Fundraising Fox

ShiftLeft

Santa Clara, US Β· Founded 2016 Β· Delaware corporation Β· 4 known investors

shiftleft.io β†—

Application security company, now branded Qwiet AI by Harness, offering code analysis that prioritizes reachable, exploitable vulnerabilities.

Also known as Qwiet AI Β· Qwiet AI by Harness Β· Shiftleft Inc Β· ShiftLeft Inc.

Founders & leadership

ShiftLeft was founded in 2016 by Chetan Conikee Sathyanarayana and Manish Gupta.

CC
Chetan Conikee SathyanarayanaCo-founder
MG
Manish GuptaCo-founder
UP
Urshit ParikhNamed on SEC filing

Board

UP
Umesh PadvalBoard director
ESEnrique Salem
Enrique Salemin𝕏Board directorPartner at Bain Capital Ventures

Investors Β· 4

Also in the syndicate Β· 2

Blackstone Innovations InvestmentsleadMayfield

Reported raises Β· per SEC filings

Form D private placements

$15.2M disclosed across 1 of 4 rounds Β· 2017–2021

β–Ά$15.2MraisedNov 2018 Β· 5 investors Β· Other Technology
Rule 506(b)
Officers, directors & promoters on the filing
  • Chetan Conikee SathyanarayanaExecutive Officer, Director
  • Urshit ParikhDirector
  • Manish GuptaExecutive Officer, Director
  • Umesh PadvalDirector
  • Enrique SalemDirector
Offering amount
$20M
Amount sold
$15.2M
First sale
Oct 2018
Incorporated
Corporation, Delaware, 2016
Federal exemptions
06b
Full filing on SEC EDGAR β†—

Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.

Company profile

researched Aug 2026

ShiftLeft, Inc. is a Santa Clara, California-based application security company founded in 2016 and publicly launched in October 2017. Its platform combines static code analysis with application instrumentation to identify vulnerabilities and protect running applications, an approach the company described as "code-informed runtime protection" and "runtime-informed code analysis." The core technology is a Code Property Graph that maps abstract syntax trees, control flow graphs, call graphs, program dependency graphs and directory structures to build a model of an application, which is then used to detect vulnerabilities in context and to configure lightweight "microagents" that block or alert on activity targeting the specific weaknesses present in each application version. The company also shipped Ocular, a product built around a CPG Query Language (CPGQL).

The product is now marketed as Qwiet AI by Harness and is presented on shiftleft.io as part of the Harness platform. It consolidates SAST, software composition analysis, infrastructure-as-code, container and secrets scanning into a single scan, uses reachability and exploitability filters to prioritize findings, and adds AI agents that generate unit-tested code fixes ("AI Autofix"). Documented platform capabilities include support for Java, Scala, Python 3.10+, Go 1.21, C#/ASP.NET Core and PHP (beta); SBOM generation and export in CycloneDX and SPDX formats with OSS licensing data and exploitable-CVE counts; CWE reports exportable as PDF or HTML; build rules including license checks; trend and comparison reporting; personal access tokens; and integrations with Jira, GitHub pull requests, Azure DevOps Pipelines, AWS CodeBuild and CI/CD pipelines generally.

Founding story

The company was founded in 2016; Manish Gupta served as CEO and co-founder and Chetan Conikee as CTO. Gupta described the founding vision as making application security a seamless part of the development process rather than an afterthought, arguing that existing tools were inaccurate and heavily manual.

Business model

Software platform sold to enterprises, with a free tier, a 15-day premium trial permitting scanning of up to 10 applications concurrently, and team/enterprise subscriptions that unlock reporting, API access and enterprise-level support.

Tiered subscription software (free tier, premium trial, team/enterprise subscriptions with enterprise support).

Traction

Customers cited in 2019 coverage include Nutanix (Nutanix Epoch), Raytheon and Tavant. The company raised roughly $58 million in total across rounds through 2021 and reported plans to hire aggressively across departments. Product documentation shows a continuous release cadence from 2020 through at least December 2023.

Latest developments

The shiftleft.io site (Β© 2025) presents the product as Qwiet AI by Harness, part of the Harness platform, centered on a single consolidated scan, reachability/exploitability prioritization and AI agents that produce production-ready, unit-tested fixes in about five minutes. Documentation for 2023 records general availability of Python 3.10+ support, a new Qwiet AI by Harness dashboard with a sankey findings chart, PHP exclusions, Go 1.21 support, auto-language detection, SBOM exports with exploitable CVE counts, an ARM64 Docker image, and migration of all users to the new UI.

β–ΈFull profile β€” market position, technology, go-to-market, geography, history

Market position

Positioned as an application security testing vendor differentiating on accuracy and speed against traditional SAST/DAST tooling. In September 2018 the company reported a 100% true positive rate with 25% false positives on the OWASP Benchmark for Security Automation v1.2, which it said beat the commercial average by 45%. It was named a winner of the 2020 SINET 16 Innovator Award.

Emphasizes low false-positive rates and prioritization by reachability and exploitability rather than raw vulnerability counts, consolidation of SAST, SCA, IaC, container and secrets scanning into a single scan, and AI-generated, unit-tested fixes rather than findings alone. Marketing claims include a 97% true positive rate, 90% fewer false positives, 10x faster scans and a 95% reduction in remediation time.

Technology

The platform is built on a Code Property Graph that unifies abstract syntax trees, control flow graphs, call graphs, program dependency graphs and directory structures to reason about application context and detect complex, multi-component vulnerabilities. That analysis drives code-informed microagents deployed with each software release, which are described as having minimal latency, memory and CPU impact because they know precisely which parts of an application are vulnerable. Ocular exposes the graph through a CPG Query Language. The current Qwiet AI product adds reachability and exploitability filtering, EPSS scoring, secrets detection with field-level tracking, SBOM generation (CycloneDX, SPDX), CWE reporting, and AI agents that produce verified, unit-tested code fixes.

Go-to-market

Sold through direct enterprise sales and marketing; the 2019 Series B funded expansion of global sales and marketing, including the hire of a vice president of worldwide sales, and the company assembled an external advisory board of security and engineering leaders. Adoption is developer-led in practice via CI/CD pipeline and IDE integrations, a free tier and self-service trials, with demo requests on the website.

Enterprise application security, DevSecOps and development teams. Named customers include Nutanix, Raytheon and Tavant; website testimonials reference healthcare and biotech, retail, finance and services companies with revenues from $50M to over $10B, and the site references Fortune 500 AppSec programs.

Geography

Headquartered in Santa Clara, California, United States, with stated global sales and marketing expansion following the 2019 Series B.

History

Founded in 2016 in Santa Clara, California, ShiftLeft launched publicly in October 2017 after a first funding round of $9.3 million. A $20 million Series B led by Thomvest Ventures closed in February 2019, bringing total funding to nearly $30 million, alongside the hire of a VP of worldwide sales and the formation of an advisory board. In 2020 the company expanded dashboard reporting, GitHub and Jira integrations, and Ocular, and won the SINET 16 Innovator Award. It later raised $29 million in expansion capital led by Blackstone Innovations Investments and SYN Ventures, taking total funding above $58 million. The product was subsequently rebranded Qwiet AI and, per the current website and documentation, is offered as Qwiet AI by Harness.

Compiled by commissioned research from 8 cited public sources β€” announcements, filings, and press listed under research sources below.

Key figures

latest reported
OWASP Benchmark v1.2 false positive rateSep 201825%
OWASP Benchmark v1.2 true positive rateSep 2018100%
Reduction in false positives (company-claimed)Jan 202590%
Reduction in remediation time (company-claimed)Jan 202595%
Scan speed improvement (company-claimed)Jan 202510 x
Total funding raisedJan 2021$58M
True positive rate (company-claimed)Jan 202597%

Company-reported or press-reported figures, each dated to when it was claimed β€” not independently audited.

Competitors Β· 10

by search overlap
Snyk57 shared keywordsSnyk is a developer-focused security platform that identifies and fixes vulnerabilities in code, dependencies, containers, and cloud infrastructure using AI-powered analysis. The company serves organizations of all sizes looking to integrate security into their software development process.
Legit Security37 shared keywordsLegit Security provides an application security platform that helps organizations identify and manage software vulnerabilities and risks across their development environments. The platform serves enterprise security teams seeking to reduce alert fatigue and improve visibility into their application attack surface.
Wiz34 shared keywordsWiz provides cloud security platform that identifies and removes critical risks across multi-cloud environments. The company offers a unified security layer for organizations to manage risks and accelerate business operations on major cloud providers.
Cycode33 shared keywordsCycode provides an application security and product security platform focused on securing the software development lifecycle, including risks from AI-generated code and shadow AI. The company serves CISOs and security teams, offering research and tooling for AppSec and code security.
Imperva Impv32 shared keywordsImperva provides cybersecurity solutions to protect customers from cyberattacks across applications, data, and identities during digital transformation. The company serves enterprise customers including major financial institutions, telecom providers, and Fortune 100 companies.
Crowdstrike30 shared keywordsCrowdStrike provides an AI-native cybersecurity platform that unifies endpoint, identity, cloud, SaaS, and AI protection to detect and stop breaches for enterprise organizations. It combines automated response with human-led security operations including managed detection and response, threat hunting, and security services.
F529 shared keywordsF5 develops application delivery and security software and hardware platforms, including BIG-IP load balancers and application firewalls, for enterprise and government networks. The company serves organizations requiring network traffic management, cybersecurity, and application access control.
Splunk29 shared keywordsSplunk offers a unified platform for security and observability that ingests and analyzes large-scale data across hybrid cloud environments. Its tools support security operations centers with analytics and automated response, and help teams monitor application and infrastructure performance.
StackHawk28 shared keywordsStackHawk provides an API security tool designed for software development teams to identify and fix security vulnerabilities in real-time as part of their development workflow. The platform targets developers and modern software teams seeking to integrate security checks into continuous integration and deployment practices.
Codacy28 shared keywordsCodacy provides a platform for code quality, security, and AI coding policy enforcement, letting engineering teams define coding standards and apply them across projects, IDEs, and AI coding agents. It offers automated pull request reviews, SAST, secret scanning, dependency/CVE scanning, AI guardrails, and audit-ready reports for compliance frameworks like SOC2 and ISO27001.

Companies competing with ShiftLeft for the same Google search keywords, organic and paid, via search-intersection analysis.

Non-dilutive funding Β· 1 SBIR/STTR award

Federal grants β€” no equity taken
AgencyPhaseYearAmount
U.S. Air ForceAir ForcePhase I2020$50K

Source: SBIR.gov award data (U.S. Small Business Administration). SBIR/STTR awards are competitive federal R&D grants and contracts β€” non-dilutive capital alongside any venture rounds above.

Timeline Β· 11

launches, deals, and filings
Dec 2023
General availability of Python 3.10+ support

Support for applications written in Python 3.10 or later became generally available via the --pythonsrc flag; OSS findings on the applications list page gained a severity breakdown.

source β†—

Sep 2023
New UI becomes generally available

The updated UI became generally available and all users were migrated; the classic UI was retired. Also added Go 1.21 analysis, SBOM exports with exploitable CVE counts and an ARM64-compatible Docker image.

source β†—

Jun 2023
Beta support for PHP and OSS licensing checks

Beta support for PHP applications, detailed OSS licensing information in generated SBOMs, license-based build rules, and EPSS score and exploitability status filters.

source β†—

Jan 2021
ShiftLeft raises $29 million in expansion capital

Round led by Blackstone Innovations Investments and SYN Ventures with participation from previous investors, bringing total raised to over $58 million; proceeds earmarked for hiring, sales and marketing, and cloud-native product development.

$29M source β†—

Nov 2020
Reporting features and premium trial launched

Reporting added to the dashboard for premium trial and team/enterprise subscribers, plus a 15-day premium trial allowing scanning of up to 10 apps with API and reporting access.

source β†—

Sep 2020
Named a winner of the 2020 SINET 16 Innovator Award

source β†—

Sep 2020
Ocular 0.4.1 released with rearchitected CPG Query Language

Ocular release 0.4.1 introduced a major rearchitecture of the CPG Query Language (CPGQL), requiring a user migration.

source β†—

Feb 2019
ShiftLeft raises $20 million Series B

Series B led by Thomvest Ventures with new investor SineWave Ventures and existing investors Bain Capital Ventures and Mayfield, bringing total funding to nearly $30 million. Funds earmarked for product portfolio breadth, application coverage and global sales and marketing.

$20M source β†—

Feb 2019
Jim Sortino joins as vice president of worldwide sales

Sortino, previously in executive roles at Trend Micro and Dome9 Security (acquired by Checkpoint), was named VP of worldwide sales.

source β†—

Feb 2019
Advisory board formed

Advisory board announced with Bob Flores (former CTO, CIA), Craig Rosen (CISO, AppDynamics), Shahar Ben Hador (CIO, Exabeam), Aaron McKeown (Xero), Manish Arya (Tavant) and Yonatan Ryabinski (Vanguard).

source β†—

Oct 2017
ShiftLeft launches publicly

ShiftLeft launched in October 2017, a year before its OWASP Benchmark results were published.

source β†—

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

Legal entities Β· 1

corporate structure
ShiftLeftDelaware

β–ΈResearch sources Β· 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does ShiftLeft do?
Application security company, now branded Qwiet AI by Harness, offering code analysis that prioritizes reachable, exploitable vulnerabilities.
Who founded ShiftLeft?
ShiftLeft was founded by Chetan Conikee Sathyanarayana, Manish Gupta in 2016.
Who are ShiftLeft's investors?
ShiftLeft's investors include Bain Capital Ventures, Wipro Ventures.
How much funding has ShiftLeft raised?
ShiftLeft has disclosed $15.2M raised across 1 of its 4 known rounds.
Where is ShiftLeft headquartered?
ShiftLeft is headquartered in Santa Clara, US.