Mend provides a unified platform that secures code, open‑source dependencies, containers, and AI components through continuous reachability‑based testing, AI red‑team simulations, and automated remediation. It prioritizes exploitable risks using EPSS and CVSS 4.0 scores, generates AI‑driven fixes, and enforces policy‑driven compliance for standards such as NIST, ISO, and the EU AI Act.
Funding
$75M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.
3OPVFounders
Product
Problem
Modern software development faces hidden vulnerabilities in open‑source dependencies, AI models, and runtime behavior that traditional static analysis and pre‑deployment scans cannot detect. Organizations also struggle to keep up with continuous delivery cycles, leading to delayed remediation and compliance gaps.
Solution
Mend offers a unified platform that combines application security (SAST, SCA, container scanning), AI security (AI‑BOM, red‑team testing, prompt hardening, runtime guardrails), and automated remediation (AI‑generated fixes and dependency updates). The platform continuously inventories code and AI components, runs reachability‑based testing on every build, and prioritizes exploitable risks using EPSS and CVSS 4.0 scores. AI‑driven fixes and automated pull‑request updates reduce remediation effort by up to 75%, while real‑time behavioral controls protect applications in production. Integrated policy engines enforce licensing and regulatory compliance, delivering audit‑ready evidence for standards such as NIST, ISO, and the EU AI Act.
Target Audience
Primary customers are development and DevSecOps teams in enterprises that need to secure proprietary code, open‑source components, and AI‑enabled applications, as well as compliance officers responsible for regulatory adherence.
Features
- High‑precision differential SAST with 38% higher precision and 48% higher recall than benchmark tools
- Reachability‑driven SCA that surfaces exploitable open‑source and container risks first, prioritized by EPSS and CVSS 4.0
- AI‑BOM and continuous inventory of models, agents, and “shadow AI” across the software supply chain
- Automated AI red‑team testing for prompt injection, data leakage, hallucination, and other behavioral threats
- AI‑generated code fixes and automated dependency updates (Mend Renovate) that cut remediation time by up to 75%
- Runtime in‑application protection that monitors live interactions, enforces policy, and blocks unsafe behavior without patch cycles
- Policy engine for licensing and regulatory compliance, producing machine‑readable SBOMs and compliance reports aligned with NIST, ISO, EU AI Act, and other frameworks
- Deep integrations with IDEs, CI/CD pipelines, repositories, and package managers for seamless developer workflow