Skip to content
45/100Emerging / Unranked

Innovation Matrix Assessment

Innovation Velocity 5/10

MIT-originated reachability engine built for both binary and source analysis across a dozen-plus languages shows fast technical execution.

Operational Value 3/10

Small team; operational scale beyond initial technology deployment is unproven publicly.

Market Momentum 5/10

Acquired by Boost Security in May 2026 as part of a two-company deal plus $4M in new funding.

Category Disruption 5/10

Reachability-based vulnerability prioritization addresses a well-known pain point (alert fatigue) in traditional SCA tooling.

Real-World Efficacy 3/10

No independent efficacy benchmarks found; claims are vendor and academic-lineage based.

Enduring Relevance 6/10

As AI-generated code accelerates software supply-chain volume, reachability-based vulnerability triage becomes increasingly necessary.

Why CISOs Should Care

SecureIQx built an MIT-founded software composition analysis reachability engine that analyzes both binary and source code across a dozen-plus languages to tell teams whether vulnerable open-source components are actually reachable and exploitable.

What Makes It Different

Focuses specifically on reachability analysis across binary and source code, cutting through the noise of standard SCA tools that flag every known vulnerable dependency regardless of exploitability.

The Matrix Verdict

45/100 — EMERGING / UNRANKED

A technically differentiated, MIT-originated reachability-analysis startup acquired alongside Korbit.ai to strengthen Boost Security's AI-native application security platform.

Editorial Note: Claims vs. Verified Findings

Boost Security announced the acquisition of SecureIQx (with Korbit.ai) on May 6, 2026 alongside a $4M funding round; deal price and founding year were not disclosed.

Sources