NowSecure
Automated mobile application security testing platform used across DevSecOps pipelines and by numerous US federal agencies for NIAP-compliant app vetting.
Visit Website ↗ + Add to CompareOverview
NowSecure provides automated mobile app security testing designed to run at DevSecOps speed rather than the slower pace of manual mobile penetration testing. The platform performs static, dynamic, and behavioral analysis of iOS and Android apps to identify vulnerabilities, privacy issues, and supply-chain risks (such as third-party SDKs routing data to unexpected destinations), and is built to plug into CI/CD pipelines so mobile security testing can happen on every build rather than as a periodic audit.
Founded in 2009 by Andrew Hoog and Chee-Young Kim and headquartered in Chicago, Illinois, NowSecure has raised roughly $29 million across a Series A and Series B, with investors including Baird Capital, Jump Capital, Math Venture Partners, and ForgePoint Capital. A notable and independently verifiable proof point is the company’s federal government work: starting from an SBIR partnership with the U.S. Air Force, NowSecure built the first automated testing solution supporting the NIAP v1.3 Mobile App Vetting Protection Profile, and the company states it is used by dozens of federal agencies including the Department of Defense, Department of Homeland Security, DEA, and State Department for mobile app security and privacy assessment.
NowSecure’s specific niche — deep, automated mobile app testing rather than broad application security coverage — differentiates it from general-purpose AppSec platforms that treat mobile as one asset type among many. Its long operating history (since 2009, well before mobile-first security was a mainstream category) and documented federal government adoption for a specific compliance standard (NIAP) are genuine, verifiable differentiators, even though detailed penetration-test-level efficacy data beyond the government use case is not independently published.
Innovation Matrix Assessment
NowSecure has steadily expanded its platform over the years, adding NIAP v1.3 automated vetting (2020), GovAppDB, and a threat assessment service tied to newer federal mobile security mandates, showing a consistent if not explosive pace of feature development.
Operating continuously since 2009 with roughly 100 employees, NowSecure runs a mature automated testing platform integrated into DevSecOps pipelines and has sustained real federal government program work (an SBIR partnership with the U.S. Air Force's BESPIN team), indicating genuine operational depth for a company of its size.
The company's most recent disclosed funding is a $20M Series B; no larger or more recent round was found in public sources, and while continued federal contract relevance is a positive signal, there is no clear evidence of accelerating growth beyond steady, sustained operation.
Automating mobile app security testing to run inside CI/CD pipelines rather than as periodic manual penetration tests is a meaningful efficiency gain, but NowSecure competes with several other established mobile application security testing (MAST) vendors making similar automation claims, so it is a strong execution of an established idea rather than a novel one.
NowSecure's efficacy claims are unusually well substantiated for this category: it built the first automated testing solution supporting the NIAP v1.3 Mobile App Vetting Protection Profile, originating from a U.S. Air Force SBIR partnership, and independent reporting (Potomac Officers Club) confirms DoD adoption of that specific capability, which is a genuine third-party-verifiable proof point beyond vendor marketing.
Mobile apps are a growing and often under-tested part of the enterprise and government attack surface, and newer federal mandates around mobile security and privacy (which NowSecure built a dedicated GovAppDB and threat assessment service to address) make automated, standards-aligned mobile app testing directly relevant to current compliance pressures.
Why CISOs Should Care
CISOs responsible for a mobile app portfolio, whether commercial DevSecOps pipelines or federal agencies bound by NIAP compliance requirements, get an automated testing platform with an unusually long track record and documented government adoption for a specific compliance standard.
What Makes It Different
NowSecure focuses exclusively on deep, automated mobile app security testing rather than treating mobile as a minor add-on to a broader application security platform, and it has built specific compliance tooling (NIAP v1.3 vetting) that few competitors can point to with independent federal adoption evidence.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
A mature, focused mobile AppSec vendor with genuine, independently corroborated federal government traction; solid and well-evidenced within its niche, if not currently showing explosive growth.
Editorial Note: Claims vs. Verified Findings
NowSecure's founding, funding history, and the NIAP v1.3 automated vetting solution (including its origin in a U.S. Air Force SBIR partnership and subsequent DoD adoption) are independently corroborated by Potomac Officers Club and NowSecure's own press materials cross-checked against government-facing trade coverage. The specific claim of usage by 'dozens of federal agencies' is vendor-stated and was not independently itemized for this profile.
Sources
Alternatives to NowSecure
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…