Onapsis
Application security platform purpose-built for SAP and Oracle business-critical ERP applications, backed by a research team credited with multiple CISA-cataloged critical SAP vulnerabilities.
Visit Website ↗ + Add to CompareOverview
Onapsis provides a security and compliance platform purpose-built for SAP and Oracle business-critical applications — ERP systems that run finance, supply chain, and core operations for large enterprises but that traditional application-security and vulnerability-scanning tools generally do not cover well. The Onapsis Platform covers vulnerability and configuration management, code security, and threat detection specific to SAP/Oracle environments, and its Onapsis Research Labs team works directly with SAP’s own Product Security Response Team to find and help patch critical vulnerabilities before they are exploited.
That research relationship has produced independently significant results: Onapsis Research Labs co-discovered the 2022 ICMAD vulnerabilities (including CVE-2022-22536, rated a maximum CVSS 10.0), which CISA added to its Known Exploited Vulnerabilities catalog and which affected up to 40,000 SAP customers; more recently, Onapsis Research Labs directly observed active exploitation of CVE-2025-31324 and CVE-2025-42999, both of which CISA also added to its Known Exploited Vulnerabilities catalog in 2025. This is a rare case of a vendor’s security research being independently validated by a government agency’s own exploitation tracking rather than resting on the vendor’s own claims.
Founded in 2009 (originating in Argentina before relocating its headquarters to Boston, with offices in Heidelberg and Buenos Aires), Onapsis has raised roughly $116 million across multiple funding rounds, including a $55 million Series D led by CDPQ and NightDragon to expand into securing mission-critical SaaS applications beyond on-premises SAP, alongside earlier backing from LLR Partners and .406 Ventures. It reports roughly $93.5 million in estimated annual recurring revenue as of 2025, reflecting a mature, scaled business within its ERP-security niche rather than an early-stage startup.
Innovation Matrix Assessment
Onapsis Research Labs has continued to publish new SAP vulnerability research and threat briefs through 2025 (including CVE-2025-31324 active-exploitation analysis), and the company expanded its platform scope into SaaS applications following its Series D, indicating sustained, well-documented product and research investment.
Covers vulnerability management, configuration, code security, and threat detection specifically tuned to SAP/Oracle ERP internals that generic vulnerability scanners and AppSec tools do not natively understand, addressing a real, underserved operational gap for large enterprises running business-critical ERP.
A $55M Series D (part of ~$116M total raised) and reported ~$93.5M estimated ARR in 2025 indicate a scaled, growing business, though these are third-party-estimated figures (Latka) rather than company-disclosed audited revenue.
Onapsis pioneered the ERP/business-critical-application-security niche and remains a category leader within it, but that category is now well-established, and per this site's convention a company of Onapsis's scale and maturity is scored more conservatively on disruption.
Onapsis Research Labs' co-discovery of the ICMAD vulnerabilities (CVSS 10.0, CISA KEV-listed, up to 40,000 SAP customers affected) and its direct observation of active exploitation of CVE-2025-31324/CVE-2025-42999 (also CISA KEV-listed) represent independently verifiable, government-corroborated evidence of research quality and real-world relevance, rather than vendor-only marketing claims.
SAP and Oracle ERP systems remain foundational, high-value targets across large enterprises, and CISA's repeated inclusion of SAP vulnerabilities Onapsis helped surface in its Known Exploited Vulnerabilities catalog demonstrates the ongoing, real-world relevance of ERP-specific application security.
Why CISOs Should Care
Gives CISOs at large enterprises running SAP or Oracle ERP dedicated vulnerability, configuration, and threat-detection coverage for business-critical applications that generic AppSec and vulnerability-management tools do not natively understand.
What Makes It Different
Backed by an in-house research team (Onapsis Research Labs) with a direct working relationship with SAP's own Product Security Response Team and a track record of co-discovering CISA-KEV-listed critical vulnerabilities, rather than relying solely on generic scanning signatures.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
A mature, scaled category leader in ERP/business-critical application security with unusually strong, government-corroborated evidence of research quality; less disruptive at this stage of its lifecycle but operationally and evidentially one of the stronger profiles in this batch.
Editorial Note: Claims vs. Verified Findings
The ICMAD vulnerability co-discovery, CISA Known Exploited Vulnerabilities catalog listings, and 40,000-customer exposure estimate are independently reported by CISA, CyberScoop, and The Record, not solely Onapsis's own claims. The $55M Series D and ~$116M total funding come from SecurityWeek; the ~$93.5M estimated 2025 ARR is a third-party estimate (Latka), not company-disclosed audited revenue, and should be treated accordingly.
Sources
Alternatives to Onapsis
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…