Skip to main content
S

StackHawk

StackHawk provides an automated dynamic application security testing (DAST) platform that integrates with CI/CD workflows to identify and prioritize exploitable vulnerabilities in APIs and applications. By enabling continuous security testing early in the software development lifecycle, StackHawk helps teams reduce the risk of security breaches and accelerate the delivery of secure code.

Denver, United StatesFounded 2019453K+ followers
Updated 20 months ago

Funding

$35.4M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

CV
Funding rounds are not available yet.

Founders

Product

Problem

Modern software development relies heavily on APIs, but traditional security testing methods often fail to keep pace with rapid development cycles. This can lead to exploitable vulnerabilities in APIs and applications, increasing the risk of security breaches. Existing Dynamic Application Security Testing (DAST) solutions can be slow, noisy, and difficult to integrate into CI/CD pipelines.

Solution

StackHawk provides an automated DAST platform designed for modern software teams, enabling continuous security testing throughout the software development lifecycle (SDLC). The platform integrates directly into CI/CD workflows, allowing developers to identify and address vulnerabilities early and often. By automating API discovery and security testing, StackHawk helps teams gain visibility into their attack surface, prioritize actionable insights, and ship secure code at scale. The platform's developer-centric approach empowers teams to shift security left, reducing the risk of security breaches and accelerating the delivery of secure applications and APIs.

Target Audience

StackHawk is designed for development, DevOps, and AppSec teams that need to automate security testing within their CI/CD pipelines and shift security left, including those in health tech, financial services, and industrial automation.

Features

  • Automated API discovery to identify all APIs within the application's attack surface
  • Dynamic analysis of REST, GraphQL, gRPC, and SOAP APIs
  • Custom scan discovery using Postman Collections, Cypress, Selenium, or other test scripts
  • Authentication as code for reliable scanning of authenticated routes and API endpoints
  • Integration with CI/CD tools such as GitHub, Snyk, AWS, Atlassian, and Microsoft Azure DevOps
  • Real-time vulnerability alerts and notifications via Slack, Jira, and Azure DevOps Boards
  • Detailed scan reports with actionable insights and cURL-based validation commands
  • Role-based access control and team-based access for managing findings across the organization
  • API access for major functionality, scan results, and audit logs
This profile is AI-generated and may contain inaccuracies.