Skip to content

StackHawk

A CI/CD-embedded API and application security testing platform built on ZAP, designed to catch vulnerabilities as developers write code rather than after the fact.

Visit Website ↗ + Add to Compare
58/100Incremental Innovator

Overview

StackHawk builds developer-first application and API security testing that runs dynamic application security testing (DAST) directly inside CI/CD pipelines, rather than as a separate, later-stage scan run by a security team. Built on top of the open-source ZAP (Zed Attack Proxy) scanning engine, StackHawk lets engineering teams find and fix vulnerabilities in APIs and web applications as code is written, with results routed back to developers as actionable tickets instead of a PDF report handed to security weeks later.

Founded in 2019 in Denver, Colorado by Joni Klippert (CEO), Scott Gerlach (Chief Security Officer, previously a security leader at SendGrid and GoDaddy), and Ryan Severns, StackHawk has raised a total of roughly $47.3 million, including a $20.7 million Series B in 2022 co-led by Sapphire Ventures and Costanoa Ventures, and a further $12 million strategic round in 2025 aimed specifically at helping security teams keep pace with AI-generated code. That later raise reflects a real shift in the market: as AI coding assistants accelerate how fast code — and API surface area — gets shipped, the case for automated, pipeline-embedded testing gets stronger.

StackHawk competes with established players like Veracode and Snyk as well as API-specific testing tools, differentiating on developer workflow fit rather than raw scan-engine novelty. The company is still relatively small (LinkedIn lists 11-50 employees), and while its funding and named investor base show real institutional confidence, independent benchmark data comparing its detection accuracy to competitors is not publicly available.

Innovation Matrix Assessment

Innovation Velocity 6/10

StackHawk continues to ship product against a shifting target: it added AI-generated-code-focused testing capability in 2025 on top of its core CI/CD-embedded DAST engine, but public evidence of release cadence is limited and the team is small (11-50 employees), which caps how broad the roadmap can be.

Operational Value 6/10

Operating continuously since 2019 with roughly $47.3M raised across seed, Series A, Series B, and a 2025 strategic round, StackHawk has institutional backing (Sapphire Ventures, Costanoa Ventures, Foundry Group) and a multi-year track record, though headcount remains modest for a company at this funding level.

Market Momentum 6/10

A fresh $12M strategic raise in 2025, explicitly positioned around helping security teams keep pace with AI-generated code, signals continued investor confidence and a response to a real market shift, though no public customer-count or revenue figures were found to independently corroborate growth.

Category Disruption 5/10

Embedding DAST directly into developer CI/CD workflows (built on open-source ZAP) is a genuine shift from traditional, security-team-run, after-the-fact scanning, but the underlying approach is shared by other developer-first AppSec vendors, so differentiation is workflow fit rather than a novel detection technique.

Real-World Efficacy 4/10

No independent benchmark, third-party detection-accuracy comparison, or named enterprise case study was found; StackHawk's effectiveness claims relative to competitors like Veracode and Snyk are not independently verifiable from public sources.

Enduring Relevance 8/10

API and application security testing is highly relevant to any organization shipping software, and the 2025 pivot toward AI-generated-code testing tracks a widely-recognized and growing CISO concern as AI coding assistants expand API surface area faster than manual review can cover.

Why CISOs Should Care

For engineering and AppSec leaders trying to shift DAST left without slowing releases, StackHawk offers CI/CD-native scanning that routes findings to developers as tickets rather than as a separate security-team report, and is now explicitly targeting the AI-generated-code testing gap.

What Makes It Different

Rather than competing on scan-engine novelty, StackHawk differentiates on developer workflow integration -- running on the open-source ZAP engine but packaging it for pipeline-native use, in contrast to heavier, security-team-centric legacy DAST tools.

The Matrix Verdict

58/100 — INCREMENTAL INNOVATOR

A credible, well-funded developer-first DAST vendor with real institutional backing and a timely pivot toward AI-generated-code testing, but one whose competitive claims against larger AppSec incumbents remain vendor-asserted rather than independently benchmarked.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: comparative detection-accuracy or efficacy claims against competitors (Veracode, Snyk, other DAST/API testing tools) are not backed by any independent benchmark found in public sources. Independently verified across multiple sources: founding year (2019), founder identities (Joni Klippert, Scott Gerlach, Ryan Severns), and funding amounts/dates -- the $20.7M Series B (2022) and $12M strategic round (2025) are corroborated by StackHawk's own press release plus independent trade coverage (SecurityWeek, Dark Reading, PR Newswire), consistently totaling approximately $47.3M raised.

Sources