Back to vendors
d

depthfirst

Visit site
Entry priceNot public; sold through sales after a demoFull pricing detail

AI security platform that detects, triages, and remediates software vulnerabilities.

depthfirst is an applied AI lab building what it calls General Security Intelligence, a platform of custom AI agents that detect, triage, and remediate software vulnerabilities across code, dependencies, secrets, infrastructure, and runtime.

Founded in 2024 by Qasim Mithani, former head of infrastructure security at Databricks, and Andrea Michi, who spent nearly seven years building AI at Google DeepMind, with a founding team drawn from DeepMind, Databricks, and Faire, the San Francisco company has raised 120 million dollars in total.

An 80 million dollar Series B led by Meritech in March 2026, at a 580 million dollar valuation, came less than ninety days after its 40 million dollar Series A led by Accel, with angels including Jeff Dean.

The thesis is that winning in the AI era of security requires security specific models rather than general language models bent to the task. depthfirst builds its own models, trained through reinforcement learning in security environments: dfs-mini1 for smart contract vulnerabilities, and dfs-large1, post trained on GLM 5.2, in preview for large enterprise repositories.

On top of the models sit six named products that work as a continuous loop: a Code Scanner that traces business logic and data flows, a Security Reviewer that checks every human and agent code change before merge, a Dependency Firewall that blocks malicious packages, Secrets and Supply Chain agents, the latter tracing reachability through transitive dependencies in every scan, and an Agentic Pentester that validates findings against the running application and replays the attack after a fix is merged, so a finding closes only when exploitation fails. Fixes arrive as pull requests an engineer reviews and merges, and every human and agent action is logged. Access is role based by repository, environment or organization, with customer held encryption keys and a SOC 2 audit.

The company reports many times more true vulnerabilities than static analysis, roughly eighty five percent fewer false positives, and about eighty percent of its fix suggestions accepted and merged; those are its own figures. Customers it names include Lovable, Supabase, Moveworks, AngelList, ClickUp, and incident.io. It does not publish its hosting model or pricing, and its documentation sits behind the customer login. For an engineering organization shipping AI generated code faster than it can secure it, depthfirst validates and fixes rather than just flags; teams wanting a traditional scanner or a bring your own model approach will find a model owning platform instead.

Vendor details

Canonical URL

https://depthfirst.com

Category

Security / SOC agent

Subcategory

Application security vuln triage and remediation

Funding status

Independent, founded in 2024 by Qasim Mithani, former head of infrastructure security at Databricks, and Andrea Michi, formerly of Google DeepMind, with a team from DeepMind, Databricks, and Faire. Raised 120 million dollars in total, including an 80 million dollar Series B led by Meritech Capital in March 2026 at a 580 million dollar valuation, following a 40 million dollar Series A led by Accel. Angel investors include Jeff Dean and Kirsten Green.

Company status

independent

Use cases & customers

Primary use cases

vulnerability detection and validationAI and human code review in pull requestsdependency and supply chain protectionagentic penetration testing

Target customers

enterpriseengineering teams

Deployment options

SaaS

Integrations

Integrates directly into developer workflows, reviewing pull requests and delivering ready to merge fixes, and connects across code, dependencies, secrets, infrastructure, and runtime in one continuous system. The agentic pentester can validate findings against a running application with or without code access.

In practice

Your team ships AI generated code faster than security can review it. depthfirst's Security Reviewer checks every human and agent change in the pull request and proposes ready to merge fixes, so security keeps pace with development.

Scanners bury your team in false positives. depthfirst's Agentic Pentester validates each finding against your running app with real attack paths, so only exploitable risk reaches the queue, cutting noise sharply.

A vibe coded internal app pulls in a malicious dependency. depthfirst's Dependency Firewall blocks malicious packages before they land, letting you use AI coding tools across the company safely.

Agentic Index coverage score

9.5 / 14 capabilities · 68%

Integrations & Tool Calling Full

Connects to GitHub, GitLab, Jira, Linear, Docker, AWS, Google Cloud, Azure, Terraform and JFrog, and its remediation agent opens a pull request against the customer's repository for every confirmed vulnerability.

Sourcedepthfirst.com/platformread 2026-09-28

Workflow Orchestration Full

Several agents hand work to each other across one loop: the code scanner and supply chain agent find issues, the agentic pentester validates exploitability, the remediation agent opens the fix, and the pentester replays the attack after merge, with a finding closed only when exploitation fails. No workflow builder the buyer configures is documented.

Sourcedepthfirst.com/platformread 2026-09-28

Knowledge Grounding & RAG Partial

Agents read the customer's code, dependencies and data flows at scan time and show the call chain behind each finding. No maintained index, graph or embeddings layer over the customer's code is documented; the searchable system of record holds findings and fixes, not the customer's knowledge, and product docs sit behind the app login.

Sourcedepthfirst.com/post/reachability-in-supply-chain-riskread 2026-09-28

Human Oversight & Guardrails Partial

Policy set once applies to every scan, fix and agent action, a customer controlled constraint. Fixes arrive as pull requests an engineer reviews and merges, but that review gate belongs to the customer's code host, and no depthfirst approval step before an agent action commits is documented.

Sourcedepthfirst.comread 2026-09-28

Security, Identity & Governance Full

Role based access is scoped by repository, environment or organization, and customers hold their own encryption keys. The SOC 2 attestation is independently audited, with a trust center at trust.depthfirst.com, though the SOC 2 type is not stated.

Sourcedepthfirst.comread 2026-09-28

Observability & Auditability Full

Every human and agent action is logged, immutable and traceable, showing who did what, when and why, and each finding carries the full call chain from application code to the vulnerable function.

Sourcedepthfirst.comread 2026-09-28

Memory & State Persistence Partial

The platform improves over time by learning from developer feedback on its recommendations, which carries state across scans. No memory store, scope or lifetime is documented.

Sourcedepthfirst.com/platformread 2026-09-28

Deployment & Data Residency Not documented

No hosting model, region or self hosted option is published, and customer held keys are an encryption control rather than a deployment option. The product docs at docs.depthfirst.com sit behind the app login.

Sourcetrust.depthfirst.comread 2026-09-28

Prebuilt Agents, Templates & Packs Full

Six named products, each doing its own job: Code Scanner, Dependency Firewall, Agentic Pentester, Security Reviewer for pull requests, Secrets and Sensitive Data, and Supply Chain; removing one leaves the others whole.

Sourcedepthfirst.comread 2026-09-28

Triggers & Channel Coverage Full

Work starts on events with no one asking: every pull request is reviewed before merge, the pentester replays attacks after every merge, reachability runs in every SCA scan, and the dependency firewall watches packages in real time.

Sourcedepthfirst.comread 2026-09-28

Model Flexibility & Routing Not documented

Runs depthfirst's own security models (dfs-mini1, and dfs-large1 in preview, post trained on GLM 5.2); no provider list the customer selects from or bring your own model path is documented.

Sourcedepthfirst.com/research/dfs-large-new-model-releaseread 2026-09-28

APIs, SDKs & MCP Extensibility Full

An API queries findings, triggers scans and integrates depthfirst into the customer's own tooling; its reference sits behind the customer login at docs.depthfirst.com.

Sourcedepthfirst.com/platformread 2026-09-28

Testing, Debugging & Optimization Full

A quality gate reads on the agent's own output: the pentester replays the same attack after every fix is merged and a vulnerability counts as resolved only when exploitation fails in the running application, and recommendations improve on developer feedback, an optimization loop after deployment. The dfbench model benchmark is the vendor's own publication rather than a customer surface.

Sourcedepthfirst.com/platformread 2026-09-28

Browser & Computer Use Not documented

The agentic pentester runs attacks against the running application with no browser mechanism named for it, and no agent is documented driving a browser, desktop or remote computer.

Sourcedepthfirst.com/platformread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-30·Agent capabilityVerified

depthfirst launched Agentic Pentesting, autonomous agents that log in to a running application and attack it through its interfaces and APIs, on demand or from a CI pipeline. With source code connected, they use earlier findings and the threat model to pick attack paths, confirm whether scanner or bug bounty findings can really be exploited, and replay the attack after a fix to prove it worked.

Bears on: Agent capability

View source
2026-09-23·Agent capabilityVerified

depthfirst makes transitive dependency reachability available to customers as part of every software composition analysis scan. Its agent follows execution paths through intermediate packages and exposes the chain of calls leading from application code to a vulnerable function. The analysis can follow invocation mechanisms that static call graphs miss, including command line startup and framework callbacks.

Bears on: Agent capability

View source
2026-07-30·Agent capabilityVerified

DepthFirst introduced dfs-large1, a proprietary security model built on GLM 5.2 and post-trained using reinforcement learning within its security agent harness. The model is now available in preview for vulnerability discovery and validation across large enterprise repositories.

Bears on: Agent capability

View source
View all 4 changes for depthfirst →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Not public; sold through sales after a demo

not published

Trial available

What is public

No public rate. depthfirst publishes no list pricing; commercial terms are set through sales.

Billing mechanics

Sold through sales after a demo. depthfirst does not publish its billing unit; whether the six products are bundled or sold separately is not stated.

Cost watchouts

Confirm whether the dependency firewall, security reviewer, and agentic pentester are bundled or priced separately, and how pricing scales with codebase size and scan frequency.

Variable cost rationale

No billing unit is published. As an inference, scope may track repositories, developers or products enabled; confirm in the quote.

Additional watchouts

With no public rate, benchmark against your current AppSec tooling and security headcount, and confirm which of the Security Reviewer, Dependency Firewall and Agentic Pentester modules the base contract includes.

Sales call required

Yes, required for paid access

Free / trial

Demo available on request; no public self serve tier

Key ambiguities

No entry rate or per developer figure is published; all pricing is quoted under sales.

Agentic Index verified 2026-09-28

Alternatives to depthfirst

The closest documented capability profiles to depthfirst among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Repello AI8.0 / 14A lighter documented profile than depthfirst
  • Magnitude8.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
  • Parameter7.5 / 14A lighter documented profile than depthfirst
  • Abnormal AI9.0 / 14Adds documented Deployment & Data Residency
  • Capsule Security9.0 / 14Fuller documented coverage on Knowledge Grounding & RAG and Human Oversight & Guardrails
  • Dropzone AI11.0 / 14Adds documented Deployment & Data Residency and Model Flexibility & Routing

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.