Market Opportunity
Stop malicious npm installs at install time - preinstall CLI inspector targets a $9.0B = 18M developer teams x $500 ACV. Rationale: global developer population roughly 25-30M; assume 18M small-to-large developer teams/orgs that would consider developer-security tooling, each averaging $500/year on per-team/preinstall protection and policy tooling in a mature market. total addressable market with medium saturation and a year-over-year growth rate of 12-20% growth in developer security and supply-chain security adoption, driven by automation and regulatory focus.
Key trends driving demand: AI-driven automation of development workflows -- agents and CI automation are running installs autonomously, increasing unsupervised exposure to malicious packages.; Rising supply-chain attacks -- attackers are increasingly targeting package ecosystems and postinstall scripts, creating demand for preinstall defenses.; Shift-left security plus runtime checks -- teams want both static SCA and runtime/behavioral protections to catch novel compromises beyond CVEs..
Key competitors include Snyk, GitHub Dependabot and GitHub Advanced Security, Sonatype Nexus / OSS Index, JFrog Xray, npm audit / native tooling and lightweight OSS projects.