Legit Security
AI-native ASPM platform for discovering, prioritizing, and remediating risk across the software supply chain, with a separate module governing AI-generated code.
Visit Website ↗Overview
Legit Security was founded in 2020 by Roni Fuchs, Liav Caspi, and Lior Barak, with dual headquarters typically cited as Boston and Tel Aviv. The platform automates discovery of an organization’s software factory — repos, pipelines, dependencies, secrets — and layers prioritization and remediation workflows on top of SAST/SCA/secrets findings.
Its differentiator is treating the SDLC itself (build systems, CI/CD configuration, pipeline permissions) as an asset to be inventoried and monitored for drift and misconfiguration. It has also added ‘VibeGuard,’ a module aimed specifically at governing AI-generated/’vibe coded’ software.
Legit Security has raised roughly $70-76.5M, most recently a $40M Series B (around 2023), from investors including CyberStarts, Bessemer Venture Partners, TCV, CRV, and Tenable Ventures.
Innovation Matrix Assessment
Extended from core ASPM discovery/prioritization into a dedicated AI-generated-code governance module (VibeGuard), a fast response to a newly emerging risk.
SDLC/pipeline-configuration monitoring targets an operational blind spot that pure code-scanning tools miss.
Smallest total disclosed funding in this set (~$70-76.5M) and smallest employee count, with the last round dated to roughly 2023.
A credible ASPM platform but its architecture tracks closer to the established category pattern than to a structurally new approach.
Its site features named CISOs and practitioners attributed to specific quotes about outcomes, plus recognizable enterprise logos.
SDLC/pipeline posture and governance of AI-generated code are both squarely aligned with where AppSec risk is heading.
Why CISOs Should Care
Extends visibility beyond application code into the CI/CD pipeline and build infrastructure itself, and adds a specific control point for AI-generated code entering most engineering organizations' repos.
What Makes It Different
Treats the software factory (pipeline configuration, build permissions, SDLC toolchain) as a first-class asset to secure, not just the code artifacts that pass through it.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
Incremental Innovator (62/100): solid ASPM fundamentals with some real customer-attributed evidence and a timely AI-code governance angle, but the smallest funding and headcount footprint in this comparison set.
Editorial Note: Claims vs. Verified Findings
Named customer quotes appear directly attributed to individuals on Legit's own site, which is stronger than an anonymized logo wall but still vendor-published and not independently corroborated.
Sources
Alternatives to Legit Security
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…