Market Opportunity
Block malicious npm and pip installs by inspecting packages at install time targets a $4.8B = 160,000 mid-to-large software teams x $30,000 ACV. Rationale: target customers are orgs with dedicated security/devops and CI pipelines; enterprise security tooling ACV typically tens of thousands. total addressable market with medium saturation and a year-over-year growth rate of 18-25% for developer security and SCA adjacent markets, driven by rising supply chain risk and cloud-native adoption.
Key trends driving demand: AI coding agents and automation -- agents autonomously run installs, increasing unattended package pulls and the attack surface.; Software supply chain attacks -- adversaries target package ecosystems, creating demand for pre-install defenses that catch novel compromises.; Shift-left and runtime hybrid security -- teams expect prevention across dev and CI workflows, not just post-facto scanning.; Open source ecosystem centrality -- heavy reliance on npm and PyPI means a single compromised package can impact many users, raising urgency for install-time controls..
Key competitors include npm audit (built-in), Snyk, Sonatype Nexus Lifecycle, Sigstore.