DefectDojo

DefectDojo, Inc. develops an open-source DevSecOps and unified vulnerability management platform that helps security teams ingest findings, organize them in context, reduce duplicate noise, and track remediation through a consistent workflow. Its documentation and website position the platform as a central system for application and cloud security data rather than a point scanner, with support for broad tool ingestion, reporting, and remediation management.

DefectDojo, Inc. offers both DefectDojo Open-Source and DefectDojo Pro. The Pro edition adds enterprise-oriented capabilities such as connectors, advanced dashboards and reporting, workflow automation, improved UI/UX, and flexible deployment through SaaS or self-hosting. More recent expansion areas include DefectDojo Sensei for AI-assisted security analysis and the PSIRT Advisory Engine for product security advisory intake, matching, prioritization, publication, and tracking.

Offerings, Capabilities, and Integrations

DefectDojo, Inc. centers its offering on unifying security findings from a large ecosystem of scanners and security tools, normalizing data, tuning deduplication, prioritizing remediation, and automating repetitive program workflows. The platform supports multiple import methods, configurable parsing, scheduled rules, and metrics views designed for executive, program, and remediation stakeholders.

Its integration footprint spans security scanners, cloud-security feeds, and issue-tracking systems. Official materials highlight integrations and workflow handoffs across tools such as AWS Security Hub, Azure Boards, ServiceNow, GitHub, GitLab, Jira, Snyk, SonarQube, Semgrep, Tenable, and Wiz, helping teams keep remediation work inside the systems developers and operators already use.

Products and Services

  • DefectDojo Pro: Commercial edition of the platform that builds on the open-source foundation with advanced dashboards and reporting, automation through Rules Engine, connectors, improved UI/UX, optimized import workflows, and support for SaaS or self-hosted deployment.
  • DefectDojo Open-Source: Open-source edition that provides core vulnerability management, including import and reimport for supported tools, REST API access, deduplication, and essential reporting for teams starting or standardizing DevSecOps workflows.
  • DefectDojo Sensei: AI-focused offering introduced in 2025 as an agentic security assistant designed to help with cybersecurity analysis while emphasizing self-contained operation.
  • PSIRT Advisory Engine: Product security offering launched in 2026 for PSIRT teams to ingest advisories from multiple feeds, match them against SBOM components or asset rules, prioritize impact, publish advisories, and track remediation inside DefectDojo Pro.
  • Universal Parser: Pro feature that lets teams map and ingest custom or unsupported JSON and CSV security reports into actionable findings.
  • Smart Upload: Pro import capability for infrastructure scan data that can split findings from a single scan file into separate Products based on discovered endpoints or hosts.
  • Rules Engine: Pro automation capability for creating custom rules, bulk actions, ownership changes, field updates, alerts, and scheduled workflow execution on matching objects.
  • Connectors: Pro integration capability that provides out-of-the-box API connections to supported tools such as AWS Security Hub, BurpSuite, Checkmarx ONE, Dependency-Track, Semgrep, SonarQube, Snyk, Tenable, and Wiz.

Target Customers

DefectDojo, Inc. targets modern security programs that need to consolidate findings across distributed development and infrastructure environments. Its website speaks directly to AppSec leaders, security engineers, CISOs, pen testers, and MSPs, and more recent product expansion extends relevance to SOC teams and dedicated PSIRT organizations.

The open-source edition is suited to teams establishing a vulnerability management foundation, while DefectDojo Pro is positioned for organizations with larger data volumes, broader stakeholder groups, and stronger automation and reporting requirements. Documentation and use cases point to cloud-native organizations, microservices environments, embedded systems teams, large enterprises, and organizations onboarding acquisitions or managing shared services.

Cloud Integrations and Marketplace

  • AWS Marketplace: DefectDojo, Inc. has a verified AWS Marketplace presence for its Professional Edition, and the platform also supports AWS-oriented integrations including AWS Security Hub and ASFF/Security Hub finding ingestion.
  • Microsoft Azure: DefectDojo, Inc. integrates with Microsoft Azure through Azure Boards for remediation workflow handoff and supports ingestion of Azure Security Center, now Microsoft Defender for Cloud, findings.
  • Google Cloud: DefectDojo, Inc. supports Google Cloud integration through ingestion of Google Cloud Artifact Vulnerability Scan results, allowing cloud vulnerability data to flow into the platform’s finding management workflow.

Key People

  • Greg Anderson: CEO & Co-Founder
  • Matt Tesauro: Co-Founder & CTO
  • Frank Morris: Chief Revenue Officer
  • Abbey Kirkland: Customer Success Manager

Key Facts

  • Headquarters: Austin, Texas, United States
  • Employees: Approximately 25 employees
  • Annual Revenue: Undisclosed
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Private

Analyst Recognitions

  • IDC: 2025 IDC MarketScape: Worldwide Application Security Posture Management (#US53001925e) – Major Player.
DefectDojo

Enter a search