CodeScoring
CodeScoring is an on-premise secure-software-development platform that delivers software composition analysis, supply-chain protection, code-quality intelligence, and secrets detection via four integrated modules. It sells to banks, telecom operators, healthcare organizations, IT firms, and computer-security companies.
- Company typePrivate
- Founded-
- Headquarters—
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What CodeScoring does
CodeScoring is a privately held software composition analysis and secure-software-development platform commercialized in January 2021 by Saint Petersburg-based parent entity Profiscope, which has worked with global open-source databases since 2011. The platform is delivered as an on-premise solution that ingests source code, builds Software Bills of Materials, and enforces security and license policies across the SDLC; it comprises four integrated modules — OSA (open-source supply-chain protection), SCA (software composition analysis), TQI (teams and quality intelligence), and Secrets (sensitive-data identification) — and supports 12 programming languages spanning TypeScript, Swift, Ruby, Python, PHP, Kotlin, JavaScript, Java, Go, C#, C++, and C.
Technically, the platform is anchored by a Universal CodeScoring Agent that runs on developer machines or in CI/CD pipelines, performs manifest analysis and transitive dependency resolution, and feeds a curated vulnerability-intelligence layer that aggregates NVD CVE, GHSA, OSV, and 12+ ecosystem feeds with de-duplication and error correction. Deep proxy-repository plugins integrate with Nexus Repository Manager and JFrog Artifactory PRO to block vulnerable or malicious components before they reach developers, while additional VCS integrations span GitHub, GitLab, Bitbucket, and Azure DevOps; enterprise identity is supported via Active Directory and orchestration via SOAR/ASOC, email, and task-management APIs. A proprietary machine-learning model reduces false positives in the Secrets module, and a curated database of 2,000+ open-source licenses with vendor-specific compatibility policies underpins compliance features.
Commercially, CodeScoring sells to banks, IT companies, telecom operators, healthcare organizations, and computer-security companies via direct enterprise field sales with quote-based, annual subscriptions; a partner/reseller program and educational licenses extend distribution. The company is small (firmographic headcount of 13; marketing claim of 30+ experts), privately funded with no disclosed institutional investment, and operates with no public ticker or exchange listing.
CodeScoring firmographics
Firmographics- Name
- CodeScoring
- Website
- https://codescoring.com
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CodeScoring is an on-premise secure-software-development platform that delivers software composition analysis, supply-chain protection, code-quality intelligence, and secrets detection via four integrated modules. It sells to banks, telecom operators, healthcare organizations, IT firms, and computer-security companies.
- Ownership category
- akta.pro rank
CodeScoring industry classification
Industry- Product category
- Application Security / Software Composition Analysis
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG), Data Discovery, Classification & Labeling (HDADAFAF)
Keywords
CodeScoring business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Software Subscriptions: On-premise solution sold as enterprise software with modular pricing (OSA, SCA, TQI, Secrets modules). Pricing is quote-based through demo requests, suggesting annual or multi-year subscription contracts for B2B customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise modular pricing with demo-based quotes |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
CodeScoring product offering
Product offeringCore offering
CodeScoring is an on-premise secure software development platform that combines four integrated modules: OSA for open source supply chain protection, SCA for software composition analysis, TQI for code quality intelligence across development teams, and Secrets for sensitive data and hardcoded credentials identification. The platform automates detection of vulnerabilities, malicious packages, license incompatibilities, and secrets across the SDLC while integrating with repository managers, CI/CD tools, and VCS providers.
Product overview
CodeScoring is a comprehensive platform for secure software development delivered as an on-premise solution. The platform consists of four integrated modules: (1) OSA Module for Open Source Analysis and supply chain protection, blocking malicious components at proxy repository level via Nexus and JFrog Artifactory integration; (2) SCA Module for Software Composition Analysis, building Software Bills of Materials and checking vulnerabilities and licenses at every stage of development; (3) TQI Module for Teams & Quality Intelligence, analyzing proprietary code for technical debt, cyclomatic complexity, and developer profiles; and (4) Secrets Module for identifying sensitive data in source code using machine learning to reduce false positives. The platform supports 12+ programming languages and integrates with VCS systems (GitHub, GitLab, Bitbucket) and enterprise identity via Active Directory.
Differentiator
Problem solved
Functional benefit
Products and services
- CodeScoring Platform (On-Premise Edition) On-premise secure software development platform for enterprises that need full data sovereignty and isolated infrastructure. Combines open source analysis, software composition analysis, code quality intelligence, and secrets detection in a single deployable system.
- OSA (Open Source Analysis) Module
Quantifiable outcome
- 90% of secrets remain valid 5 days after the leak, highlighting the critical need for automated secrets detection
- +3 more outcomes
Companies that use CodeScoring
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles3 records
CodeScoring technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability4 records
Feature8 records
CodeScoring partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- Nexus Repository ManagercoreCodeScoring plugins are embedded in Nexus Repository proxy repositories for blocking malicious or vulnerable components in accordance with configured security policies. This integration provides supply chain protection at the repository level.
- JFrog ArtifactorycoreCodeScoring plugins are embedded in JFrog Artifactory PRO proxy repositories for blocking malicious or vulnerable components based on security policies. Provides supply chain protection integrated into artifact management.
- NVD CVEcoreNational Vulnerability Database (NVD) CVE feed integration for vulnerability data aggregation. Part of the multi-feed vulnerability intelligence system.
- GitHub Security Advisories (GHSA)coreGitHub Security Advisories feed integration for vulnerability data. Part of comprehensive vulnerability intelligence aggregation.
- OSV (Open Source Vulnerabilities)coreOSV vulnerability feed integration from OpenSSF for standardized vulnerability database. Part of multi-feed vulnerability intelligence.
Scale indicators11 records
Recent moves6 records
Expansion highlights5 records
CodeScoring competitors and assessment
Company assessmentDirect peers
- Snyk: Direct competitor offering SCA, SBOM, secrets detection, and code quality analysis. Targets the same enterprise developer-security buyer with similar vulnerability and license compliance functionality, though primarily delivered as SaaS.
- Mend (formerly WhiteSource): Direct peer offering SCA, license compliance, and SBOM tooling for enterprise development teams. Competes head-to-head on open source vulnerability and license detection workflows.
- JFrog: Direct competitor with JFrog Artifactory and JFrog Xray for binary/SCA supply chain security. CodeScoring integrates with JFrog Artifactory PRO, and JFrog offers overlapping SCA and vulnerability blocking capabilities.
- Black Duck (Synopsys): Direct peer providing SCA, SBOM, and license compliance for enterprise customers. Long-standing incumbent in the open source security space with overlapping use cases to CodeScoring's SCA module.
- Sonatype: Direct peer with Nexus Repository and Sonatype Lifecycle, providing SCA, SBOM generation, and supply chain security. Closely comparable on artifact-manager integration and OSS vulnerability intelligence.
Broad incumbents
- GitLab: Broad incumbent offering SAST, dependency scanning, container scanning, and license compliance within its DevSecOps platform. Overlaps with CodeScoring's SCA and Secrets modules but as part of a full ALM/SDLC suite.
- Checkmarx: Broad incumbent in application security (SAST, SCA, IaC scanning). Competes indirectly through its SCA offering targeting the same enterprise AppSec buyer that CodeScoring serves.
- Veracode: Broad incumbent application security vendor with SCA and SBOM capabilities. Overlaps with CodeScoring in license compliance and open source vulnerability detection for large enterprise customers.
- GitHub Advanced Security: Broad incumbent bundling code scanning, secret scanning, and dependency review directly into the GitHub platform. Competes on SCA and secrets detection as part of a much wider developer platform portfolio.
Emerging players
- Anchore: Emerging player in SBOM, SCA, and container security with a focus on regulated industries and on-premise deployment. Closely comparable to CodeScoring's positioning around supply chain security for compliance-driven buyers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
CodeScoring social profiles
Digital presenceCodeScoring financial estimates
Financial estimateRevenue estimate
Valuation estimate
CodeScoring leadership team
Management profileNumber of profiles
Profiles1 record
CodeScoring funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CodeScoring M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CodeScoring
What does CodeScoring do?
CodeScoring is an on-premise secure software development platform that combines four integrated modules: OSA for open source supply chain protection, SCA for software composition analysis, TQI for code quality intelligence across development teams, and Secrets for sensitive data and hardcoded credentials identification. The platform automates detection of vulnerabilities, malicious packages, license incompatibilities, and secrets across the SDLC while integrating with repository managers, CI/CD tools, and VCS providers.
Is CodeScoring a public or private company?
CodeScoring is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was CodeScoring founded?
CodeScoring was founded in -1. It employs 11 to 50 people.
How does CodeScoring make money?
One revenue line is on record: software Subscriptions.
Who are CodeScoring's main competitors?
Direct peers on record are Snyk, Mend (formerly WhiteSource), JFrog, Black Duck (Synopsys) and Sonatype. Broad incumbents are GitLab, Checkmarx, Veracode and GitHub Advanced Security. Anchore is listed as an emerging player.
Does CodeScoring have an API?
Yes. CodeScoring provides API access for integrating with the platform's capabilities. The OSA module mentions 'the ability to use APIs' as part of its feature set. The API enables programmatic access to policy settings, vulnerability management, project scanning, and system integrations including SOAR/ASOC connections.
What industry is CodeScoring in?
CodeScoring's product category is Application Security / Software Composition Analysis. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its SIC code is 7370.