DryRun Security
AI-native application security platform that reviews pull requests with full code context to catch logic-level vulnerabilities SAST tools miss.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
DryRun Security, founded in Austin, Texas by application-security veterans James Wickett and Ken Johnson, builds what it calls Contextual Security Analysis (CSA) — a PR-native review engine that evaluates data flow, architecture, change history, and developer intent alongside the raw diff, rather than matching code against static rule patterns. The goal is to surface logic-heavy findings (missing authorization on new endpoints, IDOR, business-logic flaws, prompt injection in LLM-enabled code) that traditional SAST tools typically miss or bury in noise, and to post plain-language remediation guidance directly in the pull request before merge. The company has layered on Natural Language Code Policies (letting AppSec teams write policy in plain English), a Custom Policy Agent, secrets detection, IaC scanning, and a repo-wide “DeepScan” capability.
DryRun raised an $8.7M seed round (announced January 22, 2025) led by LiveOak Ventures and Work-Bench, with Cannage Capital participating — modest but credible early institutional backing. The company lists enterprise and mid-market customer logos including AIG, Cloudera, Flex, Dematic, Tines, Gusto, and Invisible Technologies, the last of which is on record with a named-executive testimonial (Patrick McKinney, VP of Security) describing the tool as supplementing their AppSec team’s capacity for Fortune 50 client work. DryRun’s own marketing claims 500,000+ code reviews per week, though this and an earlier-cited 88% seeded-vulnerability detection rate are vendor-published figures without independent benchmarking.
For a CISO, DryRun’s pitch is incremental AppSec capacity: catching the class of bugs that pattern-matching scanners structurally can’t see, in the workflow developers already use, without a dedicated logic-bug review headcount. It competes in an increasingly crowded “AI reviews AI-written code” field (Dam Secure, Staris, and general tools like CodeRabbit/Greptile adding security checks), so its durability will depend on proving detection accuracy at scale rather than on its current seed-stage funding or customer count.
Innovation Matrix Assessment
Founders are established AppSec practitioners (Wickett: DevSecOps community leader; Johnson: longtime security engineering veteran) who have shipped a sequence of distinct capabilities (CSA, NLCP, Custom Policy Agent, DeepScan, secrets/IaC scanning, MCP integration) within roughly 2-3 years of founding.
Embeds directly in the PR workflow developers already use and targets a real, underserved gap (logic/business-logic bugs vs. pattern-based SAST); named customer testimonial (Invisible Technologies) describes tangible team-capacity relief, though this is a single data point.
An $8.7M seed round and a visible logo list (AIG, Cloudera, Flex, Gusto, Tines, Invisible Technologies) show real but early traction; usage figures (500K reviews/week) are vendor-reported and unaudited.
Contextual, diff-aware review is a meaningful evolution over rule-based SAST, but the approach is quickly being replicated by multiple well-funded competitors (Dam Secure, Staris, and general AI code-review tools adding security checks), limiting category-defining uniqueness so far.
Detection-rate and noise-reduction claims come only from company marketing; no independent test, named-incident catch, or third-party benchmark was found.
AI-assisted coding is structurally increasing the volume of logic-level vulnerabilities that pattern-based scanners miss, which is a durable, growing problem over a 3-5 year horizon.
Why CISOs Should Care
Gives AppSec teams PR-level, context-aware review that catches business-logic and authorization bugs conventional SAST tools structurally cannot, without adding headcount.
What Makes It Different
Evaluates data flow, architecture, change history and intent together (Contextual Security Analysis) rather than matching code against static vulnerability patterns.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
A credible, founder-led early entrant in AI-era AppSec with real customers and funding, but still unproven at independent-evaluation scale and facing fast-moving competition in the same niche.
Editorial Note: Claims vs. Verified Findings
Vendor-published statistics (500,000+ code reviews/week; an earlier-cited 88% seeded-vulnerability detection rate) could not be independently verified and are presented here as company claims, not confirmed facts. Exact founding date is disputed across sources (2022 stealth founding per aggregator data vs. May 2023 public launch per BusinessWire); both are noted.
Sources
Alternatives to DryRun Security
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…