Mend
20 Park Plaza, Suite 322, Boston, MA, 02116, United States
Overview
WhiteSource automatically identifies every open source component in a company’s technology stack, then identifies and prioritizes vulnerabilities and issues real-time alerts on genuine risks. The platform integrates with popular development environments and IDEs, provides a dashboard for dependency and license risk visibility, and offers remediation guidance such as recommended upgrades. WhiteSource offers tiered plans (free; Essentials at $2,400/year; Teams at $10,000/year; Enterprise starting at $28,000/year). The company says enterprise customers tripled and revenue grew by 800% over the past three years. Founded in 2011, WhiteSource is used by customers including Microsoft, IBM, and Comcast. The company plans to expand beyond software composition analysis (SCA) into broader application security testing (AST), including prioritization and auto-remediation of open source vulnerabilities. WhiteSource provides software composition analysis tools that track open-source components, detect security vulnerabilities, and offer remediation and governance actions across the software lifecycle. Its platform scans multiple sources (including the National Vulnerability Database) and includes prevention tools to stop vulnerable components entering code as well as retroactive fixes. The company says nearly 98% of open-source vulnerabilities have fixes available and publishes research on vulnerability trends; it estimates 7.5% of projects are vulnerable and 32% of the 100 most popular projects have vulnerabilities. WhiteSource counts roughly 500 large-enterprise customers, including 23% of the Fortune 100, and maintains offices in New York, Boston and Tel Aviv. Founded in 2011, the company was an early coiner of the term “software composition analysis.” Following the new funding, WhiteSource plans to hire more engineers, double down on its platform and expand into more geographies to grow beyond its current customer base. WhiteSource offers a namesake solution that secures and manages open source components across the DevOps lifecycle, providing real-time alerts, reports and automated policy enforcement. Its platform automates component detection, vulnerability alerts and fixes, license risk and compliance analysis, quality review, and new-version alerts. The product is used by hundreds of enterprises and SMBs and is positioned as an integral part of customers' DevOps processes. WhiteSource has been recognized by Forrester as a “strong performer” in Software Composition Analysis. The company grew revenues 300% year-over-year for the last three years. The new funding is intended to help WhiteSource expand its market leadership in open source security and compliance.
- Total raised
- $120M
- Funding rounds
- 3
- Latest round
- Series D
- Latest activity
- Apr 2021
Industries
- Cyber Security
- Developer Tools
- Open Source
- Software
Recent funding
Series D
Apr 2021
$75M
Series C
Oct 2018
$35M
Series B
Jun 2017
$10M