Phylum
Last updated: Jul 31, 2026
Phylum developed software supply-chain security technology that analyzes open-source packages, detects malicious behavior, and enforces package-admission policy. Veracode acquired certain Phylum assets and technology in January 2025; current Phylum documentation identifies the platform as part of Veracode, so this record represents an acquired capability rather than an independent startup.
Visit WebsiteCompany Overview
Phylum developed an automated software-supply-chain security platform focused on risks that conventional vulnerability lists can miss. Its product analyzed open-source packages as they were published, ingested packages, lockfiles, and software bills of materials, and combined package behavior, authorship, provenance, licensing, engineering, and vulnerability context into policy decisions. The important distinction was malicious-package detection: a package can be newly published, deliberately weaponized, or suspicious without already appearing in a conventional CVE database. Phylum also offered a package firewall, CLI-based pre-install checks, installation sandboxing for supported ecosystems, and a threat feed for security workflows.
The customer problem is structurally significant. Modern applications depend on large and fast-changing npm, PyPI, Maven, and other package ecosystems, creating opportunities for typosquatting, dependency confusion, compromised maintainers, malicious install scripts, credential theft, and targeted malware campaigns. A useful product must inspect new packages quickly, distinguish malicious intent from ordinary engineering risk, and integrate with CI/CD and developer workflows without turning every dependency update into a manual security review. Phylum's historical positioning covered package blocking, risk prioritization, governance, compliance, vendor assessment, and third-party software review, which gives the capability relevance beyond a narrow scanner.
The competitive environment is crowded and increasingly platform-oriented. Snyk, Mend, Sonatype, JFrog, GitHub, Socket, and Checkmarx address overlapping combinations of software composition analysis, package reputation, malware detection, repository controls, and developer remediation. Phylum's credible differentiation was its dedicated focus on package behavior and emerging malicious activity rather than treating known vulnerabilities as the entire problem. That edge depends on research quality, corpus coverage, low-latency analysis, useful explanations, and high-confidence policy decisions. Veracode currently markets the inherited research and data through its Software Supply Chain Intelligence offering, but claims such as detecting more malicious packages than competitors remain vendor claims requiring independent benchmarking; public evidence does not establish standalone Phylum market share or customer concentration.
The commercialization picture must now be read through the transaction. Veracode announced on January 6, 2025 that it acquired certain Phylum assets, including malicious-package analysis, detection, and mitigation technology, and described plans to integrate the capability into its software-supply-chain security offering. Current Phylum documentation says the service is part of Veracode and that the documentation is for a legacy platform; Veracode's current datasheet describes the Threat Research team as formerly the Phylum Research Team. This is meaningful evidence that the capability remains commercially relevant inside Veracode, but it is not evidence that Phylum remains an independent operating company, that historical standalone revenue persisted, or that the acquisition price created venture-return potential.
The defense and national-security relevance is substantive but indirect. Defense contractors, government software factories, critical-infrastructure operators, and intelligence systems all rely on third-party code and build pipelines where a malicious dependency can create a route to credential theft, data exfiltration, or compromise of mission software. Package admission controls, behavioral analysis, SBOM context, sandboxing, and threat feeds can therefore contribute to secure software development and supply-chain assurance. The record should not imply a confirmed defense customer, government contract, accreditation, or operational deployment: the public evidence supports an applicable cybersecurity capability, not a documented defense program. As an acquired asset, its strategic value is best assessed through Veracode's integration, research continuity, coverage, independent efficacy, and customer adoption rather than through an independent startup financing thesis.
Dual-Use Assessment
Phylum's core capability addresses malicious open-source code and software supply-chain risk, a direct commercial security problem with credible applicability to defense contractors, government software factories, critical infrastructure, and other sensitive development environments. The adjacency is in protecting trusted software production, not in a confirmed weapons or government deployment.
Strategic Fit Assessment
The technology addresses a consequential and growing security problem and appears strategically valuable enough for Veracode to acquire selected assets. However, the transaction means Phylum is no longer an independent startup opportunity in this database; there is no basis here for a standalone financing, ownership, valuation, or investment recommendation. Diligence should instead track how fully Veracode integrates the capability, preserves research velocity, and converts detection quality into customer adoption.
Strategic Value to U.S.-Israel Alliance
Phylum's strategic value is as a high-signal control layer for deciding which third-party code is safe to admit into software-production environments. Its package analysis, threat research, and policy-enforcement concepts can strengthen Veracode's broader application-risk platform and can help sensitive organizations reduce dependency-based compromise. The value is credible but now resides primarily in an acquired technology and research capability; the key unknowns are integration depth, ongoing coverage, independent efficacy, and customer outcomes.
Key Technologies
- Static, heuristic, and machine-assisted analysis of open-source packages
- Malicious-package and zero-day supply-chain threat detection
- Package-management firewall and automated package blocking
- Dependency, lockfile, and SBOM risk contextualization
- Package authorship, provenance, and reputation analysis
- Real-time software-supply-chain malware and reputation intelligence feeds
- Installation sandboxing and pre-install package checks
Use Cases & Applications
- Block malicious npm, PyPI, Maven, and similar packages before installation
- Detect typosquatting, dependency confusion, and malicious post-install behavior
- Prioritize risky direct and transitive dependencies using package context
- Assess third-party software and open-source components during procurement or M&A
- Enforce package admission and governance policy in enterprise CI/CD pipelines
- Protect defense-contractor and government software factories from dependency compromise
- Feed package-threat intelligence into security analytics and observability systems
- Provide malware and reputation signals to SOC, threat-hunting, and software-assurance workflows
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- veracode.com Public source used for profile verification.
- veracode.com Public source used for profile verification.
- docs.phylum.io Public source used for profile verification.
- docs.phylum.io Public source used for profile verification.
- Company announcement Public source used for profile verification.
- veracode.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Acquired asset
Why it may matter
Phylum may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify technical claims
- Verify regulatory/export-control issues
Main investor questions
- Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
- What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Phylum's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.