
Work Here?
StackHawk provides application security testing tailored for developers, specializing in dynamic application security testing (DAST) to find vulnerabilities in applications and APIs. It works by running automated security tests within running apps and APIs and integrating these tests into CI/CD pipelines, enabling engineers to detect and fix security issues as part of the development process. Compared with others, StackHawk emphasizes a developer-first approach with strong automation and broad API coverage, allowing seamless integration into existing development workflows and offering tiered subscription pricing based on team size, number of applications, and support level. The goal is to help software teams ship secure software faster by identifying and addressing security weaknesses early in the development cycle, reducing costly fixes after release.
Industries
Enterprise Software
Cybersecurity
Company Size
11-50
Company Stage
Late Stage VC
Total Funding
$47.3M
Headquarters
Denver, Colorado
Founded
2019
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$47.3M
Below
Industry Average
Funded Over
5 Rounds
Health Insurance
Dental Insurance
Vision Insurance
Remote Work Options
Paid Vacation
Paid Holidays
Company Equity
StackHawk has launched Wingman, a tool that autonomously fixes security vulnerabilities during AI coding sessions. Priced at $10 per user per month, Wingman integrates with AI coding agents like Claude Code, Cursor, and GitHub Copilot to identify and remediate flaws before code reaches production. The tool has automatically fixed over 7,500 vulnerabilities for early-access customers, with 98% of fixes remaining resolved. It addresses high-severity issues including remote code execution, SQL injection, and cross-site scripting. Wingman operates within existing AI coding workflows, automatically scanning applications when features are completed, sending findings back to the AI agent for fixing, and verifying repairs before pull requests open. The system includes unlimited applications and 50 scans per user monthly. CEO Joni Klippert noted that whilst AI coding agents enable faster development, security processes haven't kept pace, creating organisational risks. Wingman aims to close vulnerabilities at the speed code is written.
StackHawk's Wingman fixes security flaws while the AI agent is still coding. Application security company StackHawk Inc. today launched Wingman, a tool that fixes security vulnerabilities inside the artificial intelligence coding session that produced the flawed code. The software installs into agentic coding workflows, among them Claude Code, Cursor and GitHub Copilot. Wingman fires when a coding agent marks a feature as done. The scanner configures itself, boots the running application and probes it the way an attacker would, without a manual setup step. Findings then go back to the agent that wrote the code, which patches the flaw, and a second scan checks the repair before a pull request opens. StackHawk's argument is that an agent that built an application already holds its architecture, its dependencies and the conventions the rest of the team codes to. StackHawk said that context is what separates Wingman from a scanner bolted on downstream. Patches come back in the shape of the surrounding code. Codex and Antigravity are supported too. Wingman tells the continuous integration pipeline whether a commit is clean. Because every test carries the commit it ran against, security teams end up with a record of what shipped. StackHawk said Wingman fixed more than 7,000 vulnerabilities for early-access customers before the launch, and that 98% of those repairs have held. Attackers often reach a vulnerability before it is publicly disclosed, Chief Executive Joni Klippert said. AI coding agents have pushed engineering teams out ahead of what security can absorb. "Finding was never the hard part," Klippert said. "Fixing and verifying [a vulnerability] fast enough to match how engineering teams ship today, at machine speed, inside the workflow, as the code is written, is what security teams have never had the staff or the hours to do." Wingman costs $10 per user each month and includes unlimited applications with 50 scans per user a month. A 14-day free trial is available. Teams that need broader application programming interface discovery and attack-surface mapping can pair the tool with StackHawk Scale, the company's enterprise tier. StackHawk sells to more than 200 enterprises. The company is venture capital-backed and raised $20.7 million in May 2022 in a round led by Sapphire Ventures and Costanoa Ventures. Klippert spoke with theCUBE, SiliconANGLE Media's livestreaming studio, in March, when she discussed how developers should not have to become security specialists to ship safe code. "They want to write quality code, but they don't want to become security engineers," she said. Image: StackHawk. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from its Marketplace portal page and links: https://siliconangle.com/aws-marketplace/. About SiliconANGLE Media. SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
Lessons from Hagerty: scaling AppSec without becoming the bottleneck. Casey Cline | May 5, 2026 Scaling to 40+ teams in two quarters. Hagerty chose StackHawk for its strong documentation, flexibility across environments, developer-friendly design, and ability to simulate real attacks without blocking pipelines. But when John Mercer, DevOps Security Engineer at Hagerty, decided it was time to scale StackHawk across more than 40 developer teams, he faced a common organizational challenge. How do you get leadership and dev buy-in, secure resources, and make sure everyone is up to speed about a new product, all in the course of two quarters? Like most companies, Hagerty's Security team is small compared to its Engineering team. "It's a challenge when Security is only 7 or 8 percent of your whole IT budget, and you are asking them to do something." This is something StackHawk Inc. hear time and time again at StackHawk. It's why StackHawk Inc. emphasize that shifting AppSec left requires distributed ownership. In John's words, "One person can't go through 20, 30, 40, 100 teams... You have to distribute it." As Hagerty's Customer Success Manager here at StackHawk, I had a front-row seat to the rollout. John's approach was genuinely impressive, and I knew other customers could learn from it. John and I sat down for a conversation, and these are the lessons I came away with. AppSec at scale is a coordination effort. "The trouble isn't really technical... It's bureaucratic. It's a project management problem." I asked John why he chose to roll out to 40 teams at once, rather than implement one team at a time. His answer was very direct: "Because that approach could take literally five years. Why not knock it out all at once and make it a company-wide standard?" John leveraged Hagerty's "awesome project managers," who prioritized the StackHawk work, assigned deadlines, and fit implementation into an upcoming sprint. As John put it, "The real challenge wasn't technical, and it wasn't the devs. It's an easy product to implement. It was a project management problem." Once he had the project managers on board, things moved quickly. Not every customer has a dedicated project management team, but in many cases, all it takes is one person willing to own the implementation and prioritize it. Leadership alignment is necessary but not sufficient alone. One thing that became clear throughout Hagerty's rollout is that leadership alignment, while important, isn't the hardest part. In John's experience, getting buy-in at the CIO or CISO level was relatively straightforward. Leadership at Hagerty understands how important AppSec is. Where things became more complex was in translating that priority into actual work across teams. Even with clear top-down direction, the real effort was in scheduling, prioritizing, and completing the work within existing sprint cycles. The challenge wasn't convincing people of the importance; it was operationalizing it. Pattern-Based rollouts work. Before rolling StackHawk out to the entire Hagerty organization, John did a deep dive into its product, set up and configured initial scans, and then optimized them. I teased him that, at this point, he is such a StackHawk SME that he could be on its payroll. That upfront investment made it easy to take the approach StackHawk Inc. often recommend to larger organizations: templatize and repeat. In John's own words, "Once there's a pattern, you can simply copy it with very little additional work needed." Specifically, he did upfront work across multiple stacks (.NET, Python, Node) and then reused it for a comprehensive yet scalable approach. Communicate the value to developers. John focused on communicating the value of StackHawk in a way that would resonate with developers and address their concerns up front. "I always led with 'StackHawk mimics a real-world attack.' Then I reassured them that I will never block them with StackHawk. It'll only add like five minutes to their pipeline, and then they're covered. They were good with that." Leverage existing goodwill. At Hagerty, Security and Engineering have a strong working relationship, and that wasn't accidental. It's been an intentional, mindful choice grounded in mutual trust and respect. As John said, "We've worked hard to build good relationships with engineers. They know we're not adversarial." That trust paid off during the rollout. Engineers gave the work the benefit of the doubt because they had reason to. AppSec at scale, without the bottleneck. Over roughly two quarters, Hagerty rolled StackHawk out across more than 40 teams without turning security into a bottleneck. The technical pieces (easy implementation, dev-friendly pipeline integration, strong documentation, scans that mimic real attacks) gave John a foundation he could trust. From there, the work that mattered was operational: focusing on repeatable patterns, clear communication, and distributed ownership, they were able to scale AppSec in a way that actually worked for engineers. As John put it, "You have a great tool. You've got great documentation. It's very clear how to implement it in different environments. It's very flexible for all kinds of different scenarios or use cases." Once StackHawk reached developers' hands, adoption followed quickly. For organizations looking to do the same, the takeaway is simple: treat AppSec scale as a coordination effort. Build the pattern, communicate the value, and make it easy for teams to run with it. Read the full customer success story.
StackHawk, an application security company, has appointed Joe Sullivan to its board of directors. Sullivan previously served as chief security officer at Meta, Uber and Cloudflare during critical growth periods. The appointment comes as StackHawk scales operations amid rising demand for security testing that matches AI development velocity. A recent StackHawk survey found 87% of organisations have adopted AI coding assistants like GitHub Copilot, driving code velocity up to 10 times faster. Sullivan cited the paradigm shift created by AI coding tools, noting traditional security approaches cannot handle the accelerated application generation speed. StackHawk's platform combines shift-left runtime testing with attack surface discovery, integrating directly into development workflows. The Boulder-based company recently launched an Alliance & Reseller Programme to expand market reach.
David Geevaratne joins StackHawk as EVP of Sales. David Geevaratne | Feb 27, 2026 David brings 20+ years of IT and cybersecurity sales experience to his role at StackHawk. Learn what brought him here. Why runtime application security? Throughout my career in IT and cybersecurity, I've had a front-row seat to major platform shifts: cloud migration, DevOps, container adoption. Each one reshaped how software gets built and eventually secured. What's happening with AI-assisted development is, without a doubt, the most dramatic yet, with higher stakes for application security than ever. Organizations are reporting an eightfold increase in code output through AI coding assistants. That's not theoretical. It's happening inside every engineering org right now (87% according to its recent survey!). And it has a longer tail impact than the market is paying attention to. The jury might be out as to how secure vs. vulnerable AI-generated code is. But what's not up in the air: more code means more attack surface, more endpoints, and more to test. When security validation doesn't scale at the same rate, the gap compounds fast. And yet, AppSec tools are moving in the wrong direction, trading precision for promises with black-box approaches that can't tell you what's covered and what isn't. Budgets are flat. Teams are stretched. And the CISOs I talk to aren't asking for more tools. They're asking three questions: Can you show me what StackHawk Inc. has? Can you prove it's tested? Can you prove StackHawk Inc. is reducing risk? Answering those takes dynamic testing that is API-first, pipeline-native, and defined as code. Not promises. Proof. Why StackHawk? AI has reset the software lifecycle. Every day is effectively Day 0. You either maintain perpetual visibility and continuously test what's exploitable, or you try to find the needle in the haystack and end up finding it in production. What drew me to StackHawk is that the approach maps to how modern AppSec actually needs to work: shift-left DAST that runs natively in CI/CD and finds real, exploitable vulnerabilities before production. That is the only way to keep up with the pace of AI. On top of that, the product this talented team has built is solving real problems for real customers. Attack surface discovery from source code, so you know what exists before production. Centralized program intelligence so leaders can prove what's working and where risk lives. Most tools are built for one audience. Developer tools that security teams tolerate. Security tools that developers ignore. StackHawk serves the full triangle of influence: practitioners, AppSec leaders, and CISOs. I'm proud to be joining this team, and I'm looking forward to helping organizations understand their real attack surface, demonstrate actual risk reduction, and move as confidently as the AI-powered development teams they protect. About David. David brings 20+ years in cloud-native and cybersecurity sales leadership to StackHawk. Most recently, he served as SVP of Sales at Uptycs, a cloud-native security analytics company. Before that, he held leadership roles at Rapid7 and DivvyCloud (acquired by Rapid7), where he led cloud security go-to-market efforts. Earlier in his career, David co-founded New Signature, a Microsoft cloud services provider later acquired by Cognizant, where he served as President and CRO and helped drive 12 consecutive years of double-digit revenue growth. David has been recognized as a Washington Business Journal Minority Business Leader, a CRN 30 in Their 30s honoree, and a Washington Business Journal Corporate Philanthropy Award recipient for his work at New Signature.
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
11-50
Company Stage
Late Stage VC
Total Funding
$47.3M
Headquarters
Denver, Colorado
Founded
2019
Find jobs on Simplify and start your career today