Loading organizations...
Legit Security offers an AI-native Application Security Posture Management (ASPM) platform, automating discovery, prioritization, and remediation of application security issues. Key capabilities include unified vulnerability management, comprehensive code security (SAST, SCA), secrets detection, and robust software supply chain protection. The platform secures both traditional and AI-generated code within modern development pipelines.
Roni Fuchs, Lior Barak, and Liav Caspi co-founded the company in 2020. Their insight identified a critical gap: traditional application security tools struggled with the complexities of AI-driven development and modern software supply chains. This understanding fueled their mission to build a platform tailored for these evolving security challenges.
Legit Security serves organizations overseeing AppSec and software supply chain security initiatives. Its vision centers on establishing inherent security throughout the entire software development lifecycle, from code commits through cloud deployment. The company aims to deliver intelligent, proactive security solutions adapting to rapid technological advancements.
Legit Security has raised $74.0M across 3 funding rounds.
Legit Security has raised $74.0M in total across 3 funding rounds.
Legit Security has raised $74.0M across 3 funding rounds. Most recently, it raised $40.0M Series B in September 2023.
| Date | Round | Lead Investors | Other Investors | Status |
|---|---|---|---|---|
| Sep 1, 2023 | $40M Series B | CRV, James Green | Accel, Bain Capital Ventures, Bessemer Venture Partners, Cyberstarts VC, Haystack, Lightspeed Venture Partners, NFX, Nine Four Ventures, Openview Venture Partners, Transmedia Capital, Twenty TWO Ventures, Vertex Ventures Israel, Zeev Capital, Ariel Maislos, Assaf Rappaport, Gili Raanan, TCV | Announced |
| Feb 1, 2022 | $30M Series A | Bessemer Venture Partners, TCV | Accel, Lightspeed Venture Partners, Openview Venture Partners, Vertex Ventures Israel, Cyberstarts | Announced |
| Aug 1, 2020 | $4M Seed | — | Cyberstarts VC, NFX, WestWave Capital, Zeev Capital, Ariel Maislos, Assaf Rappaport, Vivek Patel | Announced |
# High-Level Overview
Legit Security is an application security posture management (ASPM) platform that automates security across the software development lifecycle (SDLC), from code to runtime.[3] The company provides end-to-end visibility into development environments, CI/CD pipelines, and code repositories, enabling organizations to detect and prioritize vulnerabilities, manage secrets, enforce compliance policies, and secure AI-generated code.[1][2][5]
The platform serves enterprise software development teams and cloud computing organizations that need to integrate security seamlessly into DevOps workflows without sacrificing development speed.[2] Legit's core mission is to help organizations "quickly understand risks, tackle the biggest issues, and deliver more secure products" by giving security teams visibility and control over their entire attack surface.[6] The company addresses a critical pain point: security teams are overwhelmed with vulnerability data, lack visibility into development environments, and struggle to prioritize which issues matter most to their business.[6]
# Origin Story
Legit Security was founded in 2020 and is based in Tel Aviv, Israel.[3] The company was established by a team with deep expertise in application security and enterprise software. CEO Roni previously led Product and Business Units at Checkmarx and Microsoft (following startup acquisitions), and earlier worked in the Israeli Defense Force's Unit 8200, a prestigious technology and intelligence unit.[6]
The founding team recognized that traditional security approaches were failing modern development organizations. As development velocity accelerated and AI tools became ubiquitous in coding, security teams found themselves drowning in vulnerability alerts without sufficient context to act effectively.[6] This insight drove Legit's creation as a platform designed to inject intelligence and prioritization into the security process, transforming security from a bottleneck into an enabler of faster, safer development.
# Core Differentiators
# Role in the Broader Tech Landscape
Legit Security operates at the intersection of several powerful trends reshaping enterprise security. The software supply chain has become a primary attack vector, with adversaries increasingly targeting development processes rather than just production systems.[2] This shift has elevated ASPM from a niche concern to a critical enterprise requirement.
Simultaneously, AI-driven development is accelerating faster than security practices can adapt. The rapid adoption of AI coding assistants has introduced new blind spots—organizations lack visibility into AI-generated code and its security implications.[5] Legit's AI-native approach positions it to capture value as enterprises grapple with securing this new development paradigm.
The company also benefits from the convergence of IT and OT (operational technology) security, as critical infrastructure increasingly relies on software and connected systems.[4] This expands the addressable market beyond traditional software companies to energy, manufacturing, and other sectors managing critical infrastructure.
Legit's emphasis on reducing security team cognitive overload—by providing context rather than noise—aligns with a broader industry recognition that security effectiveness depends on prioritization and actionability, not alert volume. This philosophy influences how the entire ASPM market is evolving.
# Quick Take & Future Outlook
Legit Security is well-positioned to capture significant market share in the rapidly growing ASPM category. The company's timing is optimal: enterprises are simultaneously grappling with AI-driven development, supply chain security mandates, and the need to maintain development velocity. By solving the "too much data, not enough context" problem that plagues security teams, Legit addresses a genuine pain point with measurable ROI.
The company's trajectory will likely be shaped by how comprehensively it can extend its platform into adjacent security domains—particularly AI code security and operational technology environments. As regulatory pressure around software supply chain security intensifies globally, platforms that provide both visibility and compliance automation will become table stakes for enterprise development organizations.
Legit's founding team's pedigree (Checkmarx, Microsoft, Israeli Defense Force) and backing from prominent venture investors suggest strong execution capability. The key question for the next phase is whether Legit can maintain its developer-friendly positioning while scaling to enterprise complexity—a challenge that has defined winners and losers in the application security space.
Legit Security has raised $74.0M in total across 3 funding rounds.
Legit Security's investors include CRV, James Green, Accel, Bain Capital Ventures, Bessemer Venture Partners, Cyberstarts VC, Haystack, Lightspeed Venture Partners, NFX, Nine Four Ventures, Openview Venture Partners, Transmedia Capital.