ShiftLeft Exits Stealth Mode
October 11, 2017

ShiftLef emerged from stealth mode to enable organizations to secure their cloud applications and microservices as part of their continuous integration pipeline, rather than merely reacting to threats discovered in production.

The company is launching with a $9.3 million Series A round of funding from top-tier venture capital firms Bain Capital Ventures and Mayfield, and from individual investors. In addition, Enrique Salem, Bain Capital Ventures managing director, FireEye board chairman, and former Symantec CEO; and Ursheet Parikh, Mayfield partner and StorSimple founder and former CEO, have joined the company’s Board of Directors.

ShiftLeft also announced the general availability of fully-automated Security-as-a-Service (SECaaS) for cloud software that understands the security needs of each version of each application, and creates custom security and threat detection for it. It is offered as a try-and-buy solution. With ShiftLeft, organizations can now secure their cloud applications as part of their continuous integration pipeline, rather than merely reacting to threats discovered in production. ShiftLeft also identifies vulnerabilities, including contextual vulnerabilities with usage of Open Source Software (OSS) and data leakage risks, allowing organizations to either fix them or protect against them in production using ShiftLeft’s Microagent.

ShiftLeft founders are experts with an extensive background in security and cloud infrastructure. CEO Manish Gupta (formerly of FireEye, Cisco, and McAfee) has been at the helm of several security innovations such as malware sandbox and Next Generation Firewall. CTO Chetan Conikee (formerly of Cloud Physics, Business Signatures, and CashEdge), and Chief Architect Vlad A Ionescu (formerly of Google, LShift, and Founder of Lever OS) have enabled innovations that underpin the electronic transactions in the financial industry and several open source initiatives.

ShiftLeft is directed by a strong Advisory Board, including Florian Leibert, Mesosphere CEO; Mitch Wainer, DigitalOcean co-founder and head of brand marketing; and Gabe Monroy, lead program manager for containers at Microsoft Azure.

“With its DevOps and SecOps friendly solution that blends security knowledge of code from build-time with runtime data from production, ShiftLeft solves a real problem for customers without slowing them down,” said Leibert.

ShiftLeft was founded with the mission to develop a better approach to protecting the next engine of innovation – software. The team sought to solve the problem of matching signatures to fast changing threats that results in an overwhelming amount of false alerts, making security capital and operationally inefficient. They realized scarce security talent coupled with the rapid increase in software causes traditional security approaches to fail. The team set out to invent a solution that with each new build extracts all security relevant aspects from the codebase, called Security DNA, and uses it to create a custom Microagent to provide runtime protection. Now for the first time, software is able to inform teams how it should be protected around its unique security specific needs.

“There is a large and important opportunity in the industry today to insert highly accurate security in the continuous integration and delivery (CI/CD) lifecycle, without impacting an organization’s pace of innovation,” said Gupta. “By assembling a world-class team that truly understands security, modern software development practices that enable Cloud adoption, and modern program analysis techniques, ShiftLeft is in an unparalleled position to deliver on this opportunity.”

The Latest

September 18, 2018

To celebrate IT Professionals Day 2018 (this year on September 18), the SolarWinds IT Pro Day 2018: A World Powered by Tech Pros survey explores a "Tech PROactive" world where technology professionals have the time, resources, and ability to use their technology prowess to do absolutely anything ...

September 17, 2018

The role of DevOps in capitalizing on the benefits of hybrid cloud has become increasingly important, with developers and IT operations now working together closer than ever to continuously plan, develop, deliver, integrate, test, and deploy new applications and services in the hybrid cloud ...

September 13, 2018

"Our research provides compelling evidence that smart investments in technology, process, and culture drive profit, quality, and customer outcomes that are important for organizations to stay competitive and relevant -- both today and as we look to the future," said Dr. Nicole Forsgren, co-founder and CEO of DevOps Research and Assessment (DORA), referring to the organization's latest report Accelerate: State of DevOps 2018: Strategies for a New Economy ...

September 12, 2018

This next blog examines the security component of step four of the Twelve-Factor methodology — backing services. Here follows some actionable advice from the WhiteHat Security Addendum Checklist, which developers and ops engineers can follow during the SaaS build and operations stages ...

September 10, 2018

When thinking about security automation, a common concern from security teams is that they don't have the coding capabilities needed to create, implement, and maintain it. So, what are teams to do when internal resources are tight and there isn't budget to hire an outside consultant or "unicorn?" ...

September 06, 2018

In evaluating 316 million incidents, it is clear that attacks against the application are growing in volume and sophistication, and as such, continue to be a major threat to business, according to Security Report for Web Applications (Q2 2018) from tCell ...

September 04, 2018

There's a welcome insight in the 2018 Accelerate State of DevOps Report from DORA, because for the first time it calls out database development as a key technical practice which can drive high performance in DevOps ...

August 29, 2018

While everyone is convinced about the benefits of containers, to really know if you're making progress, you need to measure container performance using KPIs.These KPIs should shed light on how a DevOps team is faring in terms of important parameters like speed, quality, availability, and efficiency. Let's look at the specific KPIs to track for each of these broad categories ...

August 27, 2018

Protego Labs recently discovered that 98 percent of functions in serverless applications are at risk, with 16 percent considered "serious" ...

August 23, 2018

After another record year of breaches, The 2018 DevSecOps Community Survey found that 3 in 10 respondents suspected or verified breaches stemming from vulnerabilities in open source components — a 55% increase over 2017, and 121% increase since 2014 ...

Share this