GrammaTech, a high-profile provider of application security testing products and software research services, and Multi-Award Champion in the Annual ‘ASTORS’ Homeland Security Awards Program, announced its software products division, including the CodeSonar and CodeSentry product lines, have been acquired by Battery Ventures.
This transaction establishes a new, independent entity that will operate under the name CodeSecure, and be headquartered in Bethesda, Maryland.
GrammaTech will continue to offer cybersecurity research and development services and tools to the US defense and intelligence community.
The application security testing market (AST) is fast-growing, projected to show an annual growth rate (CAGR 2023-2028) of 12.83%, according to data provider Statista, resulting in a market volume of US$11bn by 2028.
More organizations are buying this software as attacks on software supply chains increase, prompting them to build security into their software development lifecycles earlier.
“We are excited to partner with the CodeSecure product team on its mission to enable developers to detect and fix vulnerabilities within their development pipelines, allowing them to accelerate critical DevSecOps deployments,” explained Battery Vice President Lauren Wedell, who is joining CodeSecure’s board.
“We’re also looking forward to working with the team behind CodeSentry, a technology with multiple use cases, from detecting open-source vulnerabilities in third-party code to generating software bill of materials (SBOMs).”
“We’re extremely impressed with the company’s vision and execution in this market to date, and we look forward to helping the new company grow organically and, potentially, through acquisitions,” added Battery Partner Jordan Welu, who is also joining the company’s board.
The Battery investment will allow CodeSecure to operate with greater flexibility and grow its business in markets including automotive, aerospace and defense, medical devices, IoT, enterprise IT, and financial services, all sectors in which code security and safety is imperative.
(CodeSentry 4.2 is now deployed to all SaaS instances and is also available for on-premise installations. CodeSentry 4.2 makes searching your software inventory for vulnerable open-source packages easy with the new ‘Component Search’ feature. The new CodeSentry Dashboard also provides a ‘single pane of glass’ overview of artifact scanning and results across the CodeSentry instance. Courtesy of GrammaTech and YouTube.)
“Software security is undergoing significant change and expansion; many organizations are creating their own product security teams and recognizing that product safety is a critical function,” said Mike Dager, who will serve as CEO of CodeSecure.
“With more than 40 years of experience growing some of the world’s most well-known software businesses, we feel Battery Ventures is the ideal partner to help us scale up the CodeSonar and CodeSentry product lines.”
“They have the resources and are committed to our success. We are excited to be working with them.”
GrammaTech will continue to focus on the growth and expansion of its core cyber security offerings and services to the US Government Department of Defense and Intelligence Community under the direction of Dan Goodwin, who was elevated to the role of CEO of GrammaTech following the acquisition of CodeSecure by Battery.
Canaccord Genuity and McGuire Woods advised GrammaTech on the transaction.
CodeSecure CodeSonar is a SAST (Static Application Security Testing) solution that enables developers to create and release high-quality, secure software. CodeSonar promotes a shift-left approach that ensures developers can implement security early and throughout the Software Development Life Cycle (SDLC) without impacting innovation or slowing time-to-market.
The CodeSecure CodeSentry software supply chain security platform allows organizations to produce SBOMs and detect security vulnerabilities “under the hood” in third-party code. CodeSentry uses binary software composition analysis (BSCA) to identify known threats (CVEs) and common weakness enumeration (CWE) errors in externally developed software components without access to source code. CodeSentry also plays a valuable role in helping organizations meet emerging federal standards for cyber security.
CodeSecure is a leading global provider of application security testing (AST) solutions used by the world’s most security-conscious organizations to detect, measure, analyze, and resolve vulnerabilities for software they develop or use. CodeSecure products enable rapid DevSecOps deployments while also securing their software supply chains.
CodeSecure has corporate headquarters in Bethesda, MD, and publishes Shift Left Academy, an educational resource for product software developers.
To learn more, visit www.codesecure.com.
CodeSentry Nominated to Compete in Fifth ‘ASTORS; Homeland Security Awards
American Security Today’s Annual ‘ASTORS’ Awards is the preeminent U.S. Homeland Security Awards Program, and now entering its Eighth Year, continues to recognize industry leaders of Physical and Border Security, Cybersecurity, Emergency Preparedness – Management and Response, Law Enforcement, First Responders, as well as federal, state and municipal government agencies in the acknowledgment of their outstanding efforts to Keep our Nation Secure.
Best SBOM (Software Bill of Materials) Solution
Enterprise organizations are using hundreds of pre-packaged
commercial-off-the-shelf (COTS) business applications for communication, project management, productivity, billing, HR/payroll, ERP, CRM, BI, and more using open-source software components to innovate faster, accelerate time-to-market and lower development costs; however, research finds that 100% of widely used applications contained vulnerable open source components.
The security risk to organizations from a vulnerable software supply chain is high. Hackers are actively exploiting vulnerabilities in widely reused open-source libraries within applications, and they have already leveraged apps like Slack, Zoom, Microsoft Office.
While organizations have traditionally trusted software vendors to manage security risk associated with the applications they produce, the increasing frequency of software supply chain attacks is forcing enterprises to address risk themselves proactively.
GrammaTech CodeSentry quickly analyzes COTS applications to identify the use of open-source components and detects any associated security vulnerabilities. CodeSentry generates standard format SBOMs (SPDX and CycloneDX), derives a proprietary security score, and detects zero-day and N-day vulnerabilities, even when source code is unavailable.
CodeSentry features an easy-to-use upload interface and multiple output formats accessible to IT, risk, and security professionals without programming experience. For high-security businesses and government agencies, CodeSentry is available as an on-premises solution. Others can use the scalable, Software-as-a-Service (SaaS) option.
GrammaTech has extensive experience conducting advanced research in application security for defense agencies, including the DOD, DARPA, Army, and Navy. CodeSentry originated from one of these advanced research projects.
GrammaTech’s researchers developed highly complex algorithms identifying all software components, including custom code, vendor libraries, third-party code, and OSS for software mapping, look-up, and N-day and zero-day vulnerabilities. These algorithms work even when source code is unavailable.
(At least 90% of corporations use third-party software, and 95% of proprietary or custom software applications they create contain third-party components. To overcome this blind spot in assessing third-party software inventory and risk, CodeSentry allows security professionals to measure and manage the risk associated with open source vulnerabilities in third-party software quickly and easily. Courtesy of GrammaTech and Youtube.)
*GrammaTech was also recognized in the 2021, and 2020 ‘ASTORS’ Homeland Security Awards Program.
AST puts forward the Largest and Most Qualified Circulation in Government with Over 75,000 readers on the Federal, State and Local levels.
AST Digital Publications are distributed to over 75,000 qualified government and homeland security professionals, in federal, state, local, and private security sectors.
‘PROTECTING OUR NATION, ONE CITY AT A TIME’
AST Reaches both Private & Public Experts, essential to meeting these new challenges.
Today’s new generation of public safety and security experts need real-time knowledge to deal with domestic and international terrorism, lone wolf attacks, unprecedented urban violence, shifts in society, culture, and media bias – making it increasingly difficult for Homeland Security, Law Enforcement, First Responders, Military and Private Security Professionals to implement coordinated security measures to ensure national security and improve public safety.
These experts are from Government at the federal, state, and local levels as well as from private firms allied to the government.
AST provides a full plate of topics in our AST Monthly Magazine Editions, AST Website, and AST Daily News Alerts, covering 23 Vital Sectors such as Access Control, Perimeter Protection, Video Surveillance/Analytics, Airport Security, Border Security, CBRNE Detection, Border Security, Ports, Cybersecurity, Networking Security, Encryption, Law Enforcement, First Responders, Campus Security, Security Services, Corporate Facilities, and Emergency Response among others.
AST has Expanded readership into integral Critical Infrastructure audiences such as Protection of Nuclear Facilities, Water Plants & Dams, Bridges & Tunnels, and other potential targets of terrorism.
Other areas of concern include Transportation Hubs, Public Assemblies, Government Facilities, Sporting & Concert Stadiums, our Nation’s Schools & Universities, and Commercial Business Destinations – all enticing targets due to the large number of persons and resources clustered together.
To learn more, please see the 2022 ‘ASTORS’ CHAMPIONS Edition Fully Interactive Magazine – the Best Products of 2022 ‘A Year in Review.’
The Annual CHAMPIONS edition reviews ‘ASTORS’ Award Winning products and programs, highlighting key details on many of the winning firm’s products and services, including video interviews and more.
The 2022 CHAMPIONS serves as your Go-To Source through the year for ‘The Best of 2022 Products and Services‘ endorsed by American Security Today – and can satisfy your agency’s and/or organization’s most pressing Homeland Security and Public Safety needs.
From Physical Security (Access Control, Critical Infrastructure, Perimeter Protection, and Video Surveillance Cameras and Video Management Systems), to IT Security (Cybersecurity, Encryption, Data Storage, Anti-Malware, and Networking Security – to name a few), the 2022 ‘ASTORS’ CHAMPIONS EDITION has what you need to Detect, Delay, Respond to, and Mitigate today’s real-time threats in our constantly evolving security landscape.
It also features guest editorial pieces from some of the security industry’s most respected leaders and recognized firms in the 2022 ‘ASTORS’ Awards Program.
For more information on All Things American Security Today, as well as the 2023 ‘ASTORS’ Awards Program, please contact Michael Madsen, AST Publisher at firstname.lastname@example.org.
AST strives to meet a 3 STAR trustworthiness rating, based on the following criteria:
- Provides named sources
- Reported by more than one notable outlet
- Includes supporting video, direct statements, or photos