experts together to exchange insights and ideas on creating, improving, and promoting scalable and effective software security programs. It publishes software security guidance documents, delivers free online security engineering training courses, facilitates member working groups, and contributes to international standards such as ETSI TS 104 219.
Is SAFECode.org a public or private company?
SAFECode.org is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was SAFECode.org founded?
SAFECode.org was founded in 2007. It employs 11 to 50 people.
Where is SAFECode.org based?
SAFECode.org is headquartered in Wakefield, United States, in the North America region.
How does SAFECode.org make money?
One revenue line is on record: membership Dues.
Who are SAFECode.org's main competitors?
Broad incumbents on record are SANS Institute, ISACA, (ISC)² and Internet Security Alliance. Direct peers are Center for Internet Security (CIS), OWASP Foundation, National Cybersecurity Alliance, Cloud Security Alliance (CSA), Cyber Threat Alliance and OpenSSF (Open Source Security Foundation).
Does SAFECode.org have an API?
No public API is recorded for SAFECode.org.
What industry is SAFECode.org in?
SAFECode.org's product category is Software Security Industry Forum. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of EDABAGAN, Secure Software & DevOps Awareness (Secure Coding Basics). Its NAICS code is 81392.