Kiuwan (Sembi)
Static application security testing and software composition analysis platform originating in Spain, now part of Idera's Sembi software quality and security portfolio.
Visit Website ↗ + Add to CompareOverview
Kiuwan was founded in 2003 in Spain as a code security and quality analysis provider, building static application security testing (SAST) and software composition analysis (SCA) capabilities that work across all common programming languages and development environments. In 2018 the company was acquired by Idera, Inc. and is now positioned within Sembi, Idera’s dedicated portfolio of software quality and security brands, continuing to operate and develop its product under that ownership.
Kiuwan uses industry-standard severity ratings to help teams prioritize the security risks their applications face, and reports serving over 300 organizations and 20,000 users globally, giving it a long operating history and established customer base even as an owned subsidiary rather than an independent company.
Innovation Matrix Assessment
A mature product with a long operating history showing incremental rather than rapid recent innovation, consistent with its position as an established subsidiary product.
Broad language and environment coverage with standardized severity ratings supports consistent prioritization workflows across diverse development teams, per the platform's own documentation.
As a stable, owned subsidiary product rather than an independently growing company, Kiuwan's momentum is tied to its parent's broader portfolio strategy rather than showing independent expansion signals.
A well-established, conventional SAST/SCA approach with no evidence of a structurally new detection method or market-reshaping innovation.
Two decades of continuous use across 300+ organizations is a reasonable real-world track record, though no independent detection-accuracy benchmark was found.
Conventional SAST/SCA capability remains a baseline necessity for application security programs, though Kiuwan shows less visible evolution toward newer AI-era AppSec trends than more actively innovating competitors.
Why CISOs Should Care
Kiuwan gives CISOs a two-decade-established SAST and SCA tool with broad language coverage, backed by the stability and resources of a larger software portfolio company (Idera/Sembi) rather than a standalone startup's uncertain longevity.
What Makes It Different
Its two-decade European operating history and broad multi-language coverage differentiate Kiuwan from newer, narrower-scope AppSec entrants, though its core SAST/SCA capabilities are largely comparable to established competitors.
The Matrix Verdict
37/100 — EMERGING / UNRANKED
A mature, stable SAST/SCA tool with a long track record and the backing of an established software portfolio owner; a safe, unspectacular choice rather than an innovation leader in the current AppSec landscape.
Editorial Note: Claims vs. Verified Findings
Customer and user counts are drawn from Kiuwan's own site; acquisition details are corroborated by public reporting on the 2018 Idera acquisition.
Sources
Alternatives to Kiuwan (Sembi)
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…