Introduction
Snyk was founded in 2015 by Guy Podjarny, Assaf Hefetz, and Danny Grander, three security engineers with backgrounds in Israel’s Unit 8200 signals-intelligence corps who started the company out of London and Tel Aviv before headquartering it in Boston. Its original pitch was narrow and developer-first: scan open-source dependencies for known vulnerabilities directly inside a developer’s existing workflow, rather than bolting security review onto the end of a release cycle. A decade later, Snyk has repositioned almost its entire product identity around a newer and less settled problem — whether code, and increasingly autonomous coding agents, produced with AI assistance can be trusted before it ships.
What the company does
Snyk’s platform, now marketed as an AI Security Fabric, scans an organization’s custom code (Snyk Code), open-source dependencies (Snyk Open Source), container images (Snyk Container), and infrastructure-as-code templates (Snyk IaC) for vulnerabilities, surfacing findings directly inside developer tools and CI/CD pipelines rather than in a separate security dashboard. Snyk Code’s underlying engine traces back to DeepCode, an AI-powered static analysis company Snyk acquired in September 2020, which the company credits with letting it apply machine learning to code review years before generative AI became a mainstream development tool.
Who it serves
Snyk sells primarily to software engineering and application-security teams that want vulnerability scanning embedded in existing developer tools rather than run as a separate, periodic audit process. As AI-assisted coding has spread, Snyk has increasingly targeted a second buyer inside the same organizations: platform and security teams responsible for governing which AI coding assistants and autonomous agents are allowed to touch production code, and what those agents are allowed to do once connected via protocols like MCP.
Company background
Podjarny served as Snyk’s first CEO before stepping down in July 2019, when Peter McKay — a Snyk board member since 2016 — took over; co-founders Hefetz and Grander subsequently stepped back from day-to-day roles, with Grander departing in 2021. Snyk reported surpassing $300 million in annual recurring revenue in 2024 and said it served more than 4,500 organizations worldwide as of September 2025, according to independent research citing company disclosures. In July 2026, Snyk announced that Ken MacAskill would serve as interim chief executive while the board — now chaired by Podjarny — searches for a permanent CEO with deep AI expertise, a transition that leaves the company’s top leadership in flux at a moment when its product strategy is most dependent on AI credibility.
Product and AI capabilities
Snyk’s AI strategy has two distinct layers. The first extends its original static-analysis approach: Snyk Code uses machine learning, inherited from the DeepCode acquisition, to find and often auto-suggest fixes for vulnerabilities across more than a dozen programming languages. The second is newer and more defensive in framing — Snyk positions itself as an independent security layer that validates code written by AI assistants, governs what development agents are permitted to do inside tools such as Claude Code, Cursor, and Codex, and inspects Model Context Protocol connections for the kind of tool-permission and prompt-injection risks that are specific to agentic, rather than purely generative, AI coding workflows. Snyk’s June 2025 acquisition of Invariant Labs, an AI security research firm, was aimed squarely at deepening that second layer, adding expertise in agentic threat modeling and MCP vulnerability research.
Key developments
Snyk’s acquisition of DeepCode in September 2020 gave it the AI-powered scanning engine behind Snyk Code, which the company says had grown into a more than $100 million ARR product line by 2024. Its June 2025 acquisition of Invariant Labs extended that AI focus from analyzing AI-written code to policing the behavior of AI coding agents themselves. Most recently, in July 2026, Snyk announced Ken MacAskill as interim CEO, with founder and board chair Guy Podjarny leading the search for a permanent successor described as needing deep AI expertise — language that signals the board sees AI credibility, not just security-market position, as the defining requirement for Snyk’s next chief executive.
Why it matters
Snyk is a useful case study in how quickly a developer-security category can be redefined by AI: a company built on scanning open-source dependencies for known CVEs now spends much of its public messaging on a problem that barely existed three years ago — whether autonomous coding agents can be trusted with production access. Its July 2026 leadership search, explicitly framed around AI expertise, is itself a data point on how central that repositioning has become to the company’s identity, and how unsettled the path forward still is at the executive level.
Sector context
Within Brel’s cybersecurity coverage, Snyk sits at the intersection of application security and the newer discipline of AI governance, overlapping with cloud and code-security vendors like Wiz on the infrastructure side while carving out a distinct focus on the software development lifecycle itself — a niche that has become considerably more contested as AI coding assistants and agents move from experimental to default parts of how software gets written.
Sources and references
This profile draws on Snyk’s official About page and AI Security Fabric product page, cross-checked against Snyk’s Wikipedia entry and an independent Contrary Research business breakdown covering the company’s revenue disclosures, acquisition history, and 2026 leadership transition.