Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Accel leads $40m series A in software security AI firm Depthfirst

Depthfirst, a San Francisco-based AI lab focused on software security, has raised US$40 million in a series A round led by Accel, with participation from Alt Capital, BoxGroup, Liquid 2 Ventures, Mantis VC, SV Angel, and several angel investors.

Depthfirst plans to use the funds for research and development, go-to-market efforts, and hiring.

The company develops an AI platform called General Security Intelligence, which aims to detect and remediate vulnerabilities in software and infrastructure.

Depthfirst said that since launching its product four months ago, it has signed customers including AngelList, Supabase, Moveworks, and Lovable.

The company was founded in 2024 by technical leaders from Google DeepMind, Databricks, and Faire.

🔗 Source: Depthfirst

🧠 Food for thought

Implications, context, and why it matters.

Depthfirst’s platform finds business-logic flaws that traditional scanners miss

  • Traditional SAST tools miss business-logic vulnerabilities in how workflows, permissions and transactions should work because they lack the application’s context 1.
  • Depthfirst claims nearly 10x more true positives, including complex business-logic flaws, with an 85% drop in false positives 2.
  • Its tech caught an authorization flaw in Langfuse, a platform with 16,000 GitHub stars 1. Any authenticated user could access administrative functions due to confusion between authentication (verifying identity) and authorization (granting permissions) 1.
  • Depthfirst claims about a 90% improvement on the CyberGym vulnerability-exploitation benchmark, raising automated success from 20–28% to 53% 3.
  • The system analyzes repositories and builds a view of code, infrastructure and business logic 3. It can trace attack paths and flag cross-service authorization bugs (permission gaps that appear when multiple services interact) 3.

Security service providers and developer tool vendors can integrate with Depthfirst early to capture enterprise accounts

  • $40 million in funding and plans to expand sales may lead to partnerships with Managed Security Service Providers (MSSPs), Value-Added Resellers (VARs), plus tool vendors for joint sales 4.
  • The company is signing a new enterprise customer each week and growing its sales team 2.
  • Security tool vendors and infrastructure providers can build integrations with the platform 3. It links GitHub repositories in three clicks and connects via Application Programming Interface (API) 3.
  • Customers describe an experience like adding an autonomous senior security engineer, with ready-to-merge fixes aligning with customer frameworks 3. That traction can help partners build integrations 3.
  • Service Organization Control 2 (SOC 2) Type II compliance supports enterprise sales where certified integrations set the platform apart 3.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.