Mend.io provides a unified security platform for application security and AI security. The company helps organizations secure custom code, open source dependencies, APIs, runtime applications, and AI-powered software through a governed workflow that connects discovery, testing, prioritization, remediation, and compliance activities across the software lifecycle.
Mend.io’s market position builds on an early foundation in software composition analysis and has expanded into a broader AppSec and AI security platform. Today, Mend.io focuses on securing both the code layer and the AI layer, giving development, security, and compliance teams a single operating model for reducing software risk while supporting modern, AI-driven development practices.
Offerings, Capabilities, and Integrations
Mend.io’s platform is designed to unify risk visibility and remediation across software supply chain security, code security, dynamic testing, API exposure, and AI application risk. Its capabilities span inventory, policy enforcement, exploitability-based prioritization, automated remediation, governed workflows, and audit-ready outputs such as SBOM and AI-BOM artifacts, helping teams operationalize security without fragmenting processes across multiple point tools.
Mend.io emphasizes integration into existing developer and security workflows. It supports repository and SCM environments such as GitHub, GitHub Enterprise, GitLab, Bitbucket, and Azure Repos; IDEs including Visual Studio Code, Visual Studio, IntelliJ IDEA, PyCharm, WebStorm, and Eclipse; CI/CD and registry tooling such as Jenkins, AWS CodeBuild, Google Cloud Build, Amazon ECR, Azure Container Registry, and Google Container Registry; and issue and security ecosystems including Jira, ServiceNow, Microsoft Defender for Cloud, and AI coding tools such as Cursor, GitHub Copilot, Amazon Q Developer, Claude Code, Windsurf, and Google Gemini.
Products and Services
- Mend AppSec: Unified application security platform that brings together testing, findings, remediation workflows, and governance across code, open source, runtime, APIs, and AI-related risk.
- Mend AI: AI security offering for inventorying and governing AI components, securing AI-generated code, hardening system prompts, supporting AI-BOM workflows, and testing AI-powered applications for behavioral risk.
- Mend SCA: Software composition analysis solution for open source risk management, including reachability analysis, vulnerability prioritization, license compliance, SBOM support, and developer-focused remediation.
- Mend SAST: Static application security testing for custom code with AI-tuned analysis, in-repository feedback, and AI-powered remediation guidance to help developers fix high-priority issues faster.
- Mend Renovate Enterprise: Enterprise-grade dependency update automation that detects outdated dependencies and creates pull requests at scale, with support for self-hosting, premium support, and merge confidence workflows.
- DAST: Dynamic application security testing that identifies exploitable runtime vulnerabilities and connects runtime findings with code-level issues inside the Mend AppSec workflow.
- API Security: API security capability that discovers and inventories APIs, including shadow APIs, and helps teams monitor and remediate vulnerabilities across REST, SOAP, and GraphQL endpoints.
- EOL Support: Support for deprecated open source software through HeroDevs-backed replacement packages, ongoing CVE remediation, and compliance-oriented maintenance for end-of-life frameworks and libraries.
Target Customers
Mend.io targets software-producing organizations that need to secure modern development at enterprise scale. Its buyers and users typically include application security teams, DevSecOps leaders, platform engineering teams, developers, and compliance stakeholders that want security embedded in everyday workflows rather than managed as a separate process.
The platform is well suited to enterprises with large codebases, extensive open source usage, complex repository environments, and growing adoption of AI coding assistants or AI-powered applications. Its customer footprint and use cases align especially well with global organizations in technology, financial services and insurance, healthcare and life sciences, telecommunications, manufacturing, media, and other regulated or risk-sensitive sectors.
Cloud Integrations and Marketplace
- AWS Marketplace: Mend.io has a verified AWS Marketplace presence, including a Mend.io AppSec Platform listing available as SaaS on AWS for cloud procurement and deployment.
- Microsoft Azure Marketplace: Mend.io has a verified Microsoft Azure Marketplace presence for its AI Native AppSec Platform, and Mend Renovate Enterprise is also available through the Azure commercial marketplace.
Key People
- Azi Cohen: Co-Founder & CEO
- Rami Sass: Co-Founder, GM Mend AI
- Ilan Sidi: Chief Financial Officer
- Alon Klomek: Chief Revenue Officer
- Stephanie Broyles: Chief Marketing Officer
- Yaron Avisror: EVP Engineering
- Vered Shaked: EVP Corporate Development
- Robert Nilsson: EVP Customer Experience
- Galit Gold: EVP HR
- Inbar Seif Zuta: Chief of Staff and AI Transformation Lead
- Amit Chita: Field CTO
Key Facts
- Headquarters: Givatayim, Tel Aviv District, Israel
- Employees: Approximately 280
- Annual Revenue: $25M-$100M
- Parent Company: None
- Subsidiaries: 2 subsidiaries, including WhiteSource Software, Inc. and WhiteSource Zagreb d.o.o.
- Publicly Listed: Private
Analyst Recognitions
- Gartner: 2025 Gartner Magic Quadrant for Application Security Testing: Visionary.
- Forrester: The Forrester Wave: Software Composition Analysis, Q4 2024: Strong Performer.