Innovation Matrix Assessment
MIT-originated reachability engine built for both binary and source analysis across a dozen-plus languages shows fast technical execution.
Small team; operational scale beyond initial technology deployment is unproven publicly.
Acquired by Boost Security in May 2026 as part of a two-company deal plus $4M in new funding.
Reachability-based vulnerability prioritization addresses a well-known pain point (alert fatigue) in traditional SCA tooling.
No independent efficacy benchmarks found; claims are vendor and academic-lineage based.
As AI-generated code accelerates software supply-chain volume, reachability-based vulnerability triage becomes increasingly necessary.
Why CISOs Should Care
SecureIQx built an MIT-founded software composition analysis reachability engine that analyzes both binary and source code across a dozen-plus languages to tell teams whether vulnerable open-source components are actually reachable and exploitable.
What Makes It Different
Focuses specifically on reachability analysis across binary and source code, cutting through the noise of standard SCA tools that flag every known vulnerable dependency regardless of exploitability.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A technically differentiated, MIT-originated reachability-analysis startup acquired alongside Korbit.ai to strengthen Boost Security's AI-native application security platform.
Editorial Note: Claims vs. Verified Findings
Boost Security announced the acquisition of SecureIQx (with Korbit.ai) on May 6, 2026 alongside a $4M funding round; deal price and founding year were not disclosed.