For informational purposes only. Not financial advice, not a recommendation to buy or sell any security. Standing Order is a directory and research project, not an advisory service.
Thesis
Snyk pioneered developer-first application security — security testing embedded in the developer workflow (code, dependencies, containers, IaC) rather than imposed by a separate team afterward. As software supply-chain risk and AI-generated code expand the attack surface, scanning at the point of creation becomes more valuable.
The investment case is owning the developer-security workflow as application security shifts left and AI accelerates code volume. As a private name it has no market cap here; coverage conviction reflects category leadership against monetization and competitive pressure. Risks: competition from GitHub/Microsoft, Checkmarx, and platform consolidation; and the perennial developer-tools challenge of converting adoption to durable revenue.
Catalysts
- ARR growth and path to profitability / IPO
- AI-code-security product traction
- Software-supply-chain regulatory drivers
- Competitive position vs. GitHub Advanced Security