Skip to content

Scantist

Singapore/NTU spinout that evolved from open-source vulnerability scanning into autonomous AI penetration testing and AI runtime security governance.

Visit Website ↗ + Add to Compare Claim This Company
62/100Incremental Innovator

Overview

Scantist began as a software composition analysis (SCA) company, helping development teams find and manage security and license-compliance risk in the open-source libraries embedded in their code and binaries. Over time it has expanded into a broader application, software-supply-chain, and AI security portfolio: AppDefender continues that original SCA and supply-chain security line, PAIStrike applies autonomous, agentic techniques to penetration testing, and AIDefender targets runtime security and governance for AI systems themselves — reflecting the same underlying research applied to a widening set of security problems.

Founded in 2016 as a spin-off from a security research lab at Nanyang Technological University by co-founders including Professor Liu Yang and COO Charles Huang, Scantist is based in Singapore and has raised a total of $12.6 million from investors including GSR Ventures, Singtel Innov8, and Taurus Investment Holdings, alongside grant support from Singapore’s Cyber Security Agency and National Research Foundation. The company has picked up recognition through CSA Singapore’s Call for Innovation Grant and Huawei’s Spark Program.

Innovation Matrix Assessment

Innovation Velocity 7/10

Expanded from its original open-source SCA product into autonomous, agentic penetration testing (PAIStrike) and AI runtime security governance (AIDefender) over roughly a decade — a real pattern of building new capability on the same research base.

Operational Value 7/10

Delivers genuine operational value across two distinct needs: reducing open-source supply-chain risk and, more recently, governing the security of AI systems themselves as teams adopt them.

Market Momentum 6/10

Raised a disclosed $12.6M from credible investors including GSR Ventures and Singtel Innov8, plus multiple Singapore government grants and innovation-program recognition — solid evidence, though modest next to larger US/Israeli SCA and AI-security peers.

Category Disruption 5/10

Software composition analysis is a mature, competitive category already served by vendors like Snyk and Black Duck; Scantist's newer autonomous-pentesting and AI-security-governance products are more novel but not yet proven as category-redefining.

Real-World Efficacy 5/10

Academic origin (an NTU security research lab) and multiple government grant awards lend credibility, but no independent, named enterprise case study with concrete efficacy metrics was found.

Enduring Relevance 7/10

Spans both a persistent need (open-source software supply chain security) and a fast-growing one (AI system security), giving the company durable relevance as both concerns continue to matter.

Why CISOs Should Care

Gives security teams a single vendor covering open-source supply-chain risk, autonomous penetration testing, and AI system runtime security as those needs increasingly overlap.

What Makes It Different

Applies the same core vulnerability-research foundation across three distinct problem areas — supply chain, offensive testing, and AI runtime security — rather than specializing narrowly in one.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

Incremental Innovator. Scantist has real research pedigree and has meaningfully broadened its product line into AI security, backed by credible if modest funding, but it operates in the crowded SCA space and lacks independently published efficacy evidence for its newer AI-security products.

Editorial Note: Claims vs. Verified Findings

Funding total and grant awards are independently reported; efficacy of the AIDefender and PAIStrike products rests on Scantist's own descriptions, without independent third-party validation found.

Sources