StackHawk
A CI/CD-embedded API and application security testing platform built on ZAP, designed to catch vulnerabilities as developers write code rather than after the fact.
Visit Website ↗ + Add to CompareOverview
StackHawk builds developer-first application and API security testing that runs dynamic application security testing (DAST) directly inside CI/CD pipelines, rather than as a separate, later-stage scan run by a security team. Built on top of the open-source ZAP (Zed Attack Proxy) scanning engine, StackHawk lets engineering teams find and fix vulnerabilities in APIs and web applications as code is written, with results routed back to developers as actionable tickets instead of a PDF report handed to security weeks later.
Founded in 2019 in Denver, Colorado by Joni Klippert (CEO), Scott Gerlach (Chief Security Officer, previously a security leader at SendGrid and GoDaddy), and Ryan Severns, StackHawk has raised a total of roughly $47.3 million, including a $20.7 million Series B in 2022 co-led by Sapphire Ventures and Costanoa Ventures, and a further $12 million strategic round in 2025 aimed specifically at helping security teams keep pace with AI-generated code. That later raise reflects a real shift in the market: as AI coding assistants accelerate how fast code — and API surface area — gets shipped, the case for automated, pipeline-embedded testing gets stronger.
StackHawk competes with established players like Veracode and Snyk as well as API-specific testing tools, differentiating on developer workflow fit rather than raw scan-engine novelty. The company is still relatively small (LinkedIn lists 11-50 employees), and while its funding and named investor base show real institutional confidence, independent benchmark data comparing its detection accuracy to competitors is not publicly available.
Innovation Matrix Assessment
StackHawk continues to ship product against a shifting target: it added AI-generated-code-focused testing capability in 2025 on top of its core CI/CD-embedded DAST engine, but public evidence of release cadence is limited and the team is small (11-50 employees), which caps how broad the roadmap can be.
Operating continuously since 2019 with roughly $47.3M raised across seed, Series A, Series B, and a 2025 strategic round, StackHawk has institutional backing (Sapphire Ventures, Costanoa Ventures, Foundry Group) and a multi-year track record, though headcount remains modest for a company at this funding level.
A fresh $12M strategic raise in 2025, explicitly positioned around helping security teams keep pace with AI-generated code, signals continued investor confidence and a response to a real market shift, though no public customer-count or revenue figures were found to independently corroborate growth.
Embedding DAST directly into developer CI/CD workflows (built on open-source ZAP) is a genuine shift from traditional, security-team-run, after-the-fact scanning, but the underlying approach is shared by other developer-first AppSec vendors, so differentiation is workflow fit rather than a novel detection technique.
No independent benchmark, third-party detection-accuracy comparison, or named enterprise case study was found; StackHawk's effectiveness claims relative to competitors like Veracode and Snyk are not independently verifiable from public sources.
API and application security testing is highly relevant to any organization shipping software, and the 2025 pivot toward AI-generated-code testing tracks a widely-recognized and growing CISO concern as AI coding assistants expand API surface area faster than manual review can cover.
Why CISOs Should Care
For engineering and AppSec leaders trying to shift DAST left without slowing releases, StackHawk offers CI/CD-native scanning that routes findings to developers as tickets rather than as a separate security-team report, and is now explicitly targeting the AI-generated-code testing gap.
What Makes It Different
Rather than competing on scan-engine novelty, StackHawk differentiates on developer workflow integration -- running on the open-source ZAP engine but packaging it for pipeline-native use, in contrast to heavier, security-team-centric legacy DAST tools.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A credible, well-funded developer-first DAST vendor with real institutional backing and a timely pivot toward AI-generated-code testing, but one whose competitive claims against larger AppSec incumbents remain vendor-asserted rather than independently benchmarked.
Editorial Note: Claims vs. Verified Findings
Vendor-sourced and unverified: comparative detection-accuracy or efficacy claims against competitors (Veracode, Snyk, other DAST/API testing tools) are not backed by any independent benchmark found in public sources. Independently verified across multiple sources: founding year (2019), founder identities (Joni Klippert, Scott Gerlach, Ryan Severns), and funding amounts/dates -- the $20.7M Series B (2022) and $12M strategic round (2025) are corroborated by StackHawk's own press release plus independent trade coverage (SecurityWeek, Dark Reading, PR Newswire), consistently totaling approximately $47.3M raised.
Sources
Alternatives to StackHawk
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…