CodeClarity
CodeClarity is a Luxembourg-based open-source security analysis platform that helps software development, DevOps, and security teams detect and prioritize vulnerabilities across multiple programming languages via integrations with GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps.
- Company typePrivate
- Founded2023
- HeadquartersCharlotte, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What CodeClarity does
CodeClarity is a Luxembourg-based open-source security analysis platform that serves software development teams, DevOps engineers, and security professionals. Founded in 2023 by Cédric Herzog as a SARL with EUR 15,000 share capital, the company operated in development mode before launching its public product in April 2025.
The platform performs multi-dimensional security analysis on codebases through a plugin-based architecture supporting multiple programming languages, and integrates with the major developer-tooling ecosystem including GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps. Its AI capability is delivered through integration with VLAI (Vulnerability-Lookup AI) operated by CIRCL, which provides RoBERTa-based NLP models trained on more than 600,000 vulnerability advisories to generate contextual vulnerability scoring and remediation guidance. The product is distributed under the AGPL-3.0 license with the codebase publicly available, and is positioned against regulatory drivers including the EU Cyber Resilience Act, US Executive Order 14028, and NIS2.
The business model is open-source-first with the core platform freely accessible; no pricing tiers, paid plans, paying customer logos, revenue figures, or funding rounds have been disclosed. The company has been validated through the Fit4Start#14 accelerator (2023), the Luxembourg Cybersecurity Startup Award (2023), and participation in FIC 2025. As of February 2026 the product remains in alpha stage at v0.0.25-alpha.
CodeClarity firmographics
Firmographics- Name
- CodeClarity
- Legal name
- CodeClarity S.à r.l.
- Website
- https://www.codeclarity.io
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- CodeClarity is a Luxembourg-based open-source security analysis platform that helps software development, DevOps, and security teams detect and prioritize vulnerabilities across multiple programming languages via integrations with GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps.
- Ownership category
- akta.pro rank
CodeClarity industry classification
Industry- Product category
- Application Security
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where CodeClarity is headquartered
LocationHeadquarters
- HQ city
- Charlotte
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
CodeClarity business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure
Revenue model
- Open-source Free Tier: Core security analysis features are completely free. Open-source platform available via GitHub with self-hosting options. Targets individual developers, startups, and organizations seeking accessible security tooling.
- Enterprise/Cloud Hosting (Inferred): CodeClarity Cloud hosted platform at platform.codeclarity.io implies potential managed service offering. Enterprise support or cloud-hosted tiers may be available for organizations preferring managed infrastructure over self-hosting.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free Open-Source Tier |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
CodeClarity product offering
Product offeringCore offering
CodeClarity is an open-source security analysis platform that performs fast source code analysis to reveal software dependencies, licenses, and vulnerabilities. It generates Software Bills of Materials (SBOMs), performs static and reachability analysis, and applies AI-based vulnerability prioritization to help development teams secure their software supply chain. The platform is offered both as a hosted cloud service (platform.codeclarity.io) and as a self-hosted Docker deployment.
Product overview
CodeClarity is an open-source security analysis platform that provides comprehensive software security through a modular plugin architecture. The core CodeClarity Platform delivers source code analysis, SBOM generation, vulnerability scanning, patching, and license compliance management. The platform is extended through specialized plugins including the JavaScript SBOM Plugin (supporting npm, pnpm, and Yarn), CodeQL Plugin for JS/Go/Python analysis, Vulnerability Scanner Plugin (integrating with NVD, OSV, GCVE), License Compliance Plugin, and Patching Plugin. AI-powered features are enabled through VLAI integration for smart vulnerability prioritization. CI/CD integration is available via the CodeClarity GitHub Action. The platform also includes a built-in ticket management system for tracking remediation workflows, with ClickUp integration for syncing tickets to external project management tools.
Differentiator
Problem solved
Functional benefit
Products and services
- CodeClarity Platform
- CodeClarity GitHub Action
- Ticket Management System (built-in to CodeClarity)
Quantifiable outcome
- 80% of codebases contain at least one dependency vulnerability
- +2 more outcomes
Companies that use CodeClarity
Customer profileSegments4 records
Ideal customer profiles1 record
CodeClarity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability6 records
Feature12 records
CodeClarity partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered supporting and core.
- ClickUpsupportingClickUp integration enables security tickets to sync directly to ClickUp workspaces. Supports both OAuth and API Key authentication methods. Part of broader project management integration roadmap including Jira and Linear.
- VLAI (Vulnerability Lookup AI) / CIRCLcoreCIRCL (Computer Incident Response Center Luxembourg) provides VLAI, an AI-powered vulnerability assessment service using NLP models trained on 600,000+ vulnerability advisories. CodeClarity integrates VLAI for smarter vulnerability prioritization with confidence scoring beyond traditional CVSS ratings.
- GitHubcoreGitHub provides integration with CodeClarity's security scanning. The platform offers GitHub Action for automated CI/CD security scanning available on GitHub Marketplace. Users can import projects via GitHub URL and configure GitHub integration for vulnerability tracking.
- GitLabcoreGitLab integration allows seamless connection with GitLab version control systems. Users can import repositories by providing GitLab URLs and integrate CodeClarity with GitLab workflows.
- Vulnerability-LookupsupportingIntegration with Vulnerability-Lookup allows CodeClarity to push analysis results as sightings. When projects are public and API key is configured, vulnerabilities found are automatically submitted as sightings to the Vulnerability-Lookup platform.
- Luxembourg House of CybersecuritysupportingGovernment-backed cybersecurity body that awarded CodeClarity the Cybersecurity Startup Award during CYBERSECURITY Week Luxembourg 2023. Provides ecosystem support and validation for Luxembourg cybersecurity startups.
- Luxinnovation GIEsupportingLuxembourg's national innovation agency that runs the Fit4Start accelerator program. Selected CodeClarity for Fit4Start#14, providing acceleration support, mentorship, and ecosystem connections for startup growth.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
CodeClarity competitors and assessment
Company assessmentDirect peers
- JFrog Xray: JFrog Xray provides deep dependency analysis, vulnerability scanning, and license compliance for software supply chains — overlapping with CodeClarity's SBOM and vulnerability detection capabilities.
- Mend (formerly WhiteSource): Mend offers SCA with SBOM generation, vulnerability prioritization, and license compliance — a direct competitor to CodeClarity, particularly in the open-source dependency analysis segment.
- Sonatype Nexus: Sonatype's Nexus platform (including Nexus Lifecycle) provides SCA, dependency management, and license compliance — directly comparable to CodeClarity's open-source security analysis positioning.
- Snyk: Snyk is a leading developer-centric security platform with comprehensive SCA capabilities (Snyk Open Source) — direct overlap with CodeClarity's SBOM, vulnerability scanning, and CI/CD integration. Snyk is explicitly cited as a peer in CodeClarity's market positioning.
- GitHub Dependabot: GitHub's native Dependabot (plus GitHub Advanced Security) provides dependency scanning, SBOM, and automated PR-based patching directly within the GitHub workflow — the most direct free/embedded competitor to CodeClarity's GitHub Action.
- Anchore: Anchore provides enterprise-grade SCA with SBOM generation, vulnerability scanning, and policy-based compliance — a direct competitor especially in regulated industries and containerized software supply chains.
- Aqua Security Trivy: Trivy is an open-source vulnerability scanner covering dependencies, containers, and IaC — closely comparable to CodeClarity as a free, extensible, developer-focused open-source SCA tool with strong community adoption.
- Synopsys Black Duck: Black Duck is a pioneer in open-source security and SCA, offering SBOM generation, vulnerability detection, and license compliance — directly overlapping with CodeClarity's feature set. Explicitly cited as a competitor.
- Checkmarx: Checkmarx offers SCA (CxSCA) alongside its SAST portfolio, providing SBOM, vulnerability detection, and license compliance — directly competitive with CodeClarity's core capabilities. Explicitly cited as a competitor in CodeClarity's positioning.
Emerging players
- OWASP Dependency-Check: OWASP Dependency-Check is an open-source SCA tool that identifies project dependencies and checks for known vulnerabilities — a free, community-driven alternative that competes for the same open-source-aware developer audience as CodeClarity.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
CodeClarity social profiles
Digital presenceCodeClarity financial estimates
Financial estimateRevenue estimate
Valuation estimate
CodeClarity leadership team
Management profileNumber of profiles
Profiles1 record
CodeClarity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CodeClarity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CodeClarity
What does CodeClarity do?
CodeClarity is an open-source security analysis platform that performs fast source code analysis to reveal software dependencies, licenses, and vulnerabilities. It generates Software Bills of Materials (SBOMs), performs static and reachability analysis, and applies AI-based vulnerability prioritization to help development teams secure their software supply chain. The platform is offered both as a hosted cloud service (platform.codeclarity.io) and as a self-hosted Docker deployment.
Is CodeClarity a public or private company?
CodeClarity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was CodeClarity founded?
CodeClarity was founded in 2023. It employs 1 to 10 people.
Where is CodeClarity based?
CodeClarity is headquartered in Charlotte, United States, in the North America region.
How does CodeClarity make money?
Two revenue lines are on record. Open-source Free Tier is the primary driver. The others are enterprise/Cloud Hosting (Inferred).
Who are CodeClarity's main competitors?
Direct peers on record are JFrog Xray, Mend (formerly WhiteSource), Sonatype Nexus, Snyk, GitHub Dependabot, Anchore, Aqua Security Trivy, Synopsys Black Duck and Checkmarx. OWASP Dependency-Check is listed as an emerging player.
Does CodeClarity have an API?
Yes. CodeClarity exposes REST endpoints for scheduling and notifications via its NestJS API layer. The platform supports API key authentication for integrations and provides CLI commands for automation and scripting. Integration endpoints allow programmatic project management, vulnerability scanning, and ticket operations. Developer documentation is at doc.codeclarity.io.
What industry is CodeClarity in?
CodeClarity's product category is Application Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 513210 and its SIC code is 7372.