Dossier · Acquired asset · 5 independent sources
Oxeye Security
Last updated: Jul 31, 2026
Oxeye Security was an Israeli cloud-native application security company whose technology connected code-level findings with runtime context to identify and prioritize exploitable application risks. GitLab acquired Oxeye on 20 March 2024, so this record now represents an acquired security technology and team rather than an independently actionable startup.
Company Overview
Oxeye built cloud-native application security testing and risk-management technology for software teams operating across the software development lifecycle. Its product went beyond a conventional list of SAST, software-composition, and dynamic-testing findings by correlating application-layer vulnerabilities with execution and deployment context. The practical objective was to show which findings were reachable or exploitable, and therefore deserved engineering attention, instead of treating every scanner result as equally urgent. GitLab described the acquired capability as tracing risk from code to cloud through data collection and analysis, with an emphasis on reducing false positives and producing actionable remediation information.
The customer problem was credible and commercially important. Modern applications combine first-party code, open-source dependencies, containers, microservices, and rapidly changing cloud environments; security teams can discover more findings than developers can investigate. Oxeye's approach targeted AppSec alert fatigue and the operational gap between a vulnerability's theoretical presence in source code and its exposure in a running application. The likely buyers were enterprise security and development organizations seeking better prioritization, faster remediation, and less manual triage inside DevSecOps pipelines. Public reporting indicates Oxeye raised a $5.3 million seed round in 2021; the available evidence does not support the prior record's Series A claim.
Competition came from broad platform vendors and specialized application-security tools. Static-analysis, dependency-scanning, DAST, IAST, runtime application protection, and cloud-security products can each address part of the workflow, while larger vendors increasingly combine these functions. Oxeye's strongest differentiation was therefore not simply that it scanned code, but that it used contextual reachability and exploitability signals to improve prioritization. That distinction could be valuable if accuracy held across languages, frameworks, build systems, and production-like environments, but it also created integration and proof-of-ROI requirements. Oxeye's public vulnerability research, including reports credited to its researchers in GitLab's advisory database, is a useful technical credibility signal but not a substitute for independently verified customer retention or deployment scale.
GitLab announced the acquisition on 20 March 2024 and said it would use Oxeye to accelerate its SAST roadmap and augment software-composition analysis and compliance capabilities. GitLab subsequently stated that Advanced SAST was powered by technology acquired from Oxeye and used a proprietary engine to identify exploitable vulnerabilities in first-party code. This is stronger commercialization evidence than an unverified standalone growth claim, but it also changes the diligence question: the relevant outcome is now adoption and performance inside GitLab rather than Oxeye's standalone revenue, headcount, or fundraising trajectory. Financial terms were not disclosed in GitLab's announcement; GitLab's SEC filing records the acquisition and consideration, but does not establish a standalone valuation suitable for this database.
The defense and national-security case is technically plausible but evidence-limited. Reachability-aware application security can help secure mission software, government services, and critical-infrastructure systems, where prioritizing exploitable weaknesses matters. However, public sources reviewed here do not establish defense contracts, military deployments, security clearances, or government-specific certifications for Oxeye. Its dual-use value should therefore be assessed as an adjacency of the underlying technology, not as proof of defense traction. Since GitLab owns the technology, strategic relevance is best understood as evidence that a major DevSecOps platform considered the capability important to its security roadmap, not as a current standalone strategic-screening signal.
Dual-Use Assessment
Oxeye's code-to-cloud risk analysis and exploitability prioritization have substantive commercial and security-sector applicability: the same methods can help teams assess mission software, government applications, and critical infrastructure. Public evidence reviewed does not establish defense customers, military deployment, clearances, or government certifications, so the dual-use case is technical adjacency rather than demonstrated defense traction.
Strategic Fit Assessment
Oxeye had a credible technical problem, a reported $5.3 million seed round, and an acquisition by GitLab that validates strategic value in application security. It is not, however, an independently actionable startup after the 2024 acquisition. Standalone diligence should not rely on the former Series A label, unverified revenue estimates, or assumed customer traction. The relevant follow-up is to evaluate how GitLab's Advanced SAST incorporates Oxeye technology, including detection quality, adoption, retention, and product differentiation, while recognizing that those metrics belong to GitLab's platform rather than to an available Oxeye security.
Strategic Value to U.S.-Israel Alliance
Oxeye is strategically relevant as an acquired application-security capability that helped GitLab extend security analysis from source code toward runtime-informed risk and more accurate SAST results. That supports software-supply-chain resilience and secure delivery for commercial, government, and potentially mission systems. The acquisition also demonstrates platform-level demand for exploitability prioritization. Its value to this database is therefore as a technology and acquisition reference for cyber strategy, not as a current independent company or financing candidate.
Key Technologies
- Cloud-native application security testing
- Static analysis for exploitable first-party vulnerabilities
- Runtime-context and code-to-cloud correlation
- Static reachability analysis for application dependencies
- Contextual vulnerability prioritization
- Software composition analysis enrichment
- DevSecOps and CI/CD security workflow integration
Use Cases & Applications
- Prioritizing exploitable vulnerabilities in first-party code
- Reducing false positives in enterprise SAST programs
- Correlating source-code findings with deployed cloud application context
- Triage of open-source dependency risk using reachability signals
- Security review of microservices and containerized applications
- Integrating application risk decisions into CI/CD workflows
- Assessing mission or critical-infrastructure software attack surface, where validated
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- about.gitlab.com Public source used for profile verification.
- SEC filing Public source used for profile verification.
- s204.q4cdn.com Public source used for profile verification.
- calcalistech.com Public source used for profile verification.
- advisories.gitlab.com Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.