DryRun Security Marks First Year Out of Stealth

DryRun Security Marks First Year Out of Stealth with Strong Momentum

Read Time: 3 minutes

AI-native code security intelligence built for the age of agentic software development

DryRun Security, the industry’s first AI-native, code security intelligence company, has completed its first year out of stealth with strong corporate momentum. Over the past twelve months, the company delivered major product innovations, conducted industry-leading vulnerability research, and laid the groundwork for securing autonomous software development in the era of agentic AI.

“Modern software development has evolved dramatically, with autonomous agents and vibe coding quickly taking shape across the industry,” said James Wickett, CEO and co-founder of DryRun Security. “As AI agents take on more responsibility in coding workflows, security must become contextual, proactive, and embedded directly into the development process. DryRun Security has built the foundation for that future.”

Rapid Growth and Market Adoption

Early last year, DryRun Security closed an $8.7 million seed funding round, accelerating investments across product development, go-to-market expansion, and customer success. Enterprise and mid-market adoption has surged, with customers now running more than 250,000 code reviews every month—more than any other AI-native code security intelligence provider.

Product Innovation Built for Agentic Development

Over the past year, DryRun Security doubled down on innovation to address the limitations of traditional application security tools. Its AI-native Contextual Security Analysis (CSA) engine was purpose-built to support agentic development, delivering security insights that understand code behavior, execution context, and autonomous decision-making across both human- and AI-driven workflows.

  • Natural Language Code Policies (NLCPs): Enable security teams to define secure coding requirements in plain English, embedding policies directly into pull requests instead of static documentation.
  • Custom Policy Agent: Enforces natural language policies within developer workflows by scanning every pull request and delivering inline, actionable feedback as an autonomous security guardrail.
  • Code Insights MCP: Securely connects code insights to MCP-compatible AI assistants, enabling natural language search, summaries, and trend reporting across repositories and pull requests.

Industry-Leading SAST Accuracy

DryRun Security’s contextual approach has delivered measurable accuracy gains. In the 2025 SAST Accuracy Report, DryRun detected 88% of seeded vulnerabilities out of the box—outperforming five leading static analysis tools, particularly on complex logic and authorization flaws.

These results validate the need for AI-native security as applications become increasingly complex, dynamic, and autonomous.

Addressing AppSec Blind Spots in AI Applications

The challenge is even greater in LLM-powered and agentic applications. In its research report, “Building Secure AI Applications,” DryRun Security found that more than 80% of vulnerabilities in LLM-enabled applications go undetected by traditional static analysis tools.

As execution paths become dynamic and code is increasingly generated or modified by autonomous agents, legacy AppSec approaches struggle to keep up—creating new classes of risk that require a fundamentally different security model.

Customer Perspective

“As we lean harder into AI-generated code and highly customized delivery environments, we need more than a traditional code scanner,” said Patrick McKinney, Vice President of Security at Invisible Technologies. “DryRun Security lets us continuously understand and explain our security posture in a way that maps to how modern engineering teams work. For us, it’s a core piece of building an AI-first security program going into 2026 and beyond.”