DryRun Security
Austin, US · Founded 2022 · Delaware corporation · 17 employees on LinkedIn · 4 known investors
DryRun Security offers an AI-native code security platform that builds a contextual model of a codebase to detect exploitable vulnerabilities, guide remediation, and enforce security policies across human- and AI-generated code. It serves engineering and application security teams, integrating with tools like GitHub, GitLab, and Slack to surface findings within pull request workflows.
Also known as DryRun · DryRun Security Co.
Founders & leadership
DryRun Security was founded in 2022 by James Hagan Wickett, Ken Johnson, and James Wickett.



Board

Investors · 4
Reported raises · per SEC filings
Form D private placements$8.5M disclosed across 2 of 3 rounds · 2023–2025
▶$6.2MraisedFeb 2025 · 4 investors · Other TechnologyRule 506(b)
- Creighton HicksDirector
- Kelley MakDirector
- Kenny JohnsonDirector
- James Hagan WickettExecutive Officer, Director
- Offering amount
- $6.2M
- Amount sold
- $6.2M
- First sale
- Sep 2024
- Incorporated
- Corporation, Delaware, 2022
- Federal exemptions
- 06b
▶$2.3MraisedJan 2023 · 2 investors · Other TechnologyRule 506(b)
- Kenny JohnsonDirector
- Kelley MakDirector
- James Hagan WickettExecutive Officer, Director
- Offering amount
- $2.5M
- Amount sold
- $2.3M
- First sale
- Jan 2023
- Incorporated
- Corporation, Delaware, 2022
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Company profile
researched Aug 2026DryRun Security operates an AI-native application security platform that reviews pull requests and performs full-repository scans to identify vulnerabilities in both human-written and AI-generated code. The product is built around a proprietary Contextual Security Analysis (CSA) engine that layers static context, change context and application context, mapping architecture, code relationships, Git behavior, frameworks, routes, authorization boundaries and data flow into a continuously updated knowledge graph. Specialized agents then trace how input, logic, permissions and data move through an application, assign confidence scores based on exploitability and impact, and guide remediation for developers and their AI coding agents. The company states three patents have been awarded covering the identification of high-risk code paths.
Platform capabilities include AI-native SAST, PR code review with contextual findings and change summaries, the DeepScan Agent for on-demand full-codebase baseline scanning, secrets scanning, infrastructure-as-code scanning of Terraform, software composition analysis for known CVEs and license issues, AI-generated remediation, PR blocking against severity or policy thresholds, finding tuning and triage tracking, developer activity and risk trend reporting, and Natural Language Code Policies, which let teams write organization-specific rules in plain language for automatic enforcement on every code change. A Code Security Intelligence layer aggregates finding data to surface vulnerability trends, architecture risks, developer patterns, shadow AI usage and incident investigation.
DryRun Security integrates with source control and developer tooling including GitHub, GitLab and Slack, and exposes data to AI coding assistants through the Model Context Protocol, a DryRun Skill, webhooks and an API; supported assistants cited include Claude Code, Claude Desktop, Codex and Cursor. Supported languages include Python, JavaScript, TypeScript, Java, C#, Ruby and Go.
Founding story
Co-founder and CEO James Wickett started the company on the premise that developers care about security and quality but the security industry was not providing tools suited to them. Co-founder and CTO Ken Johnson joined from GitHub, where he led internal security code reviews and trained developers. Wickett is also a co-founder of DevOpsDays Austin. Press coverage of the seed round describes the company as founded in 2023.
Business model
DryRun Security sells a software platform to enterprise engineering and security organizations, installed into source-control workflows such as GitHub and GitLab, with documentation covering administration, notification channels, API and MCP integration for customer teams.
Traction
The company reports being trusted with more than 500,000 code reviews per week. Public customer references include Tines, Commerce and PlanetArt, whose CTO described catching issues such as hardcoded credentials early across a global development team. Disclosed funding totals $8.7 million in seed capital raised in January 2025, and the company says three patents have been awarded.
Latest developments
In early February 2026 the company introduced the DeepScan Agent for rapid, full-codebase security analysis, and in mid-February 2026 it announced the appointment of Andrew Peterson to its board of directors. Company researchers were also credited in February 2026 press coverage of a Firebase misconfiguration that exposed roughly 300 million user messages from an AI chat application.
▸Full profile — market position, technology, go-to-market, geography, history
Market position
DryRun Security describes itself as the first AI-native, agentic code security intelligence solution and competes in the static application security testing and code review market against pattern-based and query-based scanners. Third-party recognition includes Black Hat Startup Spotlight finalist status, an OWASP Global DC innovation award, inclusion in the Boundary Breaker category of Latio Tech's Cloud & Application Security List, and Austin Inno's Startups to Watch list.
The company positions its Contextual Security Analysis engine as going beyond regex and pattern libraries used by traditional SAST, reasoning about code intent, exploitability and impact rather than the presence of a pattern, and eliminating the need to author and maintain custom rules. Company-published comparisons against Snyk Code, GitHub Advanced Security (CodeQL), Semgrep and SonarQube claim broader detection of non-pattern issues such as SSRF, IDOR, broken access control, authentication logic flaws and user enumeration, near real-time pull request feedback, a false-positive rate under 5% and logic-flaw detection above 90%. Site claims include being twice as accurate as alternatives in pull request and repository review and reducing noise by 90%.
Technology
The core technology is the Contextual Security Analysis engine, which builds a living model of a codebase across architecture, authorization boundaries, data flow and behavioral history in a continuously updated knowledge graph, then applies specialized agents and multiple models to analyze code intent and behavior, validate exploitability with confidence scoring, and generate remediation guidance. It inspects data flow across files and services, detects injection, authentication, IDOR and business logic issues, and is backed by continuous evaluations of accuracy and performance. Adjacent capabilities cover secrets detection, Terraform IaC misconfiguration checks, dependency CVE and license analysis, and natural-language policy enforcement, with delivery through pull request comments, an API, webhooks and MCP.
Go-to-market
Distribution is developer- and AppSec-workflow led, through native integration with GitHub, GitLab and Slack, free security assessments and self-serve getting-started paths, supported by published benchmark research, founder-led webinars and office hours, conference and podcast appearances, security industry competitions, and trade press coverage. Proceeds from the 2025 seed round were earmarked for engineering hiring and expansion of the go-to-market function.
Application security engineers, developers and platform administrators at engineering-led organizations; named or quoted users include Tines, Commerce and PlanetArt.
Geography
Headquartered in Austin, Texas, where it was recognized on a local startups-to-watch list; one referenced customer describes using the platform across a global development team.
History
The company was launched by technology veterans James Wickett and Ken Johnson and emerged from stealth around December 2023, when Wickett publicly described its approach to development security. It was a finalist in the Black Hat Startup Spotlight competition in 2024 and received the Most Innovative Startup award at OWASP Global DC 2023. In January 2025 it closed an $8.7 million seed round and launched Natural Language Code Policies. In 2025 it was named to the Austin Inno Startups to Watch list, and in early 2026 it introduced the DeepScan Agent and appointed Andrew Peterson to its board of directors.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 10
by search overlapCompanies competing with DryRun Security for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline · 9
launches, deals, and filingsPress coverage reports DryRun Security appointing Andrew Peterson to its board of directors to drive its AI shift.
Agent for rapid, full-codebase security scanning, covered by trade press including VM Blog, Global Security Magazine, DevOps Digest and IT Brief.
Seed funding to be used to increase engineering hires and grow the go-to-market function.
$8.7M source ↗
Feature set allowing development and security teams to define and enforce application security policies in plain, conversational language instead of custom scripted rules, announced alongside the seed round.
Named one of four finalists in the Black Hat Startup Spotlight 2024 competition.
Techstrong interview with CEO and co-founder James Wickett discussing the company's recent emergence from stealth and its approach to development security.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
Legal entities · 1
corporate structureIn the news
▸Research sources · 8
primary sources listed
- DryRun Securitydryrun.security · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does DryRun Security do?
- DryRun Security is an AI-native code security platform that reviews pull requests and repositories for exploitable risk.
- Who founded DryRun Security?
- DryRun Security was founded by James Hagan Wickett, Ken Johnson, James Wickett in 2022.
- Who are DryRun Security's investors?
- DryRun Security's investors include Work-Bench, Cannage Capital, LiveOak Venture Partners, LiveOak Ventures.
- How much funding has DryRun Security raised?
- DryRun Security has disclosed $8.5M raised across 2 of its 3 known rounds.
- Where is DryRun Security headquartered?
- DryRun Security is headquartered in Austin, US.







