Company focuses on automation to dramatically reduce the software attack surface and the application security burden for developers
TEL AVIV AND BOSTON – May 25, 2022 – WhiteSource, a leader in application security, today announced the change of its name to Mend. The company is also launching the industry’s first automated remediation for custom code security issues as well as integration of Mend Supply Chain Defender (formerly WhiteSource Diffend) in its JFrog Artifactory plugin, all within the Mend Application Security Platform. Mend secures all aspects of your software, providing automated remediation, prevention, and protection from problem to solution versus only detection and suggested fixes.
With revenue up 800% over the past three years and enterprise net retention at 127% in 2021, the company added 350 new customers in the last year. Mend has over 1,000 customers including more than 25% of the Fortune 100 and is focused on investing its latest round ($75 million series D announced in April 2021) into its overall growth as it expands beyond the Software Composition Analysis (SCA) market. This includes the move into supply chain security through its acquisition of Diffend in April 2021 and the acquisitions of SAST startups Xanitizer and DefenseCode in February this year. The company’s strategic acquisitions and its unique automated remediation technologies have enabled it to deliver the Mend Application Security Platform. Combining automated remediation for static application security testing (SAST) with Mend’s existing ability to do this for software composition analysis (SCA), the platform is the first to automatically find and fix application security holes involving both open source and custom code.
“Attackers are increasingly targeting applications as the weakest link to go after organizations, and at the same time, pressure to deliver software faster has never been higher. Organizations face undeniable tension to do both, better,” said Rami Sass, Co-founder and CEO of Mend. “Mend breaks the tradeoff between security and development delivery timelines by providing a solution that automates the reduction of the software attack surface while removing most of the burden of application security, allowing development teams to deliver quality, secure code, faster.”
Mend’s Automated Remediation for SAST
Offering automated remediation for both open source and custom code, providing exact fixes for each line of code, the Mend Application Security Platform enables any level of developer to easily write quality, secure code. Prior to this advancement, leading application security products could, at best, provide training materials and examples to support developers with researching fixes for each security issue they encountered. This inefficient process forced developers to choose between security and meeting deadlines. The Mend platform delivers automated remediation for both SCA and SAST, presented directly in the developer’s repository, for easy integration into the developer workflow. With Mend, developers don’t have to sacrifice security for speed.
Mend Supply Chain Defender Integration with Artifactory Plug-In
“Whether open-source or proprietary code, the application security industry has mostly focused on vulnerability detection and management. Mend has an interesting approach of automating the remediation of code vulnerabilities,” said Josh Johnson, Manager of Solutions Architecture, Defy Security. “While the company is announcing this new name, as a partner of Mend, we are excited for it to further its commitment to solving code-based security challenges with automated-remediation. Defy Security looks forward to seeing Mend extend automation for closing security gaps.”
Mend.io, formerly known as WhiteSource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks. With a proven track record of successfully meeting complex and large-scale application security needs, Mend.io is the go-to technology for the world’s most demanding development and security teams. The company has more than 1,000 customers, including 25 percent of the Fortune 100, and manages Renovate, the open source automated dependency update project. For more information, visit www.mend.io, the Mend.io blog, and Mend.io on LinkedIn and Twitter.
Guyer Group for Mend.io