OX Security
'Active ASPM' platform combining native SDLC scanning with attack-path analysis and a software bill-of-materials lineage (PBOM) to prioritize exploitable risk.
Visit Website ↗Overview
OX Security was founded in 2021 by Neatsun Ziv and Lior Arzi, both with backgrounds in Israeli cyber units and Check Point, reportedly in response to software supply-chain incidents like SolarWinds. The company has dual roots in Tel Aviv and a U.S. corporate presence commonly listed as Boston.
OX’s platform, marketed as ‘Active ASPM,’ connects scanning across the SDLC back to a lineage it calls a Pipeline Bill of Materials (PBOM), and layers attack-path analysis and context-aware risk scoring on top to reduce alert volume. It has more recently emphasized AI-native protection embedded directly in AI coding assistants/IDEs.
Funding figures vary by source: roughly $94M-$188M total across disclosed rounds; the most recent disclosed round is roughly $60M around May 2025.
Innovation Matrix Assessment
Steady evolution from 2020-era AppSec foundation features through to 2026 AI-native, IDE-embedded protection.
Attack-path analysis plus PBOM lineage is a defensible approach to noise reduction; OX's own materials claim a large alert reduction (vendor-reported, not independently verified).
Raised roughly $60M in a 2025 round with a growing employee base, though total-funding figures conflict meaningfully between data sources.
'Active ASPM' and PBOM lineage are a differentiated framing, but the underlying approach sits within the pattern set by earlier entrants like Apiiro and Cycode.
Named customers with attributed quotes plus recognizable logos provide some real-world signal, though a claimed Gartner 'Leader' designation could not be independently verified.
Code-to-cloud correlation and in-IDE protection for AI-assisted coding are well-aligned with where application risk is trending.
Why CISOs Should Care
Aims to cut alert fatigue by tying every finding back to a concrete attack path and pipeline lineage, and by pushing protection into the AI coding tools developers are now using directly.
What Makes It Different
Anchors prioritization to a bill-of-materials-style lineage across the whole pipeline (PBOM) plus attack-path analysis, rather than treating each scanner's findings as independent signals.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
Incremental Innovator (65/100): a fast-moving, well-funded entrant with real enterprise logos and a differentiated PBOM/attack-path framing, but conflicting funding figures and an unverifiable Gartner 'Leader' claim warrant caution.
Editorial Note: Claims vs. Verified Findings
Employee and funding totals conflict meaningfully across data sources, so figures here are approximate ranges. The claimed Gartner Magic Quadrant Leader designation is stated on OX's own homepage and could not be independently verified.
Sources
Alternatives to OX Security
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Contrast Security
Instruments applications from within using IAST and RASP to find and block vulnerabilities as code actually executes, rather…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…