AppSec platform for AI-generated code and supply chain security
Legit Security builds application security tooling purpose-built for AI-powered development workflows. The tech stack is cloud-native (Kubernetes, AWS, GCP, Azure) with GitOps-heavy orchestration (ArgoCD, Flux, Terraform), suggesting a multi-tenant SaaS architecture designed for CI/CD integration. Hiring is heavily skewed toward senior engineers and sales (8 engineering, 6 sales roles open) with accelerating velocity—a pattern typical of post-product-market-fit companies scaling enterprise go-to-market while deepening platform capabilities.
Notable leadership hires: Head of Engineering
Legit Security provides an application security platform tailored to modern development environments where code is generated or assisted by AI. The product surface includes VibeGuard (visibility and security for AI-generated code) and ASPM (application security posture management), which unifies AppSec testing, secrets prevention, software supply chain security, and vulnerability management. The company operates as a cloud-native SaaS offering targeting CISOs, AppSec teams, and DevSecOps leaders. Active projects span customer onboarding, enterprise pipeline expansion, and solution architecture—indicating a sales-led scaling phase alongside product maturation.
Container orchestration (Kubernetes), cloud platforms (AWS, GCP, Azure), GitOps tools (ArgoCD, Flux, Terraform, Pulumi), observability (Prometheus, Grafana, Loki, OpenTelemetry), CI/CD (GitHub Actions, GitLab CI/CD, Jenkins, CircleCI), and languages including Python, Go, C#, Node.js, Java, and React/TypeScript frontend.
Cloud-native SaaS platform expansion, secure SDLC pipeline architecture, highly available microservices, customer onboarding and enablement, and enterprise sales pipeline development targeting AppSec and DevSecOps leaders.
Other companies in the same industry, closest in size