Salt Security

Salt Security

API security platform and threat protection

Overview

Salt Security provides an API security platform that protects software by monitoring API traffic, discovering all APIs (including shadow and zombie APIs), identifying vulnerabilities, and blocking attackers to speed up incident response. It is delivered as a cloud-based subscription service. Salt Labs is an in-house security research team focused entirely on API security, sharing findings with clients to help harden their defenses. Its goal is to help organizations securely run API-driven software by maintaining visibility over all APIs and reducing risk from threats.

YC Company

About Salt Security

Simplify's Rating
Why Salt Security is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Enterprise Software

Cybersecurity

Company Size

201-500

Company Stage

Series D

Total Funding

$270.1M

Headquarters

Palo Alto, California

Founded

2018

Get referred to Salt Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • July 20, 2026 Policy Hub reached 100 policies, with 61 auto-activating.
  • August 4, 2026 AWS WAF ruleset adds MCP awareness and API abuse blocking.
  • March 18, 2026 Siemens validated Salt’s agentic visibility and protection.

What critics are saying

  • AWS can bundle similar MCP and API defenses directly into native services.
  • Latest public funding remains 2022; slower capital markets constrain enterprise expansion.
  • If agentic-security adoption stalls, Salt turns into a commoditized API point solution.

What makes Salt Security unique

  • Salt’s Agentic Security Graph unifies LLMs, MCP servers, APIs, and runtime controls.
  • Salt Code extends governance into Claude, Copilot, Cursor, Gemini CLI, and Codex.
  • Salt Managed Rules for AWS WAF ship through AWS Marketplace in minutes.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$270.1M

Above

Industry Average

Funded Over

6 Rounds

Notable Investors:
Series D funding is typically for companies that are already well-established but need more funding to continue their growth. This round is often used to stabilize the company or prepare for an IPO.
Series D Funding Comparison
Above Average

Industry standards

$77M
$70M
Twilio
$80M
Handshake
$100M
Affirm
$140M
Salt Security

Benefits

Company Equity

Wellness Program

Remote Work Options

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
PR Newswire
Aug 4th, 2026
Salt Security launches first AWS WAF managed ruleset for AI agent and API protection

Salt Security has launched the first AWS WAF managed ruleset designed to protect both APIs and AI agents. Announced at Black Hat USA 2026, the ruleset is available through the AWS WAF Partner Managed Rules programme in AWS Marketplace. The Salt Managed Rules feature industry-first Model Context Protocol awareness, identifying traffic from MCP endpoints and blocking unauthenticated access. The ruleset also includes advanced API threat detection, blocking attack vectors such as credential brute force, excessive GraphQL queries, and JWT-based anomalies. AWS WAF customers can attach the ruleset to existing web ACLs directly from the AWS console, with deployment taking minutes and requiring no additional infrastructure. The ruleset is available now in AWS Marketplace across all commercial AWS Regions and globally via Amazon CloudFront.

VocoLife
Jul 26th, 2026
Salt Security: 100 policies secure enterprise AI agents.

Salt Security: 100 policies secure enterprise AI agents. 1h ago · 0:00 listen · Source: TipRanks Summary. Salt Security has launched a 100-policy Salt Policy Hub to govern enterprise AI agents and their APIs. This new library expands its Agentic Security Platform. The Policy Hub acts like an app store for security teams. It offers pre-built controls for data security, server configuration, and agent authorization. Of these policies, 61 activate automatically, providing immediate baseline protection. More than a dozen policies specifically address AI agent risks, such as misconfigured servers and unauthorized behavior. These are mapped across eight major compliance frameworks. This framework helps security teams avoid designing policies from scratch. It also extends Salt Security's Agentic Security Graph model, linking large language models, servers, APIs, and enterprise systems into one governance layer. This means comprehensive API posture governance becomes agent governance. The full Policy Hub is available to all customers of the Salt Agentic Security Platform. This update aims to strengthen Salt Security's role as a key control provider for agentic AI. This is an AI-generated audio summary. Always check the original source for complete reporting.

PR Newswire
Jul 22nd, 2026
Salt Security launches in Australia with local AWS infrastructure and dedicated team

Salt Security has launched in Australia with locally hosted infrastructure and a dedicated in-country team. The company deployed its Agentic Security Platform within Amazon Web Services' Sydney region, ensuring Australian customer data is processed and stored within the country's borders. The platform provides enterprises with visibility and governance across AI agents, MCP servers, and APIs. It discovers agents operating in an environment, monitors API behaviour, and provides security teams with posture management and audit capabilities. The Australian launch includes a local sales and technical team providing relationship management and support. Salt Security cited growing enterprise demand across Asia-Pacific for security solutions governing AI agent and API deployments. The company was founded in 2016 and is backed by investors including Sequoia Capital, Tenaya Capital, and Salesforce Ventures.

VocoLife
Jun 2nd, 2026
Salt Code: securing ai-generated code in development.

Salt Code: securing ai-generated code in development. Summary. Salt Security has launched Salt Code, a new solution designed to enforce security policies within AI coding assistants. This tool aims to ensure that all AI-generated code meets internal standards, industry best practices, and regulatory requirements from the moment it's created. AI coding assistants now generate a significant portion of enterprise code, with nearly half of it being machine-written. However, these tools are not trained on an organization's specific security policies. Reports indicate that roughly half of AI-generated code introduces known vulnerabilities, and these risks are accelerating. Salt Code addresses this by using Salt's Posture Governance Engine. This engine defines security and compliance standards once and applies them across the entire development lifecycle. It connects to the tools developers already use, making AI coding assistants generate compliant code by default. This matters because it helps organizations secure their software development as AI coding becomes more prevalent. This is an AI-generated audio summary. Always check the original source for complete reporting.

Pulse
Jun 1st, 2026
Nine in ten security leaders concerned about ai-generated code risks as Salt Security launches new governance tool.

Nine in ten security leaders concerned about ai-generated code risks as Salt Security launches new governance tool. - June 1, 2026 Why it matters. AI-driven code is accelerating development but also introducing vulnerabilities that existing security processes can't scale to manage, threatening enterprise risk and compliance. Embedding governance at the point of code generation offers a proactive defense as AI adoption expands. Key takeaways. * - 90% of security leaders worry about AI-generated code risks. * - 67% of firms have widely adopted AI coding assistants. * - Only 38% rely on manual reviews, deemed unsustainable. * - Salt Code embeds policy enforcement directly into AI assistants. * - Larger enterprises report higher governance challenges as AI adoption rises. Pulse analysis. AI coding assistants like GitHub Copilot, Claude Code, and Gemini have become mainstream, now responsible for roughly half of all code committed on platforms such as GitHub. Salt Security's survey of 100 senior security professionals shows that 90% view the rapid rise of machine-generated code as a security liability, with 29% pinpointing insecure coding patterns and 15% flagging policy drift. The data underscores a growing tension: developers crave speed, while security teams struggle to keep pace with the volume and opacity of AI-produced snippets. Traditional security controls - static analysis, manual code reviews, and post-commit testing - were designed for human-written code and are proving inadequate. The study reveals that only 38% of organizations still rely primarily on manual reviews, a model that quickly becomes unmanageable as AI output scales. Salt's new product, Salt Code, tackles this gap by integrating the company's Posture Governance Engine directly into the AI assistant workflow. Policy packs covering OWASP API Top 10, LLM security, and OpenAPI compliance are applied at the moment a developer prompts the AI, ensuring that insecure patterns are blocked before they enter the codebase. Analysts predict that governance will become the defining challenge of the next AI-assisted development wave. By shifting security enforcement upstream, tools like Salt Code promise to reduce "security drift" and align AI output with enterprise compliance frameworks. For large enterprises - especially those with over 500 employees - the ability to standardise policy enforcement across distributed teams could be a decisive competitive advantage, turning a potential liability into a controlled, auditable component of the software supply chain. Guru Writer The rapid adoption of AI coding assistants is creating a new governance challenge for enterprise security teams, according to research released by Salt Security, which found that nine in ten security leaders are concerned about the security risks associated with AI-generated code. The research, AI Coding Assistants and the New Security Challenge, surveyed 100 IT security leaders across the UK and US and highlights the growing tension between software development speed and security oversight. According to the study, 67% of organisations now report widespread adoption of AI coding assistants across development teams, reflecting how deeply AI has become embedded in modern software engineering practices. However, governance frameworks have struggled to keep pace. While organisations increasingly rely on AI to accelerate development, 38% still depend primarily on manual reviews to assess AI-generated code, a process many security leaders believe is becoming unsustainable. Among respondents, 29% identified insecure coding patterns as the biggest risk introduced by AI assistants, while 15% cited concerns about generated code failing to align with internal security policies. The findings mirror wider industry concerns about the quality and security of machine-generated software. According to figures cited by Salt Security, AI coding assistants now generate nearly half of all code written on platforms such as GitHub, while independent research has found that a significant proportion of AI-generated code contains known vulnerabilities. "AI coding assistants are fundamentally changing how software is built, but governance has not kept pace," said Roey Eliyahu, CEO and co-founder of Salt Security. "Most organisations recognise the risks, but many are still trying to manage AI-generated code using security processes designed for a pre-AI world. That approach does not scale. Security leaders need visibility, consistency and embedded governance across the AI-assisted development lifecycle before code volumes become unmanageable." The research also revealed that larger enterprises face greater operational complexity as AI adoption grows. Organisations with more than 500 employees were significantly more likely to report challenges around governance consistency, developer overreliance on AI-generated outputs and policy enforcement across distributed development teams. The findings coincide with the launch of Salt Code, a new addition to the company's Agentic Security Platform designed to enforce security policies directly within AI coding assistants such as Claude Code, GitHub Copilot, Cursor, Gemini CLI and Codex. Salt Code is designed to move security controls earlier in the software development lifecycle. Rather than relying solely on traditional security testing tools after code has been written, Salt Code applies organisational security policies during code generation itself. At the heart of the platform is Salt's Posture Governance Engine, which allows organisations to define security and compliance requirements once and enforce them consistently across code creation, deployment and runtime environments. The platform includes pre-built policy packs covering frameworks such as the OWASP API Top 10, MCP Security Top 10, LLM Security Top 10 and OpenAPI/Swagger compliance. According to Salt Security, the approach is intended to address what it describes as "security drift", or the gradual divergence between organisational policies and actual development practices that can occur as AI-generated code volumes increase. "AI is writing code faster than organisations can govern it, whether that AI is Claude, Gemini, Copilot, or the next tool a developer downloads tomorrow," Eliyahu said. "For the first time, security policy travels with the code itself, from the first prompt through every stage of the pipeline and into runtime. Organisations no longer have to choose between the speed AI enables and the security their business requires." Industry analysts have argued that governance will become increasingly important as AI-generated code forms a growing share of enterprise software. Salt's research suggests that organisations are already recognising the challenge, with security leaders expressing concerns that manual review processes are struggling to scale alongside AI-assisted development. "I regularly point organisations toward Salt because the full Agentic Security Graph is genuinely differentiating. Salt Code is the piece that ties it together," said Christopher M. Steffen, CISSP, CISA, CCZ, VP of Research, Information Security, Risk and Compliance Management, Enterprise Management Associates. "With code-level context layered onto runtime behaviour, Salt is building a multi-dimensional defence for agentic systems rather than another single-point tool. That is the direction this market needs to move." The company is encouraging organisations to focus on improving visibility into AI-generated code, reducing dependence on manual review, standardising secure development practices and treating AI coding assistants as part of the wider software supply chain. As enterprises continue to embrace AI-assisted development, the findings suggest that the next phase of adoption may be defined less by productivity gains and more by how effectively organisations can govern and secure the code these systems produce.

Recently Posted Jobs

Sign up to get curated job recommendations

Salt Security is Hiring for 6 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →