Mend.io
Software composition analysis platform, formerly WhiteSource, that uses reachability analysis to prioritize which open-source vulnerabilities are actually exploitable.
Visit Website ↗Overview
Founded in 2011 as WhiteSource, the company rebranded to Mend.io in 2022 to reflect an expansion beyond pure SCA. Headquartered in Givatayim, Israel, with a significant Boston presence, Mend’s core engine traces the call graph from an application’s own code through its dependencies to determine whether a flagged vulnerable function is actually reachable and invoked.
The company expanded through acquisition: Diffend (2021), Xanitizer and DefenseCode (2022, SAST), and Atom Security (2023), building toward a broader remediation-first AppSec platform that now also addresses AI model and dataset security. It has raised roughly $128 million total, including a $75 million Series D led by Pitango Growth in 2021.
Gartner named Mend.io a Visionary in its Magic Quadrant for Application Security Testing in both 2023 and 2025.
Innovation Matrix Assessment
Four acquisitions since 2021 rapidly broadened the platform from pure SCA into SAST, supply-chain, and AI-model security.
Reachability analysis is confirmed by independent Gartner Peer Insights reviewers as reducing developer alert fatigue.
Backed by Insight Partners and M12 with ~$128M raised and two consecutive Gartner Visionary placements, but no funding news since the 2021 Series D.
Reachability-based prioritization meaningfully improves on flag-everything SCA, but the underlying category remains conventional.
Two consecutive years as a Gartner Magic Quadrant Visionary is independently meaningful validation for an SCA-rooted vendor.
Open-source dependency risk and AI model/dataset provenance are durable, growing problems that map directly to Mend's core competency.
Why CISOs Should Care
Reachability analysis lets AppSec teams stop chasing every CVE in a dependency tree and focus remediation effort on the fraction that's actually invoked.
What Makes It Different
Most SCA tools flag any vulnerable package version present; Mend traces actual code paths to filter for exploitability before a finding ever reaches a developer.
The Matrix Verdict
67/100 — INCREMENTAL INNOVATOR
Incremental Innovator (~67/100) — real, Gartner-validated improvement on a well-understood problem, built through steady acquisition rather than wholesale category reinvention.
Editorial Note: Claims vs. Verified Findings
Reachability-driven noise reduction is corroborated by independent Gartner Peer Insights reviews, but Mend has not published quantified before/after metrics that could be independently checked.
Sources
Alternatives to Mend.io
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…