Skip to content

Mend.io

Software composition analysis platform, formerly WhiteSource, that uses reachability analysis to prioritize which open-source vulnerabilities are actually exploitable.

Visit Website ↗
67/100Incremental Innovator

Overview

Founded in 2011 as WhiteSource, the company rebranded to Mend.io in 2022 to reflect an expansion beyond pure SCA. Headquartered in Givatayim, Israel, with a significant Boston presence, Mend’s core engine traces the call graph from an application’s own code through its dependencies to determine whether a flagged vulnerable function is actually reachable and invoked.

The company expanded through acquisition: Diffend (2021), Xanitizer and DefenseCode (2022, SAST), and Atom Security (2023), building toward a broader remediation-first AppSec platform that now also addresses AI model and dataset security. It has raised roughly $128 million total, including a $75 million Series D led by Pitango Growth in 2021.

Gartner named Mend.io a Visionary in its Magic Quadrant for Application Security Testing in both 2023 and 2025.

Innovation Matrix Assessment

Innovation Velocity 7/10

Four acquisitions since 2021 rapidly broadened the platform from pure SCA into SAST, supply-chain, and AI-model security.

Operational Value 7/10

Reachability analysis is confirmed by independent Gartner Peer Insights reviewers as reducing developer alert fatigue.

Market Momentum 6/10

Backed by Insight Partners and M12 with ~$128M raised and two consecutive Gartner Visionary placements, but no funding news since the 2021 Series D.

Category Disruption 6/10

Reachability-based prioritization meaningfully improves on flag-everything SCA, but the underlying category remains conventional.

Real-World Efficacy 7/10

Two consecutive years as a Gartner Magic Quadrant Visionary is independently meaningful validation for an SCA-rooted vendor.

Enduring Relevance 7/10

Open-source dependency risk and AI model/dataset provenance are durable, growing problems that map directly to Mend's core competency.

Why CISOs Should Care

Reachability analysis lets AppSec teams stop chasing every CVE in a dependency tree and focus remediation effort on the fraction that's actually invoked.

What Makes It Different

Most SCA tools flag any vulnerable package version present; Mend traces actual code paths to filter for exploitability before a finding ever reaches a developer.

The Matrix Verdict

67/100 — INCREMENTAL INNOVATOR

Incremental Innovator (~67/100) — real, Gartner-validated improvement on a well-understood problem, built through steady acquisition rather than wholesale category reinvention.

Editorial Note: Claims vs. Verified Findings

Reachability-driven noise reduction is corroborated by independent Gartner Peer Insights reviews, but Mend has not published quantified before/after metrics that could be independently checked.

Sources