Skip to content

CodeLock

A DevSecOps startup building automated software-supply-chain integrity tooling that links every code change to a verifiable developer chain of custody.

Visit Website ↗ + Add to Compare
55/100Incremental Innovator

Overview

CodeLock builds software-supply-chain security tooling that operates at the code level rather than just scanning for known vulnerabilities. Its platform creates what the company calls a forensic chain of custody, cryptographically linking every code change to the developer who made it, so organizations can verify code authenticity and integrity from development through deployment. It also automates Software Bill of Materials (SBOM) generation and compliance dashboards mapped to frameworks like NIST 800-218 (the Secure Software Development Framework).

Founded in 2021 and headquartered in Ashburn, Virginia, CodeLock has raised roughly $6.72 million from a syndicate of angel and venture investors, including SoundBoard Venture Fund, Executive Venture Fund, Oakseed Ventures, and Sancus Ventures. The Department of Homeland Security has publicly stated that CodeLock "appears to have the capability to stop the most sophisticated malware," and the company has been recognized by TechCrunch among notable early-stage startups.

CodeLock’s angle — provenance and chain-of-custody verification rather than dependency scanning — addresses a different problem than traditional SAST/SCA tools: it’s aimed at proving that code wasn’t tampered with, in the mold of software supply-chain incidents like SolarWinds, rather than only flagging known-vulnerable components. As a small, young company, its independent, named enterprise track record is still thin relative to its DHS endorsement and funding.

Innovation Matrix Assessment

Innovation Velocity 5/10

Raising $6.72M and shipping a differentiated SBOM/chain-of-custody product within about four years of founding is a reasonable, if not exceptional, pace for a company this size.

Operational Value 5/10

A small team (around 11 employees) runs a functioning SaaS product with automated compliance dashboards, indicating real but early-stage operational maturity.

Market Momentum 5/10

A public DHS endorsement quote and a TechCrunch mention provide external validation and visibility beyond typical seed-stage press.

Category Disruption 6/10

Linking code changes to a verifiable developer chain of custody targets code provenance and tamper-evidence rather than known-vulnerability scanning, a genuinely different angle from typical SAST/SCA tools.

Real-World Efficacy 5/10

The DHS quote is a real, independently findable endorsement, which is stronger than pure marketing copy, but no independent lab evaluation or named enterprise deployment with measured results was found.

Enduring Relevance 7/10

Executive Order 14028 and the NIST Secure Software Development Framework have turned SBOM generation and software provenance into live compliance requirements, making this directly relevant to current CISO and federal-supplier priorities.

Why CISOs Should Care

Executive Order 14028 and NIST SSDF have made SBOM generation and software provenance a compliance requirement rather than just a best practice, and CodeLock automates the evidentiary trail that requirement demands.

What Makes It Different

Focuses on cryptographically linking every code change to its developer to create a verifiable chain of custody, rather than scanning code or dependencies for already-known vulnerabilities the way traditional SAST/SCA tools do.

The Matrix Verdict

55/100 — INCREMENTAL INNOVATOR

A focused software-supply-chain-integrity play with a real, if unusual, DHS endorsement behind it and funding from a credible if modest investor syndicate. Independent, named-customer proof of efficacy at scale is still thin for a company this young.

Editorial Note: Claims vs. Verified Findings

The DHS endorsement quote is independently findable and attributed, a stronger signal than typical vendor marketing. The funding total ($6.72M) is sourced from PitchBook/Crunchbase aggregation rather than a company press release. No independent lab test or named enterprise case study was found, so specific efficacy claims beyond the DHS quote should be treated as vendor-sourced.

Sources