Company profile
depthfirst
Autonomous security platform for modern application security from design to production.
- Category
- Security AI
- Headquarters
- San Francisco, California
- Sells to
- Mixed
- Business model
- SaaS subscription
- Deployment
- Cloud / SaaS
- Pricing
- Not published
- Builds own models
- Yes
- Modalities
- Code
What depthfirst does
depthfirst provides an autonomous security platform that acts as an operating system for modern application security. It offers a comprehensive defensive security intelligence layer for applications, understanding code, infrastructure, and business logic. The platform uses AI to find and exploit vulnerabilities at scale, providing shared context, intelligent workflows, and autonomous remediation for humans and AI agents. It aims to protect, detect, validate, and remediate at AI scale, improving with continued use and reducing false positives. The system ingests continuous signals and deploys enterprise-grade security from design to production, securing every layer of a system from code to supply chain. It also includes governance, system of record, audit trails, and role-based access, and is compliant with rigorous security standards like SOC 2 and BYOK.
Products
- Dependency FirewallBlocks malicious packages and detects malicious behavior before it spreads through the environment.
- Security ReviewerValidates human and AI-generated code changes to prevent vulnerabilities, sensitive data, or malware from entering the codebase.
- Agentic PentestingConfirms exploitable vulnerabilities by testing running applications with real attack paths.
- Secrets & Sensitive DataDetects and validates credentials across codebase, CI/CD pipelines, and runtime environments.
- Supply ChainTraces risk through the full dependency tree and surfaces vulnerabilities with a real execution path.
- GovernanceAllows setting policies once, which are then inherited by every scan, fix, and agent action.
- System of recordCentralizes every finding, decision, and fix, making them searchable, exportable, and audit-ready.
- Audit trailLogs every human and agent action, making them immutable and traceable.
- Role-based accessProvides granular access control for teams, scoped by repository, environment, or organization.
Key capabilities
- Autonomous security from design to production
- Self-learning security system that improves with continued use
- Ingests continuous signals
- Enterprise-grade security
- Traces business logic, data flows, and cross-service interactions across codebase
- Detects malicious behavior
- Confirms exploitable vulnerabilities with real attack paths
- Detects and validates credentials
- Traces risk through full dependency tree
- Governance for policy setting
- System of record for findings and fixes
- Audit trails for human and agent actions
- Role-based access control
- SOC 2 compliant
- BYOK (Bring Your Own Key) support
- Integrated with existing workflows
- Maps entire application and builds structural understanding using LLMs
- Reasons through application to find real attack paths and business logic flaws
- Evaluates conditions for exploitation and runs dynamic tests
- Generates pull requests for confirmed vulnerabilities
- Replays attacks after fixes are merged to confirm resolution
- Continuous learning from developer feedback
- Component graph mapping data flows and cross-service relationships
- Security analytics for tracking vulnerabilities, burn down, and time to remediate
- Business context integration for risk profiling
- Natural language rules for detection
- API connectivity for programmatic integration
Use cases
- Securing software applications
- Vulnerability discovery and exploitation prevention
- Malware detection in dependencies
- Validating human and AI-generated code changes
- Detecting and validating credentials
- Tracing supply chain risk
- Automated security policy enforcement
- Auditing security findings and actions
- Managing access control for security teams
- Building AI-native security programs
- Increasing code-security coverage
- Securing production environments
AI approach
depthfirst uses AI, including multiple LLMs and reinforcement learning, to build a self-learning security system that understands application structure, identifies vulnerabilities, and automates remediation. It trains agents for vulnerability discovery and improves over time by learning from developer feedback.
Tech named: LLMs, Reinforcement Learning, AI agents
Industries served
- Computer and Network Security
- Retail
- Hospitals
- Banks
- Power grids
- Defense systems
- Fast-growing startups
- Global enterprises
What it says sets it apart
- Autonomous security from design to production
- Self-learning system that improves with continued use
- Over 90% fewer false positives than traditional tools
- Detects novel malware in dependencies in under 3.5 minutes
- Saves over 6 FTE developer years
- Over 50% cheaper than the next best security harness
- Uses multiple LLMs in parallel to build structural understanding of systems
- Reasons through applications to find real attack paths, business logic flaws, and chained vulnerabilities
- Generates pull requests for confirmed vulnerabilities against actual codebase and conventions
- Confirms vulnerability resolution by replaying attacks after fixes
- Backed by investors with history in security, infrastructure, and mission-critical software
- Founders have experience building and securing large-scale software systems at companies like Faire, Cash App, AWS, Databricks, and Google DeepMind
Funding rounds we track
Meritech Capital, Forerunner Ventures, The House Fund, Accela, Box Group, Liquid 2 Ventures
Accel, Alt Capital, Accel Partners, BoxGroup, Liquid 2 Ventures, Mantis VC, SV Angel, The House Fund
From the AI funding tracker — rounds as reported by the linked publications.
This profile was compiled from depthfirst's own public pages in July 2026 and reflects what the company states about itself — not an endorsement or an independent audit of those claims. Facts are extracted with AI and filtered by an automated check that drops any named product, customer or certification missing from the source pages. Full method. Something out of date? Tell us.