Digital.ai
DevOps platform whose Application Security line (formerly Arxan) provides build-time app shielding, anti-tampering, and white-box cryptography for mobile and embedded apps.
Visit Website ↗ + Add to CompareOverview
Digital.ai is a DevOps and software-delivery platform company formed in 2020 through the merger of Arxan Technologies (mobile and application shielding), CollabNet VersionOne (agile planning), and XebiaLabs (release orchestration), later folding in Numerify. Within this broader DevOps portfolio, its security-relevant product line — Digital.ai Application Security, built on the former Arxan technology — provides runtime application self-protection (RASP), code obfuscation, white-box cryptography, and anti-tampering/anti-reverse-engineering protection injected into mobile and embedded applications at build time, aimed at organizations that need to protect app binaries running on devices they don’t control.
Arxan/Digital.ai Application Security was recognized as a Representative Vendor in Gartner’s Market Guide for Application Shielding, and its customer base skews toward public-sector and regulated-industry mobile apps that face reverse-engineering and tampering risk once distributed to end-user devices — a narrower, more specialized use case than general application security testing (SAST/DAST) vendors. Digital.ai itself is a private, equity-backed company (investors including TPG and Dcode per PitchBook) headquartered in Raleigh, North Carolina, employing roughly 1,000 people across its full DevOps and security product suite.
This profile scopes its evaluation to the application-shielding product line specifically; Digital.ai’s much larger agile-planning and release-orchestration businesses are DevOps tooling rather than cybersecurity and are excluded as out of scope for this matrix.
Innovation Matrix Assessment
Application shielding is a mature Arxan-era technology; Digital.ai's broader company roadmap is focused on AI-driven DevOps/value-stream features, with less visible recent investment specifically in the application-security line.
The build-time SDK/binary-protection integration model is well established and has operated across major platforms (iOS, Android, embedded) for over a decade under the Arxan name.
No recent (last 2-3 years) funding, acquisition, or major product-launch news specific to the application-security line was found; the parent company's total raised capital is historical and spans the whole DevOps portfolio, not this division specifically.
Application shielding/RASP is a well-established category; Arxan was an early mover roughly two decades ago but is not currently reported as advancing the category's state of the art.
Gartner Market Guide 'Representative Vendor' recognition is a real, independently sourced analyst signal, and long-term adoption by public-sector mobile-app programs suggests real-world use, though no specific breach-prevention or third-party penetration-test results were found.
Protecting mobile and embedded app binaries from reverse engineering and tampering remains relevant for banking, government, and IoT applications specifically, though it is a narrower need than broad application security testing that most enterprises prioritize first.
Why CISOs Should Care
For teams shipping mobile or embedded applications onto devices they don't control, such as banking apps, government apps, or IoT firmware, Digital.ai's Application Security line adds binary-level tamper resistance and cryptographic key protection that traditional SAST/DAST testing doesn't provide.
What Makes It Different
Its build-time binary-shielding and white-box-cryptography approach protects apps that are already deployed and running on untrusted devices, differentiating it from application-security tools that focus on finding vulnerabilities before release rather than protecting the shipped binary itself.
The Matrix Verdict
43/100 — EMERGING / UNRANKED
A legitimate, analyst-recognized application-shielding capability with a long track record in regulated and public-sector mobile deployments, but folded into a much larger non-security DevOps company with limited visible recent investment specific to this security line.
Editorial Note: Claims vs. Verified Findings
This profile is scoped to Digital.ai's Application Security (formerly Arxan) product line only; the company's much larger agile-planning and release-orchestration business lines are excluded as out of scope for this matrix. The Gartner Market Guide 'Representative Vendor' mention is an independently sourced analyst reference; company-wide funding and employee figures reflect the whole DevOps portfolio, not the security division specifically, and were not broken out separately by the company.
Sources
Alternatives to Digital.ai
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…