Corridor
Corridor provides an Agentic Coding Security Management (ACSM) platform that prevents vulnerabilities in AI-generated code via MCP server and deterministic hooks, integrated natively with Cursor, Claude Code, Codex, Factory, and Devin, sold to security and engineering teams.
- Company typePrivate
- Founded2025
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Corridor does
Corridor (legally Corridor Security Inc., a Delaware corporation headquartered in San Francisco) provides a security platform purpose-built for AI-generated code, branded as Agentic Coding Security Management (ACSM). Founded in early 2025 by former CISA senior technical adviser Jack Cable and Stanford foundation-model researcher Ashwin Ramaswami, with former Facebook/Yahoo/SentinelOne CSO Alex Stamos as CPO, the company addresses the gap between AI-accelerated software development and traditional post-hoc security scanning. Its platform combines an MCP (Model Context Protocol) server that injects security context into coding agents at the planning stage with deterministic agent hooks that perform post-generation security reviews, complemented by an organization-wide observability dashboard, automated GitHub/GitLab PR security reviews, custom codebase-aware guardrails, and MCP server allowlist/blocklist enforcement for governing third-party agents.
The underlying technology integrates natively with every major agentic coding environment — Cursor, Claude Code, OpenAI Codex CLI, Factory Droids, Cognition Devin, and GitHub Copilot/VS Code — and is distributed through the Cursor, Vercel, AWS, and Devin marketplaces. A one-command CLI installer auto-detects installed coding agents and configures the full MCP-plus-hooks stack. Corridor's commercial model is a hybrid of self-serve product-led growth and sales-assisted enterprise sales: Pro is priced at $20/month and Team at $40/developer/month on annual billing (20% annual discount), with a free trial entry point, while Enterprise is quote-based and adds codebase chat, custom guardrails, unlimited usage, and enterprise security controls. The company reached general availability on October 23, 2025, raised a $5.4M seed led by Conviction in August 2025, and closed a $25M Series A at a $200M post-money valuation led by Felicis in March 2026, with strategic angels from Anthropic, OpenAI, Cursor, Cognition, Factory, and Lovable.
Corridor firmographics
Firmographics- Name
- Corridor
- Legal name
- Corridor Security Inc.
- Website
- https://corridor.dev
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Corridor provides an Agentic Coding Security Management (ACSM) platform that prevents vulnerabilities in AI-generated code via MCP server and deterministic hooks, integrated natively with Cursor, Claude Code, Codex, Factory, and Devin, sold to security and engineering teams.
- Ownership category
- akta.pro rank
Corridor industry classification
Industry- Product category
- Application Security Software
- NAICS
- Computer Systems Design and Related Services (54151), Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industry
- DEX Aggregation & On-Chain Execution (routing, RFQ, intent-based trading) (FSAPAEAD)
Keywords
Where Corridor is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Corridor business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Subscriptions (Pro, Team, Enterprise): SaaS subscriptions sold on annual billing cadence: Pro at $20/month (individual developers, up to 5 projects, 100 PR reviews/mo), Team at $40/developer/month (up to 20 projects, 100 PR reviews/developer/mo), and Enterprise (Contact Sales, unlimited projects/PRs, custom guardrails, codebase chat). Free trial available via self-serve sign-up. Annual plans save 20%.
- Third-Party Marketplace Sales: Distribution via Third Party Marketplaces (Cursor, Vercel, AWS, GitHub Copilot/VS Code, Cognition Devin) where customers pay fees to the marketplace provider at Corridor's published rates.
- Freemium / Free Trial: Self-serve free trial entry point (Get Started for Free) to drive adoption and convert users to paid Pro, Team, or Enterprise subscriptions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Per seat | Annual | Pro for individual developers: $20/month billed annually (up to 5 projects, 100 PR reviews/month). |
| Per seat | Annual | Team for engineering teams: $40/developer/month billed annually (up to 20 projects, 100 PR reviews/developer/month). |
| Subscription | Annual | Enterprise: Contact Sales (unlimited projects and PR reviews, codebase chat, enterprise security). |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels6 records
Corridor product offering
Product offeringCore offering
Corridor sells an Agentic Coding Security Management (ACSM) software platform that integrates directly with AI coding agents (Cursor, Claude Code, Codex, Factory Droids, Devin, GitHub Copilot) via an MCP server and deterministic agent hooks. The platform prevents security vulnerabilities at the point of AI-generated code, performs real-time pull request security reviews, and provides an organization-wide observability dashboard for AI coding activity and MCP server policy enforcement. It is delivered as a hosted SaaS service sold via Pro, Team, and Enterprise subscription tiers and distributed through multiple developer-tool marketplaces.
Product overview
Corridor offers a unified Agentic Coding Security Management (ACSM) platform composed of several tightly integrated modules. The core ACSM platform is delivered as a hosted software security service (the Hosted Services) and is paired with an IDE Plugin, an MCP Server, deterministic Hooks for post-generation checks, a CLI installer, automated Pull Request Security Reviews, and a Dashboard for organization-wide observability. Enterprise customers additionally receive a Codebase Chat capability. Together, these modules prevent vulnerabilities at the source of AI-generated code while providing security teams with full visibility and policy control over AI coding activity.
Differentiator
Problem solved
Functional benefit
Brands
- ACSM (Agentic Coding Security Management): Corridor's flagship platform category and product offering for managing the security of AI-generated and agentic code throughout the development lifecycle.
Products and services
- Agentic Coding Security Management (ACSM) Platform Corridor's flagship hosted SaaS platform that prevents security vulnerabilities at the point of AI-generated code, runs real-time pull request reviews, enforces custom and codebase-specific guardrails, and provides an organization-wide AI Coding Observability Dashboard. Sold via Pro ($20/month), Team ($40/developer/month), and Enterprise (Contact Sales) subscription tiers with a self-serve free trial.
- Corridor Cursor Plugin Plugin on the Cursor Marketplace that delivers real-time, in-IDE security reviews for code generated in Cursor via the Corridor MCP server and API integration.
- Corridor Codex Integration Two-layer native integration with the OpenAI Codex CLI: the Corridor MCP server enforces security policies at the planning stage and deterministic hooks run post-generation security reviews plus MCP compliance checks on macOS. Generally available via the Corridor CLI installer.
- Corridor Factory Integration (Native CLI + Droid Hooks) Native integration with the Factory CLI and Droids: the Corridor MCP server provides plan-stage security context and Droid Hooks perform deterministic post-generation security scans and MCP server compliance checks. One-step CLI install enables coverage of Factory's autonomous Droids.
- Corridor Cursor Hooks Integration Hooks integration with Cursor that runs deterministic post-code-generation security reviews on diffs and enables MCP server management hooks for policy enforcement, addressing the non-determinism of MCP-only flows.
Quantifiable outcome
- Investors valued the company at $200 million in its Series A round announced March 18, 2026.
- +3 more outcomes
Companies that use Corridor
Customer profileNamed customers12 records
Segments4 records
Ideal customer profiles3 records
Corridor technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability9 records
Feature8 records
Corridor partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered flagship and core.
- CursorflagshipCursor is both an angel investor and a deep technology partner. Corridor ships native Cursor Hooks integration (announced December 22, 2025) and a Cursor Plugin on the Cursor Marketplace (May 2026); Cursor's blog lists Corridor among its Hooks partners.
- FactoryflagshipFactory is both an angel investor and a deep technology partner. Corridor integrates with the Factory CLI and Droid Hooks (announced March 4, 2026 and October 30, 2025), providing MCP-based security context and post-generation scans for Factory's autonomous Droids.
- CognitioncoreAngel investor and integration partner — Corridor is available in the Cognition Devin MCP Marketplace (app.devin.ai/settings/mcp-marketplace/setup/corridor).
- Claude Code (Anthropic)coreCorridor integrates with Anthropic's Claude Code IDE assistant via its MCP server and hooks, documented at docs.corridor.dev/ide-setup/claude-code.
- VercelcoreCorridor is distributed via the Vercel Marketplace (vercel.com/marketplace/corridor). Vercel also recently launched AI tools that integrate security/AI workflows, complementing Corridor's positioning.
- AWS MarketplacecoreCorridor went live on the AWS Marketplace on December 1, 2025 (announced ahead of AWS re:Invent), enabling enterprise procurement through AWS.
- GitHub Copilot / VS Code MarketplacecoreCorridor ships a VS Code extension (corridor.Corridor) on the Visual Studio Marketplace, integrating real-time PR security reviews and IDE guardrails with GitHub Copilot workflows.
- OpenAI Codex CLIcoreCorridor launched native integration with OpenAI's Codex CLI on May 28, 2026, operating at both the MCP layer (policy enforcement) and hooks layer (post-generation reviews and MCP compliance checks) — distributed via a one-step installer that auto-configures the Corridor MCP server for Codex.
- ChainguardflagshipCorridor is a founding member of the Chainguard-led Athena industry coalition (announced June 2026), which pools open-source vulnerability findings, ships patches before public disclosure, and coordinates with the Linux Foundation. Other members include BNY, Cisco, Cloudflare, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree, and PwC.
Scale indicators8 records
Recent moves6 records
Expansion highlights7 records
Corridor competitors and assessment
Company assessmentOthers
- Chainguard: Chainguard is a software supply-chain security company focused on hardened container images and is the leader of the Athena coalition Corridor joined as a founding member. It is comparable as a partner/ecosystem player in the broader secure-software-development stack rather than a direct competitor.
Broad incumbents
- Snyk: Snyk is a large developer-security platform offering SAST, SCA, and container security with an established enterprise sales motion. It is comparable as a code-security vendor targeting the same AppSec buyer, but its AI-coding-native real-time guardrail product is less mature than Corridor's ACSM approach.
- Sonar (SonarSource): Sonar provides SonarQube/SonarCloud for code quality and security analysis widely adopted in enterprise CI pipelines. It is comparable as a long-standing SAST/code-security incumbent with similar PR-review and developer-platform integrations.
- GitHub Advanced Security (CodeQL): GitHub Advanced Security (CodeQL + Copilot) is GitHub's native code-scanning suite embedded in the GitHub platform. It is the most direct incumbent threat because GitHub controls the PR-review surface that Corridor reviews and could add comparable AI-aware security features natively.
Direct peers
- CodeRabbit: CodeRabbit provides AI-driven pull-request code reviews directly in GitHub. It is a direct peer in the AI-native PR review category, though CodeRabbit focuses on quality/maintainability while Corridor focuses on security vulnerabilities and agent governance.
- Semgrep: Semgrep is a developer-first SAST platform with custom rule writing and CI-native scanning. It is a direct peer to Corridor's PR-security-review functionality, though Semgrep is a generic SAST scanner whereas Corridor is purpose-built for AI-generated code.
Emerging players
- Aikido Security: Aikido Security is an emerging all-in-one application security platform (SAST, SCA, DAST) targeting developers and security teams with consolidated code-to-cloud coverage. It is comparable as a modern challenger in the same AppSec buying motion.
- Apiiro: Apiiro provides code-to-cloud application security with deep code analysis and risk prioritization. It is comparable as a modern code-risk platform pursuing similar enterprise AppSec buyers with AI-driven analysis.
- Cycode: Cycode is an application security posture management (ASPM) platform with code-to-cloud visibility including SAST, SCA, and pipeline security. It is comparable as a platform-level AppSec vendor pursuing similar enterprise buyers with consolidated code-security coverage.
- Socket: Socket provides AI-aware supply-chain security for open-source dependencies. It is comparable as a developer-security vendor using AI/ML analysis to surface threats in code and packages, sharing Corridor's developer-first, AI-native approach to security.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat8 records
Key risks6 records
Key highlights7 records
Customer concentration
Corridor social profiles
Digital presenceCorridor compliance and trust
Trust signalCompliance3 records
Corridor financial estimates
Financial estimateRevenue estimate
Valuation estimate
Corridor leadership team
Management profileNumber of profiles
Profiles3 records
Corridor funding detail
Funding detailFunding overview
Funding rounds2 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Corridor M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Corridor
What does Corridor do?
Corridor sells an Agentic Coding Security Management (ACSM) software platform that integrates directly with AI coding agents (Cursor, Claude Code, Codex, Factory Droids, Devin, GitHub Copilot) via an MCP server and deterministic agent hooks. The platform prevents security vulnerabilities at the point of AI-generated code, performs real-time pull request security reviews, and provides an organization-wide observability dashboard for AI coding activity and MCP server policy enforcement. It is delivered as a hosted SaaS service sold via Pro, Team, and Enterprise subscription tiers and distributed through multiple developer-tool marketplaces.
Is Corridor a public or private company?
Corridor is a private company. It is classified as venture growth investor backed and is currently operating.
When was Corridor founded?
Corridor was founded in 2025. It employs 11 to 50 people.
Where is Corridor based?
Corridor is headquartered in San Francisco, United States, in the North America region.
How does Corridor make money?
Three revenue lines are on record. Software Subscriptions (Pro, Team, Enterprise) is the primary driver. The others are third-Party Marketplace Sales and freemium / Free Trial.
Who are Corridor's main competitors?
Chainguard is listed as an others. Broad incumbents are Snyk, Sonar (SonarSource) and GitHub Advanced Security (CodeQL). Direct peers are CodeRabbit and Semgrep. Emerging players are Aikido Security, Apiiro, Cycode and Socket.
Does Corridor have an API?
Yes. Corridor offers an API key-based integration (https://app.corridor.dev/settings) used to authenticate the Cursor Plugin and CLI installer for full feature access. Corridor's core product is itself an MCP (Model Context Protocol) server that integrates with coding agents; the Corridor CLI installs the MCP server and hooks for supported agents. Documentation is hosted at docs.corridor.dev with IDE-specific setup guides for Claude Code, Codex, and Factory. Auth0 is used for signup/authentication. Stripe is used as a payment processor for Pro and Team subscription tiers. Developer documentation is at docs.corridor.dev.
What industry is Corridor in?
Corridor's product category is Application Security Software. Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of FSAPAEAD, DEX Aggregation & On-Chain Execution (routing, RFQ, intent-based trading). Its NAICS code is 54151 and its SIC code is 7372.