DryRun Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2023

Last updated: Jul 31, 2026

DryRun Security is an AI-native application-security platform that builds codebase context, reviews pull requests and repositories, validates exploitability, and gives developers remediation guidance and policy feedback where they work. Its stated differentiation is contextual security analysis for logic flaws and other risks that pattern-oriented SAST can miss.

Visit Website

Company Overview

DryRun Security sells a code-security intelligence layer for development and AppSec teams. Its product combines PR code review, repository-wide DeepScan analysis, custom code policies expressed in natural language, triage and trend reporting, secrets detection, and infrastructure-as-code checks. The company says its analysis first maps architecture, code relationships, Git behavior, frameworks, routes, authorization boundaries, and data flow into a continuously updated knowledge graph. Specialized agents then analyze code intent and behavior, prioritize likely hotspots, validate exploitability and impact, and guide a fix. This is a materially more ambitious proposition than a lint rule or a thin LLM wrapper, although the technical and economic value still depends on reproducible accuracy, latency, privacy controls, and the cost of model inference.

The target customer is an organization whose software change rate has outgrown its AppSec capacity. DryRun integrates with GitHub and GitLab and advertises notifications through Slack, with API and MCP capabilities for agent-native workflows. The current website lists support for Python, JavaScript, TypeScript, Java, C#, Ruby, and Go, while its documentation describes PR scanning, full-repository baselining, risk-register workflows, administration, and integrations. GitHub Enterprise Server support announced in the company blog is relevant to larger or regulated deployments. The value proposition is strongest when security engineers need to focus on a small number of consequential changes and developers need actionable explanations without leaving code review; the product is less obviously differentiated for teams that only need commodity secrets, IaC, or conventional SAST coverage.

Commercial signals are credible but should be separated from verified operating metrics. DryRun emerged from stealth in 2023, publicly identifies James Wickett and Ken Johnson as co-founders, and announced an $8.7 million seed round in January 2025 from LiveOak Venture Partners, Work-Bench, and Cannage Capital. Its own site displays customer testimonials or references associated with Tines, Commerce, Invisible Technologies, BrightHR, PlanetArt, SimpleRose, Denim Group, Cloud Security Partners, and Defect Dojo, and it publishes product and research updates. Those are useful evidence of market engagement, not proof of recurring revenue, retention, deployment breadth, or superior detection performance. Diligence should request cohort retention, paid conversion, expansion, scan volume by customer, gross margin after inference costs, independent benchmark methodology, and the proportion of findings that receive human confirmation.

Competitive pressure is high. DryRun competes with Snyk Code, Semgrep, GitHub Advanced Security and CodeQL, SonarQube, Checkmarx, Veracode, and newer AI-assisted code-review products. Incumbents already own repository permissions, CI/CD integrations, developer trust, and security data, while cloud and platform vendors can bundle code analysis into broader application-security suites. DryRun’s contextual knowledge graph, exploitability-oriented triage, natural-language policies, and agent-native remediation could create a useful wedge if the system consistently detects authorization, IDOR, authentication, injection, and business-logic weaknesses with fewer false positives. The key question is whether that advantage survives across languages, frameworks, monorepos, legacy systems, and adversarial or AI-generated code, rather than appearing only in curated demonstrations.

The strategic and national-security relevance is defensive and credible. Software assurance, secure code review, supply-chain visibility, and protection of developer pipelines matter to cloud providers, regulated enterprises, critical-infrastructure vendors, and public-sector software programs. The same product can help screen human-written and AI-generated changes before deployment and can produce security evidence for governance or customer assurance. That creates dual-use adjacency without implying government adoption, classified work, offensive capability, or a defense contract. The record therefore merits continued strategic tracking as an early-stage defensive cyber company, with medium risk because the market is crowded, the product handles sensitive source code, and the strongest performance claims remain company-reported rather than independently established.

Dual-Use Assessment

Military & Commercial Applications

DryRun's core capability is defensive software assurance: contextual code analysis, exploitability triage, policy enforcement, and remediation guidance. Those functions serve commercial engineering teams and have substantive applicability to public-sector, critical-infrastructure, and sensitive software supply-chain assurance. The adjacency does not establish government use, classified work, offensive capability, or a defense contract.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

DryRun is a credible strategic-priority signal for a defensive cyber thesis because it addresses AppSec capacity limits at the point where software changes are created and has disclosed seed financing, a live product, public customer references, and an expanding agent-native feature set. The thesis depends on diligence proving durable precision and recall, paid usage and retention, acceptable inference economics, source-code privacy, and a repeatable enterprise sales motion. This flag is an internal fit signal, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

DryRun could become a software-assurance control point between code generation and production. Its contextual review, policy enforcement, repository intelligence, and support for AI-assisted development are relevant to organizations that need to increase code velocity without losing visibility into exploitable risk. Strategic value is highest if the product can operate in sensitive environments, integrate with existing security programs, and produce independently defensible evidence; no public evidence here establishes government deployment or mission-critical adoption.

Key Technologies

  • Contextual security analysis across code and architecture
  • Knowledge-graph modeling of code relationships, data flow, and authorization boundaries
  • Agentic exploitability validation and impact prioritization
  • AI-assisted pull-request and repository code review
  • Natural-language custom security policies
  • Secrets and infrastructure-as-code analysis
  • API, MCP, GitHub, GitLab, Slack, and GitHub Enterprise Server integrations

Use Cases & Applications

  • Prioritizing exploitable authorization, IDOR, injection, authentication, and business-logic risks in pull requests
  • Running full-repository baselines to find structural and legacy code risk
  • Giving developers contextual remediation guidance inside GitHub or GitLab workflows
  • Screening human-written and AI-generated code before merge or deployment
  • Enforcing organization-specific security policies without maintaining large rule sets
  • Detecting hardcoded credentials and infrastructure-as-code misconfigurations
  • Generating code-security evidence and trend views for regulated or customer-facing assurance
  • Supporting software-supply-chain risk reduction in critical infrastructure and public-sector vendors

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

DryRun Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies DryRun Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.