Depthfirst
Extremely fast-moving, well-capitalized AI security lab (two large rounds within 90 days) founded by DeepMind/Databricks/Faire alumni; still early enough that independent efficacy data is limited.
Visit Website ↗ + Add to CompareInnovation Matrix Assessment
Raised an $80M Series B (announced 2026-03-31) led by Meritech Capital less than 90 days after a $40M Series A, bringing total funding to $120M since a 2024 founding.
Enterprise adoption is described as an active scaling priority for the new funding; specific named customer deployments were not disclosed in coverage reviewed.
Series B closed 2026-03-31 with Meritech Capital, Forerunner Ventures, and The House Fund joining existing investors Accel and Box Group.
Building proprietary, in-house security-specific AI models (dfs-mini1) rather than relying on general-purpose LLMs is a differentiated technical bet.
False-positive-reduction and remediation-quality claims are company-described; no independent benchmark was located.
Reducing false positives and providing actionable fixes addresses a long-standing, real pain point in application and infrastructure security.
Why CISOs Should Care
Depthfirst is an applied AI lab building security models that understand code, business logic, and infrastructure together to identify real vulnerabilities, cut false positives, and hand developers actionable fixes rather than another alert queue.
What Makes It Different
Trains its own in-house security models (starting with dfs-mini1) purpose-built for vulnerability detection and remediation, rather than wrapping general-purpose LLMs around existing SAST/DAST tooling.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
Extremely fast-moving, well-capitalized AI security lab (two large rounds within 90 days) founded by DeepMind/Databricks/Faire alumni; still early enough that independent efficacy data is limited.
Editorial Note: Claims vs. Verified Findings
Funding history and founding-team background verified via SecurityWeek and BusinessWire. False-positive-reduction and fix-quality claims are vendor-described.
Sources
Alternatives to Depthfirst
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…