Fundraising Fox

Boost Security

Founded 2020 · 28 employees on LinkedIn · 8 known investors

Find your way into Boost Security

469 people in our graph share verified history with the Boost Security team — schools, employers, funds. One of them is your warm intro.

Harley Finkelsteinunlockedknows Zaid Al Hamami · together at McGill University (overlapped)
×2knows the team · via MIT Sloan School of Management
×2knows the team · via University of California, Berkeley, Haas School of Business
knows the team · via Immunio
×2knows the team · via McGill University
×2knows the team · via Rensselaer Polytechnic Institute

BoostSecurity offers an Application Security Posture Management (ASPM) platform that consolidates SAST, SCA, secrets, and IaC scanning into one engine, connecting at the source-code-management level (GitHub/GitLab) rather than the CI/CD pipeline. It uses AI-driven reachability analysis to prioritize vulnerabilities and automatically generates fixes pushed to pull requests, targeting enterprise security teams governing AI-assisted software development.

Also known as Boost Security, Inc. · BoostSecurity · BoostSecurity Inc. · boostsecurity.io

Founders & leadership

Boost Security was founded in 2020 by Zaid Al Hamami and Rajiv Sinha.

ZAZaid Al Hamami
Zaid Al HamamiinCo-founderCo-founder of Boost Security, an application security platform that consolidates vulnerability scanning and automated remediation at the source-code-management level.
RSRajiv Sinha
Rajiv SinhainCo-founderRajiv Sinha is co-founder of BoostSecurity, an Application Security Posture Management platform. He previously led global sales at Acceptto (acquired by SecureAuth in 2021), Solebit (acquired by Mimecast in 2018), and Immunio (acquired by Trend Micro in 2017), and established the Pacific Rim practice at Cigital before its acquisition by Synopsys in 2016. He holds an MBA from UC Berkeley Haas and degrees in computer science from RPI and Stevens Tech.

Investors · 8

Also in the syndicate · 1

Sorensen Capital

Company profile

researched Aug 2026

Boost Security (legal name Boost Security, Inc.; also styled BoostSecurity) is a Montreal, Canada-based application security company that sells what it calls an AI-native software development lifecycle (SDLC) defense platform. The platform unifies three areas into a single engine: developer endpoint security (governing AI coding agents, sanitizing prompts, masking outbound credentials, and blocking malicious packages on the developer workstation), software supply chain security (AI bill-of-materials mapping, real-time typosquatting blocking, artifact provenance verification, and CI/CD pipeline hardening), and AI-native Application Security Posture Management (reachability-based triage with AI-generated, context-aware fixes delivered into pull requests).

The product documentation describes coverage of source code (SAST), open-source dependency vulnerabilities, container image configurations, stored secrets, infrastructure-as-code, and SBOM generation, orchestrated across integrations with source control management systems, CI/CD platforms, cloud infrastructure, web applications, and APIs. Deployment is positioned as SCM-native and "zero-touch," requiring no pipeline changes, with policy creation and compliance reporting for repositories, pipelines, and SBOMs. The company also runs a research arm, Boost Security Labs, which publishes supply chain and CI/CD threat research and maintains open-source tooling.

Founding story

Boost Security was founded in 2022 by Zaid Al Hamami (Co-Founder & CEO) and Rajiv Sinha (Co-Founder & CTO), who concluded that AppSec programs were slowing engineering down as security teams managed YAML configurations and chased theoretical vulnerabilities. Their stated goal was to make security operate at developer speed, initially by deploying through the source code management system so developers would not have to modify pipelines, and by using context to filter out alerts that did not matter.

Business model

B2B software vendor selling a SaaS security platform to enterprise engineering and security organizations; go-to-market includes demos and a "silent mode" evaluation that runs alongside incumbent tools. Pricing terms are not disclosed in the sources.

Traction

Company-published results cite 530 verified fixes in 14 days at Demandbase with critical MTTR reduced to under 48 hours, a 1:166 security-to-developer ratio at Travelport governing 6,000 repositories with a three-person team and 20+ hours a week reclaimed from manual triage, and a 700-repository rollout completed in about two hours at a global toy manufacturer. Its open-source portfolio reports 600+ GitHub stars, 50+ forks, 30+ contributors and 20 public repositories; the GitHub organization shows 510 stars on poutine, 375 on SmokedMeat, 194 on Bagel and 162 on LOTP.

Latest developments

In May 2026 Boost Security announced two acquisitions and $4 million in additional funding from White Star Capital, Amiral Ventures, Accelia Capital and Sorensen Capital, bringing total funding to $16 million. SecureIQx contributes an SCA reachability engine spanning more than a dozen languages, and Korbit.ai contributes code review and engineering-insights capabilities; the capital is earmarked for platform development and integrating both technologies. Boost Security Labs open-sourced SmokedMeat, a red team framework for build pipelines, in April 2026, and published research on GitHub Actions OIDC immutable subject claims, the Red Hat npm compromise and a LiteLLM/PyPI credential stealer.

Full profile — market position, technology, go-to-market, geography, history

Market position

Positions itself as the only platform unifying AppSec and software supply chain security with developer endpoint protection in one engine, contrasting its approach with vendors applying human-speed review gates to machine-generated code. Independent coverage frames it as an SDLC defense startup with $16 million raised in total as of May 2026.

SCM-native deployment that avoids pipeline changes and developer friction, zero-touch provisioning across large repository estates, reachability-based auto-triage to suppress non-material alerts, automated remediation pushed into pull requests rather than ticket creation, and coverage of the developer endpoint and AI agent layer in addition to code and dependencies.

Technology

Single execution engine spanning pre-commit to production. Components include developer-endpoint controls that enforce approved models, block hallucinated dependencies and mask credentials; continuous AI-BOM tracking of agents, IDE extensions and models touching the codebase; reachability analysis to separate exploitable from non-material findings; automated fix generation injected into pull requests; and pipeline integrity checks including artifact provenance verification and detection of "living off the pipeline" attacks. Open-source projects include poutine (Go-based build-pipeline supply chain scanner with Rego rules, SARIF output and MCP integration), Bagel (cross-platform CLI inventorying security-relevant metadata, credentials and misconfigurations on developer workstations), SmokedMeat (a CI/CD red team framework), LOTP (catalog of build-tool RCE-by-design features), and drop-in scanner plugins for GitHub Actions, GitLab CI, Azure DevOps, CircleCI and Buildkite. Acquired technology adds an SCA reachability engine covering more than a dozen programming languages and an automated code-review/engineering-insights capability.

Go-to-market

Sales-led enterprise motion supported by product-led evaluation (rapid SCM-based connection, silent-mode trials that run alongside existing tools) and by developer-community distribution through open-source tools such as poutine, Bagel, SmokedMeat, and the Living Off The Pipeline catalog. Boost Security Labs publishes vulnerability and supply chain research, and the team presents at industry events including Black Hat SecTOR 2026 Arsenal in Toronto (Oct 7-8, 2026). Published customer case studies (Mattel, Demandbase) are used as references.

Enterprise security and AppSec teams and high-velocity, DevOps-oriented engineering organizations, including large repository estates governed by small security teams. Named or referenced customers include Mattel (700+ repositories, solo security lead), Demandbase (B2B SaaS), Travelport (6,000 repositories, three-person team), and an unnamed Fortune 500 global toy manufacturer.

Geography

Headquartered in Montreal, Canada; serves enterprise customers internationally and acquired Montreal-based Korbit.ai and MIT-founded SecureIQx.

History

Founded in 2022 in Montreal. In 2023 the company shipped SCM-native deployment with context-based alert filtering and no pipeline changes. From 2024 it repositioned around AI coding agents entering the SDLC, and now describes itself as an AI-native SDLC defense platform covering the developer endpoint, supply chain ingestion and pre-commit code fixes. In May 2026 it announced the acquisitions of SecureIQx and Korbit.ai alongside $4 million in additional funding, bringing total capital raised to $16 million.

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
GitHub stars - BagelJan 2026194 stars
GitHub stars - LOTPJan 2026162 stars
GitHub stars - poutineJan 2026510 stars
GitHub stars - SmokedMeatJan 2026375 stars
GitHub stars across open-source projectsJan 2026600+
Open-source contributorsJan 202630+
Public GitHub repositoriesJan 202620 repositories
Repositories governed at TravelportJan 20266,000 repositories
Repositories onboarded at global toy manufacturer (Mattel)Jan 2026700 repositories
Security-to-developer ratio at TravelportJan 20261:166
Total funding raised to dateMay 2026$16M
Verified fixes at Demandbase in 14 daysJan 2026530 fixes

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Founder mafia

2 people who came through Boost Security went on to found or lead other companies.

Timeline · 4

launches, deals, and filings
May 2026
Boost Security acquires Korbit.ai

Boost Security acquired Korbit.ai, a Montreal-based code-review and engineering-insights startup that identifies security, performance and code flaws, adding SAST and code review capabilities.

source ↗

May 2026
Boost Security acquires SecureIQx

Boost Security acquired SecureIQx, an MIT-founded startup that built a Software Composition Analysis reachability engine analyzing code across more than a dozen programming languages, to add advanced reachability analysis to its platform.

source ↗

May 2026
$4 million additional funding announced

Boost Security announced $4 million in additional funding from White Star Capital, Amiral Ventures, Accelia Capital and Sorensen Capital, bringing total raised to $16 million; proceeds fund platform development and integration of the SecureIQx and Korbit.ai technologies.

$4M source ↗

Apr 2026
Boost Security Labs open-sources SmokedMeat CI/CD red team framework

Boost Security Labs released SmokedMeat, described as the first red team framework for build pipelines, along with the Whooli CTF environment for exercising CI/CD attack chains.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Boost Security do?
Montreal-based Boost Security sells an AI-native SDLC defense platform spanning developer endpoints, supply chain, and ASPM.
Who founded Boost Security?
Boost Security was founded by Zaid Al Hamami, Rajiv Sinha in 2020.
Who are Boost Security's investors?
Boost Security's investors include Golden Ventures, Hoxton Ventures, Transform Capital Management, Accelia Capital, Amiral Ventures, Security Leadership Capital, White Star Capital.