Developer docs
API playgroundTry for free, no card

Search company profiles

CodeClarity

Full company profile

uuid00es3kc

Namestring
CodeClarity
Legal namestring
CodeClarity S.à r.l.
Company typeenum
Private
Founded yearint
2023
Descriptiontext

CodeClarity is a Luxembourg-based open-source security analysis platform that serves software development teams, DevOps engineers, and security professionals. Founded in 2023 by Cédric Herzog as a SARL with EUR 15,000 share capital, the company operated in development mode before launching its public product in April 2025.

The platform performs multi-dimensional security analysis on codebases through a plugin-based architecture supporting multiple programming languages, and integrates with the major developer-tooling ecosystem including GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps. Its AI capability is delivered through integration with VLAI (Vulnerability-Lookup AI) operated by CIRCL, which provides RoBERTa-based NLP models trained on more than 600,000 vulnerability advisories to generate contextual vulnerability scoring and remediation guidance. The product is distributed under the AGPL-3.0 license with the codebase publicly available, and is positioned against regulatory drivers including the EU Cyber Resilience Act, US Executive Order 14028, and NIS2.

The business model is open-source-first with the core platform freely accessible; no pricing tiers, paid plans, paying customer logos, revenue figures, or funding rounds have been disclosed. The company has been validated through the Fit4Start#14 accelerator (2023), the Luxembourg Cybersecurity Startup Award (2023), and participation in FIC 2025. As of February 2026 the product remains in alpha stage at v0.0.25-alpha.

Short descriptiontext

CodeClarity is a Luxembourg-based open-source security analysis platform that helps software development, DevOps, and security teams detect and prioritize vulnerabilities across multiple programming languages via integrations with GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersCharlotte, United States
HQ citystring
Charlotte
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
open-source security analysis, software composition analysis, vulnerability scanning platform, SBOM generation tools, license compliance analysis
Industry2 codes
1Software Supply Chain & Dependency Security (SBOM, Signing)
CodeHDADACADPrimaryYes
2Code & Repository Security (Git Security, Code Integrity)
CodeHDADACAGPrimaryNo
NAICS code1 code
  • Software Publishers513210
SIC code1 code
  • Services-Prepackaged Software7372
Product category
Application Security
Social media profiles2 records
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model2 records
1Open-source Free Tier
TypeFreemium
Description

Core security analysis features are completely free. Open-source platform available via GitHub with self-hosting options. Targets individual developers, startups, and organizations seeking accessible security tooling.

codeclarity.io
2Enterprise/Cloud Hosting (Inferred)
TypeSubscription Recurring
Description

CodeClarity Cloud hosted platform at platform.codeclarity.io implies potential managed service offering. Enterprise support or cloud-hosted tiers may be available for organizations preferring managed infrastructure over self-hosting.

codeclarity.io
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components3 values
Personnel, Technology or R&D, Infrastructure
Pricing details1 tier
1Free Open-Source Tier
ModelFreemiumBilling cadenceOthers
Notes

CodeClarity's core features are completely free. Individual developers, startups, and large organizations can access enterprise-grade security scanning at no cost. Self-hosting available via Docker deployment.

codeclarity.io
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

CodeClarity is an open-source security analysis platform that performs fast source code analysis to reveal software dependencies, licenses, and vulnerabilities. It generates Software Bills of Materials (SBOMs), performs static and reachability analysis, and applies AI-based vulnerability prioritization to help development teams secure their software supply chain. The platform is offered both as a hosted cloud service (platform.codeclarity.io) and as a self-hosted Docker deployment.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • 80% of codebases contain at least one dependency vulnerability
+2 more records
Product overview1 text field

CodeClarity is an open-source security analysis platform that provides comprehensive software security through a modular plugin architecture. The core CodeClarity Platform delivers source code analysis, SBOM generation, vulnerability scanning, patching, and license compliance management. The platform is extended through specialized plugins including the JavaScript SBOM Plugin (supporting npm, pnpm, and Yarn), CodeQL Plugin for JS/Go/Python analysis, Vulnerability Scanner Plugin (integrating with NVD, OSV, GCVE), License Compliance Plugin, and Patching Plugin. AI-powered features are enabled through VLAI integration for smart vulnerability prioritization. CI/CD integration is available via the CodeClarity GitHub Action. The platform also includes a built-in ticket management system for tracking remediation workflows, with ClickUp integration for syncing tickets to external project management tools.

Product and service3 records
1CodeClarity Platform
CategoryApplication Security Software
2CodeClarity GitHub Action
CategoryDevSecOps Tooling
3Ticket Management System (built-in to CodeClarity)
CategoryApplication Security Software
Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership7 partners
Strategic tierSupportingTypeTechnology or IntegrationAnnounced on2026-01-04
Description

ClickUp integration enables security tickets to sync directly to ClickUp workspaces. Supports both OAuth and API Key authentication methods. Part of broader project management integration roadmap including Jira and Linear.

2VLAI (Vulnerability Lookup AI) / CIRCL
Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-07-04
Description

CIRCL (Computer Incident Response Center Luxembourg) provides VLAI, an AI-powered vulnerability assessment service using NLP models trained on 600,000+ vulnerability advisories. CodeClarity integrates VLAI for smarter vulnerability prioritization with confidence scoring beyond traditional CVSS ratings.

codeclarity.io
Strategic tierCoreTypeTechnology or Integration
Description

GitHub provides integration with CodeClarity's security scanning. The platform offers GitHub Action for automated CI/CD security scanning available on GitHub Marketplace. Users can import projects via GitHub URL and configure GitHub integration for vulnerability tracking.

Strategic tierCoreTypeTechnology or Integration
Description

GitLab integration allows seamless connection with GitLab version control systems. Users can import repositories by providing GitLab URLs and integrate CodeClarity with GitLab workflows.

Strategic tierSupportingTypeTechnology or Integration
Description

Integration with Vulnerability-Lookup allows CodeClarity to push analysis results as sightings. When projects are public and API key is configured, vulnerabilities found are automatically submitted as sightings to the Vulnerability-Lookup platform.

Strategic tierSupportingTypeStrategic or Co-development Partner
Description

Government-backed cybersecurity body that awarded CodeClarity the Cybersecurity Startup Award during CYBERSECURITY Week Luxembourg 2023. Provides ecosystem support and validation for Luxembourg cybersecurity startups.

Strategic tierSupportingTypeStrategic or Co-development Partner
Description

Luxembourg's national innovation agency that runs the Fit4Start accelerator program. Selected CodeClarity for Fit4Start#14, providing acceleration support, mentorship, and ecosystem connections for startup growth.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

JFrog Xray provides deep dependency analysis, vulnerability scanning, and license compliance for software supply chains — overlapping with CodeClarity's SBOM and vulnerability detection capabilities.

TypeDirect peer
Description

Mend offers SCA with SBOM generation, vulnerability prioritization, and license compliance — a direct competitor to CodeClarity, particularly in the open-source dependency analysis segment.

TypeDirect peer
Description

Sonatype's Nexus platform (including Nexus Lifecycle) provides SCA, dependency management, and license compliance — directly comparable to CodeClarity's open-source security analysis positioning.

TypeDirect peer
Description

Snyk is a leading developer-centric security platform with comprehensive SCA capabilities (Snyk Open Source) — direct overlap with CodeClarity's SBOM, vulnerability scanning, and CI/CD integration. Snyk is explicitly cited as a peer in CodeClarity's market positioning.

TypeDirect peer
Description

GitHub's native Dependabot (plus GitHub Advanced Security) provides dependency scanning, SBOM, and automated PR-based patching directly within the GitHub workflow — the most direct free/embedded competitor to CodeClarity's GitHub Action.

6OWASP Dependency-Check
TypeEmerging player
Description

OWASP Dependency-Check is an open-source SCA tool that identifies project dependencies and checks for known vulnerabilities — a free, community-driven alternative that competes for the same open-source-aware developer audience as CodeClarity.

TypeDirect peer
Description

Anchore provides enterprise-grade SCA with SBOM generation, vulnerability scanning, and policy-based compliance — a direct competitor especially in regulated industries and containerized software supply chains.

TypeDirect peer
Description

Trivy is an open-source vulnerability scanner covering dependencies, containers, and IaC — closely comparable to CodeClarity as a free, extensible, developer-focused open-source SCA tool with strong community adoption.

TypeDirect peer
Description

Black Duck is a pioneer in open-source security and SCA, offering SBOM generation, vulnerability detection, and license compliance — directly overlapping with CodeClarity's feature set. Explicitly cited as a competitor.

TypeDirect peer
Description

Checkmarx offers SCA (CxSCA) alongside its SAST portfolio, providing SBOM, vulnerability detection, and license compliance — directly competitive with CodeClarity's core capabilities. Explicitly cited as a competitor in CodeClarity's positioning.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile1 record

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration6 records

Each record includes

Title, Type, Description, Source

AI capability6 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature12 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles1 record

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

CodeClarity

Application Securitycodeclarity.io

CodeClarity is a Luxembourg-based open-source security analysis platform that helps software development, DevOps, and security teams detect and prioritize vulnerabilities across multiple programming languages via integrations with GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps.

What CodeClarity does

CodeClarity is a Luxembourg-based open-source security analysis platform that serves software development teams, DevOps engineers, and security professionals. Founded in 2023 by Cédric Herzog as a SARL with EUR 15,000 share capital, the company operated in development mode before launching its public product in April 2025.

The platform performs multi-dimensional security analysis on codebases through a plugin-based architecture supporting multiple programming languages, and integrates with the major developer-tooling ecosystem including GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps. Its AI capability is delivered through integration with VLAI (Vulnerability-Lookup AI) operated by CIRCL, which provides RoBERTa-based NLP models trained on more than 600,000 vulnerability advisories to generate contextual vulnerability scoring and remediation guidance. The product is distributed under the AGPL-3.0 license with the codebase publicly available, and is positioned against regulatory drivers including the EU Cyber Resilience Act, US Executive Order 14028, and NIS2.

The business model is open-source-first with the core platform freely accessible; no pricing tiers, paid plans, paying customer logos, revenue figures, or funding rounds have been disclosed. The company has been validated through the Fit4Start#14 accelerator (2023), the Luxembourg Cybersecurity Startup Award (2023), and participation in FIC 2025. As of February 2026 the product remains in alpha stage at v0.0.25-alpha.

CodeClarity firmographics

Firmographics
Name
CodeClarity
Legal name
CodeClarity S.à r.l.
Website
https://www.codeclarity.io
Company type
Private
Founded year
2023
Operating status
Operating
Headcount range
1–10 employees
Short description
CodeClarity is a Luxembourg-based open-source security analysis platform that helps software development, DevOps, and security teams detect and prioritize vulnerabilities across multiple programming languages via integrations with GitHub, GitLab, ClickUp, Jenkins, and Azure DevOps.
Ownership category
akta.pro rank

CodeClarity industry classification

Industry
Product category
Application Security
NAICS
Software Publishers (513210)
SIC
Services-Prepackaged Software (7372)
akta.pro primary industry
Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
akta.pro secondary industry
Code & Repository Security (Git Security, Code Integrity) (HDADACAG)

Keywords

  • Open-source security analysis
  • Software composition analysis
  • Vulnerability scanning platform
  • SBOM generation tools
  • License compliance analysis

Where CodeClarity is headquartered

Location

Headquarters

HQ city
Charlotte
HQ country
United States
HQ region
North America

Offices1 record

Markets served

CodeClarity business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Infrastructure

Revenue model

  1. Open-source Free Tier: Core security analysis features are completely free. Open-source platform available via GitHub with self-hosting options. Targets individual developers, startups, and organizations seeking accessible security tooling.
  2. Enterprise/Cloud Hosting (Inferred): CodeClarity Cloud hosted platform at platform.codeclarity.io implies potential managed service offering. Enterprise support or cloud-hosted tiers may be available for organizations preferring managed infrastructure over self-hosting.

Pricing tiers

ModelBillingPrice
FreemiumOthersFree Open-Source Tier

Go-to-market motion3 records

Distribution channels4 records

Marketing channels7 records

CodeClarity product offering

Product offering

Core offering

CodeClarity is an open-source security analysis platform that performs fast source code analysis to reveal software dependencies, licenses, and vulnerabilities. It generates Software Bills of Materials (SBOMs), performs static and reachability analysis, and applies AI-based vulnerability prioritization to help development teams secure their software supply chain. The platform is offered both as a hosted cloud service (platform.codeclarity.io) and as a self-hosted Docker deployment.

Product overview

CodeClarity is an open-source security analysis platform that provides comprehensive software security through a modular plugin architecture. The core CodeClarity Platform delivers source code analysis, SBOM generation, vulnerability scanning, patching, and license compliance management. The platform is extended through specialized plugins including the JavaScript SBOM Plugin (supporting npm, pnpm, and Yarn), CodeQL Plugin for JS/Go/Python analysis, Vulnerability Scanner Plugin (integrating with NVD, OSV, GCVE), License Compliance Plugin, and Patching Plugin. AI-powered features are enabled through VLAI integration for smart vulnerability prioritization. CI/CD integration is available via the CodeClarity GitHub Action. The platform also includes a built-in ticket management system for tracking remediation workflows, with ClickUp integration for syncing tickets to external project management tools.

Differentiator

Problem solved

Functional benefit

Products and services

  • CodeClarity Platform
  • CodeClarity GitHub Action
  • Ticket Management System (built-in to CodeClarity)

Quantifiable outcome

  • 80% of codebases contain at least one dependency vulnerability
  • +2 more outcomes

Companies that use CodeClarity

Customer profile

Segments4 records

Ideal customer profiles1 record

CodeClarity technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration6 records

AI capability6 records

Feature12 records

CodeClarity partnerships and signals

Strategic signal

Partnerships

Seven partnerships are on record, tiered supporting and core.

  • ClickUpsupportingTechnology or Integration · 4 January 2026ClickUp integration enables security tickets to sync directly to ClickUp workspaces. Supports both OAuth and API Key authentication methods. Part of broader project management integration roadmap including Jira and Linear.
  • VLAI (Vulnerability Lookup AI) / CIRCLcoreTechnology or Integration · 4 July 2025CIRCL (Computer Incident Response Center Luxembourg) provides VLAI, an AI-powered vulnerability assessment service using NLP models trained on 600,000+ vulnerability advisories. CodeClarity integrates VLAI for smarter vulnerability prioritization with confidence scoring beyond traditional CVSS ratings.
  • GitHubcoreTechnology or IntegrationGitHub provides integration with CodeClarity's security scanning. The platform offers GitHub Action for automated CI/CD security scanning available on GitHub Marketplace. Users can import projects via GitHub URL and configure GitHub integration for vulnerability tracking.
  • GitLabcoreTechnology or IntegrationGitLab integration allows seamless connection with GitLab version control systems. Users can import repositories by providing GitLab URLs and integrate CodeClarity with GitLab workflows.
  • Vulnerability-LookupsupportingTechnology or IntegrationIntegration with Vulnerability-Lookup allows CodeClarity to push analysis results as sightings. When projects are public and API key is configured, vulnerabilities found are automatically submitted as sightings to the Vulnerability-Lookup platform.
  • Luxembourg House of CybersecuritysupportingStrategic or Co-development PartnerGovernment-backed cybersecurity body that awarded CodeClarity the Cybersecurity Startup Award during CYBERSECURITY Week Luxembourg 2023. Provides ecosystem support and validation for Luxembourg cybersecurity startups.
  • Luxinnovation GIEsupportingStrategic or Co-development PartnerLuxembourg's national innovation agency that runs the Fit4Start accelerator program. Selected CodeClarity for Fit4Start#14, providing acceleration support, mentorship, and ecosystem connections for startup growth.

Scale indicators5 records

Recent moves6 records

Expansion highlights6 records

CodeClarity competitors and assessment

Company assessment

Direct peers

  • JFrog Xray: JFrog Xray provides deep dependency analysis, vulnerability scanning, and license compliance for software supply chains — overlapping with CodeClarity's SBOM and vulnerability detection capabilities.
  • Mend (formerly WhiteSource): Mend offers SCA with SBOM generation, vulnerability prioritization, and license compliance — a direct competitor to CodeClarity, particularly in the open-source dependency analysis segment.
  • Sonatype Nexus: Sonatype's Nexus platform (including Nexus Lifecycle) provides SCA, dependency management, and license compliance — directly comparable to CodeClarity's open-source security analysis positioning.
  • Snyk: Snyk is a leading developer-centric security platform with comprehensive SCA capabilities (Snyk Open Source) — direct overlap with CodeClarity's SBOM, vulnerability scanning, and CI/CD integration. Snyk is explicitly cited as a peer in CodeClarity's market positioning.
  • GitHub Dependabot: GitHub's native Dependabot (plus GitHub Advanced Security) provides dependency scanning, SBOM, and automated PR-based patching directly within the GitHub workflow — the most direct free/embedded competitor to CodeClarity's GitHub Action.
  • Anchore: Anchore provides enterprise-grade SCA with SBOM generation, vulnerability scanning, and policy-based compliance — a direct competitor especially in regulated industries and containerized software supply chains.
  • Aqua Security Trivy: Trivy is an open-source vulnerability scanner covering dependencies, containers, and IaC — closely comparable to CodeClarity as a free, extensible, developer-focused open-source SCA tool with strong community adoption.
  • Synopsys Black Duck: Black Duck is a pioneer in open-source security and SCA, offering SBOM generation, vulnerability detection, and license compliance — directly overlapping with CodeClarity's feature set. Explicitly cited as a competitor.
  • Checkmarx: Checkmarx offers SCA (CxSCA) alongside its SAST portfolio, providing SBOM, vulnerability detection, and license compliance — directly competitive with CodeClarity's core capabilities. Explicitly cited as a competitor in CodeClarity's positioning.

Emerging players

  • OWASP Dependency-Check: OWASP Dependency-Check is an open-source SCA tool that identifies project dependencies and checks for known vulnerabilities — a free, community-driven alternative that competes for the same open-source-aware developer audience as CodeClarity.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks6 records

Key highlights7 records

Customer concentration

CodeClarity social profiles

Digital presence

CodeClarity financial estimates

Financial estimate

Revenue estimate

Valuation estimate

CodeClarity leadership team

Management profile

Number of profiles

Profiles1 record

CodeClarity funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

CodeClarity M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about CodeClarity

What does CodeClarity do?

CodeClarity is an open-source security analysis platform that performs fast source code analysis to reveal software dependencies, licenses, and vulnerabilities. It generates Software Bills of Materials (SBOMs), performs static and reachability analysis, and applies AI-based vulnerability prioritization to help development teams secure their software supply chain. The platform is offered both as a hosted cloud service (platform.codeclarity.io) and as a self-hosted Docker deployment.

Is CodeClarity a public or private company?

CodeClarity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.

When was CodeClarity founded?

CodeClarity was founded in 2023. It employs 1 to 10 people.

Where is CodeClarity based?

CodeClarity is headquartered in Charlotte, United States, in the North America region.

How does CodeClarity make money?

Two revenue lines are on record. Open-source Free Tier is the primary driver. The others are enterprise/Cloud Hosting (Inferred).

Who are CodeClarity's main competitors?

Direct peers on record are JFrog Xray, Mend (formerly WhiteSource), Sonatype Nexus, Snyk, GitHub Dependabot, Anchore, Aqua Security Trivy, Synopsys Black Duck and Checkmarx. OWASP Dependency-Check is listed as an emerging player.

Does CodeClarity have an API?

Yes. CodeClarity exposes REST endpoints for scheduling and notifications via its NestJS API layer. The platform supports API key authentication for integrations and provides CLI commands for automation and scripting. Integration endpoints allow programmatic project management, vulnerability scanning, and ticket operations. Developer documentation is at doc.codeclarity.io.

What industry is CodeClarity in?

CodeClarity's product category is Application Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 513210 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales