CodeLock
A DevSecOps startup building automated software-supply-chain integrity tooling that links every code change to a verifiable developer chain of custody.
Visit Website ↗ + Add to CompareOverview
CodeLock builds software-supply-chain security tooling that operates at the code level rather than just scanning for known vulnerabilities. Its platform creates what the company calls a forensic chain of custody, cryptographically linking every code change to the developer who made it, so organizations can verify code authenticity and integrity from development through deployment. It also automates Software Bill of Materials (SBOM) generation and compliance dashboards mapped to frameworks like NIST 800-218 (the Secure Software Development Framework).
Founded in 2021 and headquartered in Ashburn, Virginia, CodeLock has raised roughly $6.72 million from a syndicate of angel and venture investors, including SoundBoard Venture Fund, Executive Venture Fund, Oakseed Ventures, and Sancus Ventures. The Department of Homeland Security has publicly stated that CodeLock "appears to have the capability to stop the most sophisticated malware," and the company has been recognized by TechCrunch among notable early-stage startups.
CodeLock’s angle — provenance and chain-of-custody verification rather than dependency scanning — addresses a different problem than traditional SAST/SCA tools: it’s aimed at proving that code wasn’t tampered with, in the mold of software supply-chain incidents like SolarWinds, rather than only flagging known-vulnerable components. As a small, young company, its independent, named enterprise track record is still thin relative to its DHS endorsement and funding.
Innovation Matrix Assessment
Raising $6.72M and shipping a differentiated SBOM/chain-of-custody product within about four years of founding is a reasonable, if not exceptional, pace for a company this size.
A small team (around 11 employees) runs a functioning SaaS product with automated compliance dashboards, indicating real but early-stage operational maturity.
A public DHS endorsement quote and a TechCrunch mention provide external validation and visibility beyond typical seed-stage press.
Linking code changes to a verifiable developer chain of custody targets code provenance and tamper-evidence rather than known-vulnerability scanning, a genuinely different angle from typical SAST/SCA tools.
The DHS quote is a real, independently findable endorsement, which is stronger than pure marketing copy, but no independent lab evaluation or named enterprise deployment with measured results was found.
Executive Order 14028 and the NIST Secure Software Development Framework have turned SBOM generation and software provenance into live compliance requirements, making this directly relevant to current CISO and federal-supplier priorities.
Why CISOs Should Care
Executive Order 14028 and NIST SSDF have made SBOM generation and software provenance a compliance requirement rather than just a best practice, and CodeLock automates the evidentiary trail that requirement demands.
What Makes It Different
Focuses on cryptographically linking every code change to its developer to create a verifiable chain of custody, rather than scanning code or dependencies for already-known vulnerabilities the way traditional SAST/SCA tools do.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A focused software-supply-chain-integrity play with a real, if unusual, DHS endorsement behind it and funding from a credible if modest investor syndicate. Independent, named-customer proof of efficacy at scale is still thin for a company this young.
Editorial Note: Claims vs. Verified Findings
The DHS endorsement quote is independently findable and attributed, a stronger signal than typical vendor marketing. The funding total ($6.72M) is sourced from PitchBook/Crunchbase aggregation rather than a company press release. No independent lab test or named enterprise case study was found, so specific efficacy claims beyond the DHS quote should be treated as vendor-sourced.
Sources
Alternatives to CodeLock
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…