ShiftLef emerged from stealth mode to enable organizations to secure their cloud applications and microservices as part of their continuous integration pipeline, rather than merely reacting to threats discovered in production.
The company is launching with a $9.3 million Series A round of funding from top-tier venture capital firms Bain Capital Ventures and Mayfield, and from individual investors. In addition, Enrique Salem, Bain Capital Ventures managing director, FireEye board chairman, and former Symantec CEO; and Ursheet Parikh, Mayfield partner and StorSimple founder and former CEO, have joined the company’s Board of Directors.
ShiftLeft also announced the general availability of fully-automated Security-as-a-Service (SECaaS) for cloud software that understands the security needs of each version of each application, and creates custom security and threat detection for it. It is offered as a try-and-buy solution. With ShiftLeft, organizations can now secure their cloud applications as part of their continuous integration pipeline, rather than merely reacting to threats discovered in production. ShiftLeft also identifies vulnerabilities, including contextual vulnerabilities with usage of Open Source Software (OSS) and data leakage risks, allowing organizations to either fix them or protect against them in production using ShiftLeft’s Microagent.
ShiftLeft founders are experts with an extensive background in security and cloud infrastructure. CEO Manish Gupta (formerly of FireEye, Cisco, and McAfee) has been at the helm of several security innovations such as malware sandbox and Next Generation Firewall. CTO Chetan Conikee (formerly of Cloud Physics, Business Signatures, and CashEdge), and Chief Architect Vlad A Ionescu (formerly of Google, LShift, and Founder of Lever OS) have enabled innovations that underpin the electronic transactions in the financial industry and several open source initiatives.
ShiftLeft is directed by a strong Advisory Board, including Florian Leibert, Mesosphere CEO; Mitch Wainer, DigitalOcean co-founder and head of brand marketing; and Gabe Monroy, lead program manager for containers at Microsoft Azure.
“With its DevOps and SecOps friendly solution that blends security knowledge of code from build-time with runtime data from production, ShiftLeft solves a real problem for customers without slowing them down,” said Leibert.
ShiftLeft was founded with the mission to develop a better approach to protecting the next engine of innovation – software. The team sought to solve the problem of matching signatures to fast changing threats that results in an overwhelming amount of false alerts, making security capital and operationally inefficient. They realized scarce security talent coupled with the rapid increase in software causes traditional security approaches to fail. The team set out to invent a solution that with each new build extracts all security relevant aspects from the codebase, called Security DNA, and uses it to create a custom Microagent to provide runtime protection. Now for the first time, software is able to inform teams how it should be protected around its unique security specific needs.
“There is a large and important opportunity in the industry today to insert highly accurate security in the continuous integration and delivery (CI/CD) lifecycle, without impacting an organization’s pace of innovation,” said Gupta. “By assembling a world-class team that truly understands security, modern software development practices that enable Cloud adoption, and modern program analysis techniques, ShiftLeft is in an unparalleled position to deliver on this opportunity.”