Market Opportunity
Block malicious npm/pip installs by inspecting install-time behavior targets a $9.6B = 1.6M software development organizations x $6,000 ACV. Assumes global pool of commercial and open-source-backed engineering orgs that buy security/dependency tooling, with average security-tool spend per organization around $6k/year. total addressable market with medium saturation and a year-over-year growth rate of 15-25% growth in developer security and software supply-chain tooling spend driven by regulatory and incident-driven demand.
Key trends driving demand: AI coding agents -- increase in unattended package installs, raising frequency of potentially malicious install events; Supply-chain attacks -- rising number and visibility of dependency compromises, increasing buyer urgency for new controls; Shifting left in security -- developers prefer lightweight, inline tools that run in CI and locally without blocking velocity; Registry velocity -- package ecosystems like npm and PyPI publish many releases daily, widening the window for zero-day compromises.
Key competitors include Snyk, Sonatype (Nexus Firewall / Lifecycle), GitHub Dependabot / GitHub Advanced Security, npm audit / pip-audit and local linters.