Snyk

Developer-first cybersecurity company building a platform for finding and fixing vulnerabilities in open-source dependencies, containers, infrastructure-as-code, and source code.
Snyk is a developer-first cybersecurity company building a platform for finding and fixing security vulnerabilities in open-source dependencies, container images, infrastructure-as-code templates, and source code. Dual-headquartered in Boston, Massachusetts and London, with substantial engineering and research operations in Tel Aviv. Last valued at approximately $7.4 billion in the December 2022 down round; annual recurring revenue crossed $300 million in 2024; total funding raised exceeds $1.4 billion. The Israeli-founded application-security platform that became the reference case for the developer-first security category — and the reference case for how AI-native coding tools have restructured the DevSecOps thesis in 2025 and 2026.
Company Snapshot
- Legal entity: Snyk Limited
- Founded: 2015
- Co-founders: Guy Podjarny (Israeli, ex-CTO Akamai Web Experience), Assaf Hefetz (Israeli, ex-IDF Unit 8200), Danny Grander (Israeli, ex-Gita Technologies)
- Headquarters: Boston, MA and London (dual)
- Principal engineering site: Tel Aviv
- Current CEO: Peter McKay (appointed 2019, taking over from Podjarny)
- Chairman & Founder: Guy Podjarny
- Last valuation: ~$7.4 billion (December 2022 Series G-1 down round from prior $8.5B)
- Peak valuation: $8.5 billion (September 2021, Series F)
- Total funding raised: $1.4+ billion across nine rounds
- Reported ARR: Crossed $300 million in 2024; management targeting $500M+ trajectory
- Employees: ~1,300 (down from ~1,500+ peak after 2023 restructuring)
- Sector: Application security, DevSecOps, developer-first cybersecurity
- Category peers: Checkmarx, Veracode, GitLab, Semgrep, Aqua Security, Palo Alto Networks Prisma Cloud, Wiz
What Snyk Does
Snyk sells a platform that scans code, dependencies, container images, and infrastructure-as-code for security vulnerabilities and provides automated fix guidance. The product suite runs across four principal modules:
- Snyk Open Source — the founding product. Scans open-source dependencies in application code for known vulnerabilities (CVEs) and license-compliance issues. Integrates directly into developer IDEs, source-code management (GitHub, GitLab, Bitbucket), and CI/CD pipelines. This is the module that established the category.
- Snyk Code — static application security testing (SAST). Scans first-party source code for security vulnerabilities including SQL injection, cross-site scripting, and insecure cryptographic patterns. Built on the technology acquired through the DeepCode acquisition in September 2020.
- Snyk Container — container image scanning. Identifies vulnerabilities in container base images and application layers running in Docker, Kubernetes, and adjacent container infrastructure.
- Snyk IaC — infrastructure-as-code scanning. Identifies security misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and adjacent IaC templates before deployment.
The unifying commercial thesis is developer-first security: the security decision that matters happens at the point of code commit, not the point of network perimeter. Snyk's go-to-market motion is anchored in freemium developer adoption — individual engineers install Snyk into their IDE for free — converting into enterprise contracts as security and engineering leadership standardize on the platform.
Founding and the Israeli Cyber Cohort
Snyk was founded in 2015 by three Israeli technologists. Guy Podjarny served as CTO of Akamai's Web Experience Business Unit before founding Snyk; he had previously co-founded Blaze.io, which Akamai acquired in 2012. Assaf Hefetz and Danny Grander came from the Israeli cyber-technical layer — Hefetz from IDF Unit 8200 and adjacent Israeli cyber-industry roles, Grander from Gita Technologies and a broader Israeli offensive-security background.
The founders' core insight was that the security problem had shifted from network perimeter and endpoint into the codebase and CI/CD pipeline. As application development moved to continuous deployment, containerized infrastructure, and heavy reliance on open-source dependencies, the consequential security decisions moved to the developers writing and deploying code — not to the security engineers running perimeter tools. The available tooling at the time did not meet developers in the workflows where those decisions were being made.
Snyk built the tooling that did. The freemium developer-adoption motion, the IDE and CI/CD integration surface, and the emphasis on fix guidance over vulnerability reporting were the operating features that distinguished Snyk from the legacy application-security cohort (Checkmarx, Veracode, Fortify) and established it as the reference case for the developer-first security category.
Funding History
Snyk has raised more than $1.4 billion across nine rounds since founding.
- Seed (2015–2016): Boldstart Ventures, Heavybit Industries — early Israeli-cyber and developer-tools specialist funds
- Series A ($7M, 2017): Accel led
- Series B ($22M, 2018): Accel, GV (Google Ventures)
- Series C ($70M, 2019): Accel, GV, Boldstart
- Series D ($150M, January 2020): Stripes led at $1B+ valuation — Snyk's first unicorn round
- Series E ($200M, September 2020): Addition led at $2.6B valuation
- Series F ($300M, September 2021): Sands Capital, Tiger Global led at $8.5B valuation — the peak
- Series G ($196M, December 2022): Qatar Investment Authority led at $7.4B valuation — a down round of roughly 13 percent from the 2021 peak, executed during the broader tech-financing reset of 2022
- Additional rounds (2023–2024): Additional strategic and debt-and-equity financings to extend runway through the private-market cycle
Named investors across the cap table include Accel, Tiger Global, Sands Capital, Stripes, Addition, Qatar Investment Authority, Boldstart, GV, Salesforce Ventures, Atlassian Ventures, Amity Ventures, BOND, and Coatue. The consortium is a reference example of the growth-stage developer-tools capital pool that assembled during the 2020–2021 SaaS peak.
The 2022–2024 Reset
Snyk's trajectory through the 2022–2024 private-market cycle is the reference case for how the developer-first security category repriced through the tech-financing reset. The December 2022 Series G-1 round at $7.4 billion — down from the $8.5 billion September 2021 peak — was one of the more publicized down rounds of the 2022 cycle. The valuation compression came against continued revenue growth: ARR crossed $200 million in 2022 and $300 million in 2024, per management-reported figures.
In April 2023, Snyk executed a workforce reduction of approximately 14 percent — the second layoff round after an earlier smaller reduction in October 2022 — bringing headcount from a peak north of 1,500 back toward the current ~1,300 range. Additional adjustments continued through 2024 and 2025 as the company optimized go-to-market against the new capital-efficiency benchmark for late-stage private cybersecurity companies.
The postponed IPO remains the operative question. Snyk was widely expected to reach the public markets in 2022 before the market window closed; through 2024 and 2025 the company continued to signal readiness while waiting for the SaaS IPO window to reopen. The 2026 window has been more forgiving; whether Snyk uses it is one of the most-watched questions in the Israeli-rooted cybersecurity IPO pipeline.
Customers and Commercial Position
Snyk's customer base has grown to include a substantial share of the Fortune 500 and a comparable share of the largest publicly traded technology companies. Named customers include Google, Salesforce, Twilio, New Relic, Nasdaq, Asurion, Skyscanner, and the Washington Post. Financial-services and regulated-industry customers include multiple tier-one banks and insurance carriers.
The strategic partnership footprint is distinctive. Snyk operates deep integration partnerships with the major CI/CD and developer-tooling platforms — GitHub, GitLab, Bitbucket, Docker, HashiCorp, ServiceNow, Atlassian, IBM, and AWS. Salesforce is both a customer and a strategic investor. The partnership surface is the operational reason Snyk has been able to scale enterprise adoption despite competing directly with GitLab, GitHub Advanced Security, and adjacent platform-native security products.
Acquisitions
Snyk has been an active acquirer, using M&A to extend the platform surface across the four product modules:
- DeepCode (September 2020) — Zurich-based ML-powered code analysis; became the foundation of Snyk Code. Deal value not disclosed, reported in the $100M+ range.
- Manifold (November 2020) — developer-tools infrastructure acquisition.
- FossID (May 2021) — open-source license and vulnerability scanning specialist.
- CloudSkiff / driftctl (August 2021) — infrastructure drift detection, folded into Snyk IaC.
- TopCoat (October 2021) — developer analytics and metrics.
- Enso Security (November 2023) — application security posture management (ASPM). Reported deal value in the $50–75M range. This was the acquisition that positioned Snyk into the ASPM category, which had emerged as a distinct competitor to the Snyk platform through the 2022–2023 period.
- Probely (2024) — Portuguese dynamic application security testing (DAST) platform.
Position in the Israeli Cyber Cohort
Snyk sits within the broader Israeli-rooted application-security and DevSecOps cohort that includes Checkmarx (acquired by Hellman & Friedman for $1.15B in 2020), Aqua Security, JFrog (NASDAQ: FROG), Cycode, and Apiiro. The cohort collectively represents one of the most distinct concentrations of Israeli commercial output in defensive cybersecurity.
Snyk runs alongside listed Israeli-rooted peers including Check Point Software, CyberArk, Cellebrite, and JFrog, and unlisted peers including Wiz (acquired by Google Cloud in March 2024 for $32 billion, the largest cybersecurity acquisition in history) and Cato Networks.
The comparative valuation math is instructive. At $7.4B Snyk trades at roughly 20–25x ARR — a multiple that is meaningfully compressed from the 2021 peak but still elevated relative to public-market cybersecurity comps trading in the 8–14x range. The valuation gap between Snyk's last private mark and the public-market comp set has been one of the operational reasons the IPO has waited.
The AI-Native Coding Overlay
The rise of AI-native coding tools — GitHub Copilot, Cursor, Anthropic's Claude Code, and the broader agentic-coding category — has restructured the DevSecOps thesis on which Snyk was built. When developers are generating substantial fractions of production code through AI assistants, the volume and pattern of security vulnerabilities entering the codebase shifts.
Snyk's operating response has been to position the platform as the security-and-guardrails layer for AI-generated code, extending scanning coverage and fix guidance to code produced by AI coding assistants. Whether this is a defensive move preserving the existing category or an offensive move extending Snyk into a new category is one of the strategic questions the company faces heading into 2026 and 2027.
Leadership
Peter McKay has served as CEO since 2019, when he took over from Podjarny (who transitioned to Chairman and Founder roles). McKay previously served as President and COO of Veeam Software and as SVP at VMware. His mandate has been the enterprise commercial scale-up and the run to IPO readiness.
Guy Podjarny, co-founder and Chairman, continues to serve as the company's technical and strategic north star, with substantial ongoing engagement in product direction, industry positioning, and the Israeli engineering organization.
Why Snyk Matters
Snyk is one of the reference companies in the Israeli-rooted developer-tools and cybersecurity export layer. The developer-first thesis it commercialized has been adopted across the DevSecOps category and has become the standard operating model for how application security is delivered at enterprise scale. The company's continued private-market status through the 2022–2025 window — while sustaining ARR growth into the $300M+ range — is one of the most-watched trajectories in the Israeli-rooted cybersecurity IPO pipeline heading into 2026.
The strategic significance beyond a single-company frame is the pattern: Israeli-founded technical teams building horizontal developer-and-security infrastructure that anchors the operating stack of the world's largest technology companies. Snyk, JFrog, Wiz, Cato, and the adjacent cohort collectively define the current chapter of the Israeli cyber export story — the transition from perimeter-and-endpoint security into cloud-native, developer-embedded infrastructure.
What to Watch in 2026
- Snyk IPO timing and valuation. The company has been widely expected to file in the 2026 SaaS IPO window; the ARR trajectory and public-market comps will determine the offering size.
- Continued M&A into adjacent DevSecOps and application-security categories.
- Product response to AI-native coding tools and the AI-generated-code security category.
- Competitive dynamics with GitHub Advanced Security, GitLab, and platform-native security offerings from AWS and Azure.
- Israeli engineering scale in Tel Aviv against the broader Israeli cybersecurity talent market.
Frequently Asked Questions
Who founded Snyk?
Guy Podjarny, Assaf Hefetz, and Danny Grander — all Israeli technologists — co-founded Snyk in 2015. Podjarny was previously CTO of Akamai's Web Experience Business Unit.
What is Snyk's valuation?
Snyk was last valued at approximately $7.4 billion in the December 2022 Series G-1 round led by the Qatar Investment Authority. The peak valuation was $8.5 billion in the September 2021 Series F.
How much has Snyk raised?
Snyk has raised more than $1.4 billion across nine rounds since founding, with named investors including Accel, Tiger Global, Sands Capital, Stripes, Addition, Qatar Investment Authority, GV, and Salesforce Ventures.
What is Snyk's revenue?
Snyk's annual recurring revenue crossed $300 million in 2024, per management-reported figures. The company does not disclose full financials publicly as a private entity.
Is Snyk going public?
Snyk has been widely expected to reach the public markets, having postponed an anticipated 2022 filing through the tech-financing reset. The 2026 SaaS IPO window remains the operative timing question.
Where is Snyk based?
Snyk is dual-headquartered in Boston, Massachusetts and London, with substantial engineering and research operations in Tel Aviv, Israel.
Sources
Snyk company disclosures and press releases. Publicly reported funding rounds (Crunchbase, PitchBook). Business press coverage of the 2022 down round and subsequent restructuring. Industry analyst coverage of the application-security and DevSecOps categories.
Olam coverage
See Olam coverage of the Israeli-rooted cybersecurity export layer, including Check Point Software, CyberArk, Wiz, and the flagship Olam Nasdaq 20 for context on the Israeli-rooted technology-listing cohort.
Updated July 2026.

