F5 announced the general availability of F5 NGINXaaS for Azure, an integrated solution co-developed by F5 and Microsoft that empowers enterprises to deliver secure, high-performance applications in the cloud.
ShiftLeft raised $20 million in Series B funding.
This latest round, led by Thomvest Ventures and joined by new investor SineWave Ventures as well as existing investors Bain Capital Ventures and Mayfield, comes less than 18 months after the company announced its first round of $9.3 million, bringing the total raised to nearly $30 million. The company is also announcing the addition of Jim Sortino, who previously held executive roles at Trend Micro and Dome9 Security (acquired by Checkpoint), as vice president of worldwide sales.
The company is using these funds to drive broader adoption of its code-informed runtime protection by expanding the breadth of its product portfolio, application coverage and global sales and marketing initiatives.
“The company has an impressive team, led by CEO, Manish Gupta. ShiftLeft provides intelligent automation of code security, which addresses a major pain point for the CISOs of modern enterprises: to protect applications and data,” said Umesh Padval, venture partner at Thomvest Ventures. “ShiftLeft’s unique architecture provides a prioritized list of vulnerabilities with the least number of false positives and detailed vulnerability information, which helps developers remediate rapidly. A high-performance runtime solution that can protect applications in production empowers security teams to embrace automation as the solution which integrates seamlessly into the CI/CD [continuous integration/continuous delivery] workflow of an organization.”
From containers and microservices to cloud and open source, a vast array of forces are rapidly changing and accelerating application development and deployment. This investment underscores both the importance of ensuring security despite this complex landscape, and ShiftLeft’s ability to empower application security teams to protect the enterprise. ShiftLeft uses code analysis to deeply understand application vulnerabilities, and create a virtual security perimeter to detect and protect every application version against malicious or unauthorized activity targeted at those vulnerabilities.
As part of its growth initiative, ShiftLeft has also created an advisory board of prominent security and development thought leaders, including:
Bob Flores, former CTO of the Central Intelligence Agency
Craig Rosen, CISO of AppDynamics
Shahar Ben Hador, CIO of Exabeam
Aaron McKeown, head of security engineering and architecture at Xero
Manish Arya, founder and CTO of Tavant
Yonatan Ryabinski, chief enterprise architect at Vanguard
“Our founding vision is that application security needs to be a seamless part of the development process, not an afterthought,” said Manish Gupta, CEO and co-founder of ShiftLeft. “The problem has long been inaccurate tools and a heavily manual process, leaving security and development teams frustrated and applications vulnerable. ShiftLeft completely upends this paradigm, delivering automated and customized protection for every software release, and the analytics dev teams need to improve on the overall security posture.”
“I’ve seen organizations struggle through a reactive, threat-focused security posture, resulting in overworked security teams and frequent breaches,” said Enrique Salem, partner at Bain Capital Ventures and former CEO of Symantec. “Yet ShiftLeft gets at the root problem – vulnerable software – by automating the process of accurately and rapidly analyzing and plugging vulnerabilities in the applications themselves. It’s exciting to be an investor in a company that is meaningfully helping security teams by reducing the overall attack surface and providing direct root-cause insight for developers.”
“Every modern company has become a software company, making application security vital,” said Ursheet Parikh, partner at Mayfield. “So it’s no surprise security is daily news: as the volume and pace of new applications has skyrocketed, the number of vulnerabilities has exploded. The ability to customize security for each version of every application is what drew us to ShiftLeft, and why we think the company promises to have a remarkable impact on the overall market.”
Industry News
Tenable announced Tenable Ventures, a corporate investment program.
Ubuntu Pro, Canonical’s comprehensive subscription for secure open source and compliance, is now generally available.
Mirantis, freeing developers to create their most valuable code, today announced that it has acquired the Santa Clara, California-based Shipa to add automated application discovery, operations, security, and observability to the Lens Kubernetes Platform.
SmartBear has integrated the powerful contract testing capabilities of PactFlow with SwaggerHub.
Venafi introduced TLS Protect for Kubernetes.
Tricentis announced the general availability of Tricentis Test Automation, a cloud-based test automation solution that simplifies test creation, orchestration, and scalable test execution for easier collaboration among QA teams and their business stakeholders and faster, higher-quality, and more durable releases of web-based applications and business processes.
Couchbase announced its Couchbase Capella Database-as-a-Service (DBaaS) offering on Azure.
Mendix and Software Improvement Group (SIG) have announced the release of Mendix Quality & Security Management (QSM), a new cybersecurity solution that provides continuous deep-dive insights into security and code quality to immediately address risks and vulnerabilities.
Panaya announced a new Partnership Program in response to ongoing growth within its partner network over the past year.
Cloudian closed $60 million in new funding, bringing the company’s total funding to $233 million.
Progress announced the R1 2023 release of Progress Telerik and Progress Kendo UI.
Wallarm announced the early release of the Wallarm API Leak Management solution, an enhanced API security technology designed to help organizations identify and remediate attacks exploiting leaked API keys and secrets, while providing on-going protection against hacks in the event of a leak.