SoftFlow
SoftFlow is a Korean software supply chain security company that distributes Black Duck SCA and Synopsys/Coverity tools, layers proprietary AppSecFlow and Integrix platforms on top, and serves 100+ institutions across defense, automotive, medical device, financial, and public sectors with compliance consulting.
- Company typePrivate
- Founded2018
- HeadquartersSeongnam, South Korea
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What SoftFlow does
SoftFlow is a South Korean software supply chain security and AI verification company founded on February 8, 2018, headquartered in Anyang, Gyeonggi Province (relocated from prior offices in April 2026). The company distributes and supports globally-leading application security testing tools — including Synopsys/Coverity (SAST), Black Duck SCA, Defensics (fuzzing), Seeker (IAST), Continuous Dynamic (DAST), Code Sight (IDE plugin), Polaris (AppSec SaaS), and Software Risk Manager — and layers on proprietary platforms AppSecFlow and the Integrix family (Sigma for unified vulnerability management with VEX-based prioritization, Lambda for open source governance, Delta for zero trust and national intelligence MLS segmentation verification), along with the NCA network capture and analysis solution for closed-network environments. AI features such as Coverity's AI Fix guidance, Black Duck Assist, and Polaris AI summarization are integrated into the product suite.
SoftFlow serves more than 100 institutions across Korea's defense and aviation, automotive, financial services, medical devices, telecommunications, rail, industrial/critical infrastructure, and public sectors, including KISA, the Ministry of National Defense, KTC, KTL, Kunsan National University, and Korea Ship Classification Society. Its go-to-market is enterprise field sales supported by technical engineers, joint seminars with KTC certification body, government procurement via NCA on Geundeal (G2B), and event presence at ISEC, BestCon, NSIS, EVS, and other Korean security and automotive conferences.
Revenue is generated across five streams: (1) subscription/recurring distribution of Black Duck, Synopsys/Coverity, and complementary security tools; (2) cybersecurity testing services — source code vulnerability analysis, SCA, fuzzing, penetration testing delivered by certified engineers; (3) cybersecurity licensing and regulatory consulting covering FDA, ISO 21434, IEC 62443, UNECE R155/R156, EU CRA, and KISA guidelines; (4) SW supply chain security consulting for open source governance, DevSecOps pipelines, and SBOM system establishment; and (5) testbed/living lab construction for SW V&V and security testing environments. Pricing is custom enterprise subscription with annual billing; the company sells exclusively through consultation, demo, and quote requests rather than self-serve or marketplace channels.
SoftFlow firmographics
Firmographics- Name
- SoftFlow
- Legal name
- 소프트플로우 주식회사
- Website
- https://softflow.io
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- SoftFlow is a Korean software supply chain security company that distributes Black Duck SCA and Synopsys/Coverity tools, layers proprietary AppSecFlow and Integrix platforms on top, and serves 100+ institutions across defense, automotive, medical device, financial, and public sectors with compliance consulting.
- Ownership category
- akta.pro rank
SoftFlow industry classification
Industry- Product category
- Application Security Testing (Software Supply Chain Security)
- NAICS
- Software Publishers (5132), Computer Systems Design and Related Services (5415), Other Computer Related Services (541519), Custom Computer Programming Services (541511), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Testing Laboratories (8734), Services-Computer Programming Services (7371), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage) (HDAAAKAG), Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where SoftFlow is headquartered
LocationHeadquarters
- HQ city
- Seongnam
- HQ country
- South Korea
- HQ region
- Asia
Offices2 records
Markets served
SoftFlow business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- Software Security Tools Distribution (Resale): Distribution and resale of globally-leading security analysis tools including Coverity (SAST), Black Duck SCA, Defensics, Seeker (IAST), Continuous Dynamic (DAST), Code Sight, Polaris, and Software Risk Manager. Revenue generated from software licenses, subscriptions, and support contracts with enterprise and government customers.
- Cybersecurity Testing Services: Professional services including source code vulnerability analysis, cybersecurity testing, software composition analysis, vulnerability analysis, and penetration testing. Delivered by certified engineers using proprietary and third-party tools.
- Cybersecurity Licensing Consulting: Consulting services for global regulatory compliance (FDA, ISO 21434, IEC 62443, UNECE R155/R156, EU CRA, KISA guidelines). Includes gap analysis, security requirement design, SBOM management system establishment, and technical documentation for certification submissions.
- SW Supply Chain Security Consulting: Consulting services covering open source governance establishment, DevSecOps CI/CD security pipeline construction, and SBOM-based integrated management system setup. Combines commercial (Black Duck SCA) and open-source tools (Trivy) strategically.
- Testbed/Living Lab Construction Services: SW V&V testbed and security living lab construction services, including security testing environment setup per international standards, security model research, test automation, and threat demonstration development.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise licensing and services |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
SoftFlow product offering
Product offeringCore offering
SoftFlow distributes and integrates globally-leading software security analysis tools (Coverity SAST, Black Duck SCA, Defensics, Seeker IAST, Continuous Dynamic DAST, Code Sight, Polaris) and provides proprietary platforms (AppSecFlow, Integrix Sigma/Lambda/Delta) for software supply chain security, SBOM automation, vulnerability management, and AI-generated code security. The company also delivers cybersecurity testing services, regulatory compliance consulting (EU CRA, ISO 21434, UN R155/R156, FDA, KISA), and testbed/living lab construction for Korean defense, automotive, medical device, financial, and public sector clients.
Product overview
SoftFlow is a software supply chain security and AI verification company offering a comprehensive portfolio of software risk analysis and cybersecurity products. The product portfolio is organized into two main categories: Software Risk Analysis Tools (Coverity Static Analysis, Black Duck SCA, Defensics, Seeker IAST, Continuous Dynamic DAST, Code Sight IDE Plugin, Polaris AppSec Platform, Software Risk Manager) and Cyber Security products (NCA Network Traffic Analysis, Tenable IT/OT Security). The core offering centers on Black Duck SCA and Coverity as the primary platforms for open source security management and static code analysis, supplemented by specialized testing tools for fuzzing, dynamic analysis, and interactive testing. The company also offers consulting and testing services including cybersecurity testing, licensing consulting, SW supply chain security consulting, source code vulnerability analysis, software composition analysis, and testbed/living lab setup services.
Differentiator
Problem solved
Functional benefit
Brands
- AppSecFlow: 자체 통합 플랫폼. Black Duck SCA 및 Coverity 연동을 통한 보안 분석 결과 관리 및 공인 시험기관 제출용 자료 생성 지원.
- Integrix
- Integrix Sigma
- Integrix Lambda
- Integrix Delta
- NCA
Products and services
- Coverity Static Analysis AI-powered static analysis solution for detecting software defects, security vulnerabilities, coding rule violations, and quality metrics with the highest accuracy and lowest false positive rate. Distributed by SoftFlow for Korean enterprises and government.
- Black Duck SCA Open source security and software composition analysis solution providing real-time visibility into open source vulnerabilities and license risks with multi-factor scanning and automated SBOM generation.
- Defensics Protocol fuzz testing solution for detecting unknown zero-day vulnerabilities in automotive, medical, and industrial control system communication protocols through intelligent fuzzing data injection.
- Seeker Interactive Application Security Testing (IAST) solution that detects security vulnerabilities in real-time during application execution with code-level accurate remediation guidance.
- Continuous Dynamic Dynamic Application Security Testing (DAST) SaaS solution for continuous security monitoring of running web services and API endpoints without disrupting service availability. Offered in Premium, Standard, and Basic Edition tiers.
- Code Sight IDE Plugin AI-powered real-time IDE security assistant that detects vulnerabilities and open source risks as developers write code, integrated with VS Code, IntelliJ, Eclipse, Visual Studio, and AI-first editors.
- Polaris AppSec SaaS Platform Cloud-native unified Application Security Testing platform integrating SAST, SCA, and DAST capabilities with AI-powered insights, governance, and automated workflow integration.
- Software Risk Manager Security vulnerability integration and risk visualization solution that consolidates results from 135+ security testing tools, performs correlation analysis, and provides priority-based remediation guidance.
- NCA (Network Capture & Analysis) Network traffic collection and inspection solution for security inspection automation in physically isolated networks for critical information infrastructure, national important facilities, and smart factories.
- Tenable IT/OT Security Vulnerability and risk management solution for IT/OT environments covering Nessus Expert, Tenable Security Center, and Tenable OT Security for comprehensive asset identification and vulnerability analysis.
- Integrix Platform (Sigma, Lambda, Delta) Proprietary next-generation integrated vulnerability and supply chain security management platform with VEX-based vulnerability priority analysis across application, infrastructure, and endpoint layers. Comprises Sigma (vulnerability/supply chain), Lambda (open source governance portal), and Delta (zero trust/MLS segmentation verification).
- AppSecFlow Proprietary integrated platform for SW supply chain security management, SBOM generation, and compliance reporting. Connects Black Duck SCA and Coverity for unified security analysis and vulnerability prioritization.
- Cybersecurity Testing Services Professional services including source code vulnerability analysis, cybersecurity testing, software composition analysis, vulnerability analysis, and penetration testing delivered by certified engineers.
- Cybersecurity Licensing Consulting Consulting services for global regulatory compliance including FDA, ISO 21434, IEC 62443, UNECE R155/R156, EU CRA, and KISA guidelines. Includes gap analysis, security requirement design, SBOM management system establishment, and technical documentation for certification submissions.
- SW Supply Chain Security Consulting Consulting services covering open source governance establishment, DevSecOps CI/CD security pipeline construction, and SBOM-based integrated management system setup. Combines commercial (Black Duck SCA) and open-source tools (Trivy) strategically.
- Testbed/Living Lab Construction Services SW V&V testbed and security living lab construction services, including security testing environment setup per international standards, security model research, test automation, and threat demonstration development.
Quantifiable outcome
- Remediation speed improved by 66% when using Code Sight IDE plugin for real-time vulnerability detection and AI-powered fix guidance.
- +4 more outcomes
Companies that use SoftFlow
Customer profileNamed customers8 records
Segments8 records
Ideal customer profiles6 records
SoftFlow technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability14 records
Feature7 records
SoftFlow partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and major.
- Black Duck Software (Synopsys)coreSoftFlow is the primary Korean channel partner and technical support provider for Black Duck Software's SCA solutions (Black Duck SCA, Polaris). The partnership enables automated SBOM generation, open source vulnerability detection, and AI-BOM management. The company relocated its headquarters in 2026 specifically to build EU CRA-compliant technical support infrastructure alongside Black Duck. Black Duck Assist AI features are integrated into SoftFlow's Code Sight IDE plugin offering.
- Synopsys (Coverity)coreSoftFlow distributes Synopsys' Coverity Static Analysis tool in Korea, providing SAST services including AI-powered fix guidance, industry standard compliance (MISRA, AUTOSAR, CERT, OWASP), and CI/CD pipeline integration. Coverity holds Gartner's top ranking in Application Security Testing for 7 consecutive years.
- KISA (Korea Internet & Security Agency)majorSoftFlow participated in KISA's Supply Chain Security Model Construction Support Project for 2 consecutive years (2025-2026). The project supports Korean enterprises in building supply chain security systems compliant with global regulations, including SBOM creation, license management, and vulnerability tracking.
- KTC (Korea Mechanical, Electrical & Electronic Test Institute / 한국기계전기전자시험研究院)coreSoftFlow and KTC co-host annual seminars on security compliance verification and SW supply chain security strategy. In 2026, they jointly hosted the '2026 Security Compliance Verification and SW Supply Chain Security Strategy' seminar at COEX, targeting enterprise and government compliance professionals.
Scale indicators5 records
Recent moves7 records
Expansion highlights6 records
SoftFlow competitors and assessment
Company assessmentDirect peers
- Checkmarx: Global application security testing platform offering SAST, SCA, and IAST. Directly comparable to the Coverity/Black Duck/Seeker portfolio that SoftFlow distributes and integrates in Korea.
- Veracode: Enterprise application security testing SaaS covering SAST, DAST, and SCA. Comparable to SoftFlow's Polaris/Continuous Dynamic/AppSecFlow offering for regulated enterprise customers.
- Snyk: Developer-first security platform with strong SCA/SBOM and SAST capabilities. Competes head-on with the Black Duck SCA + Code Sight proposition SoftFlow sells to Korean enterprises.
- Contrast Security: Provider of IAST and runtime application security. Directly overlaps with SoftFlow's Seeker IAST and runtime analysis positioning for security-aware enterprises.
Emerging players
- Anchore: SBOM generation and software supply chain security platform. Comparable to SoftFlow's Integrix Lambda and Black Duck SCA-based SBOM offering, particularly in regulated industries.
- Cybellum: Product security and SBOM platform purpose-built for automotive and medical device OEMs. Comparable to SoftFlow's automotive/medical device vertical practice around ISO 21434, UN R155/R156, and FDA premarket security.
- Chainguard: Software supply chain security company specializing in hardened container images and SBOM-based provenance. Adjacent competitor to the SCA/SBOM part of SoftFlow's portfolio, especially for DevSecOps buyers.
Regional players
- AhnLab: Leading Korean cybersecurity vendor offering endpoint, network, and application security products. A domestic Korean peer competing in the same enterprise/government accounts SoftFlow targets.
- Igloo Security: Korean cybersecurity company focused on application security, encryption, and zero-trust solutions. Directly comparable in Korean enterprise/government AppSec deals.
- SK shieldus: Large Korean managed security and cybersecurity services provider with government and critical-infrastructure customers. Comparable in Korean defense/public-sector AppSec and supply chain security deals.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
SoftFlow social profiles
Digital presenceSoftFlow financial estimates
Financial estimateRevenue estimate
Valuation estimate
SoftFlow leadership team
Management profileNumber of profiles
Profiles1 record
SoftFlow funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SoftFlow M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SoftFlow
What does SoftFlow do?
SoftFlow distributes and integrates globally-leading software security analysis tools (Coverity SAST, Black Duck SCA, Defensics, Seeker IAST, Continuous Dynamic DAST, Code Sight, Polaris) and provides proprietary platforms (AppSecFlow, Integrix Sigma/Lambda/Delta) for software supply chain security, SBOM automation, vulnerability management, and AI-generated code security. The company also delivers cybersecurity testing services, regulatory compliance consulting (EU CRA, ISO 21434, UN R155/R156, FDA, KISA), and testbed/living lab construction for Korean defense, automotive, medical device, financial, and public sector clients.
Is SoftFlow a public or private company?
SoftFlow is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SoftFlow founded?
SoftFlow was founded in 2018. It employs 1 to 10 people.
Where is SoftFlow based?
SoftFlow is headquartered in Seongnam, South Korea, in the Asia region.
How does SoftFlow make money?
Five revenue lines are on record. Software Security Tools Distribution (Resale) is the primary driver. The others are cybersecurity Testing Services, cybersecurity Licensing Consulting, SW Supply Chain Security Consulting and testbed/Living Lab Construction Services.
Who are SoftFlow's main competitors?
Direct peers on record are Checkmarx, Veracode, Snyk and Contrast Security. Emerging players are Anchore, Cybellum and Chainguard. Regional players are AhnLab, Igloo Security and SK shieldus.
Does SoftFlow have an API?
Yes. Defensics offers REST API for integration with existing CI/CD and automation testing environments. The API enables integration with continuous integration and continuous deployment pipelines for automated security testing workflows.
What industry is SoftFlow in?
SoftFlow's product category is Application Security Testing (Software Supply Chain Security). Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDAAAKAG, AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage). Its NAICS code is 5132 and its SIC code is 7372.