Montreal company developing a software development lifecycle security platform covering application security posture management, CI/CD and software supply-chain protection, and monitoring of AI coding agents and tools on developer machines.
Montreal company developing a software development lifecycle security platform covering application security posture management, CI/CD and software supply-chain protection, and monitoring of AI coding agents and tools on developer machines.
Announced in May 2026 the acquisitions of Korbit.ai and SecureIQx and a funding round from White Star Capital, Amiral and Accelia; the amount was not disclosed. boostsecurity.io ↗
A published case study names Mattel as a customer, stating its AppSec lead reached visibility across 700+ repositories within two hours. boostsecurity.io ↗
Emerged from stealth in November 2022 with $12 million in seed funding led by Sorenson Capital. boostsecurity.io ↗
Products BoostSecurity publishes on its own site. Each card links to the page it was taken from.
Boost AI-Native ASPM
Application security posture management
Deploys at the source-control level without CI/CD edits, consolidates SAST, SCA, secrets and IaC scanning, prioritizes findings with reachability analysis and pushes code fixes to pull requests.
Inventories third-party actions, plugins and build scripts in CI/CD pipelines, blocks typosquatted or malicious packages at install time and scans for build-time flaws such as command injection.
Detects coding agents, MCP servers, local models and IDE extensions on developer machines, masks credentials in outbound prompts and scans for exposed secrets, malicious extensions and malware.
BoostSecurity announced it acquired Korbit.ai, an AI code review company with AI-native SAST, and SecureIQx, an MIT-founded team focused on binary and source composition analysis with reachability analysis, and welcomed White Star Capital, Amiral and Accelia as investors. No amount was stated.