Skip to content
Z Zendikt
S

Snyk

Developer-first SCA + container VM category leader.

By Snyk Limited · Founded 2015 · Boston, MA / London, UK · private

Snyk is the developer-first vulnerability management leader for software composition analysis (SCA), container scanning, and infrastructure-as-code (IaC) scanning, founded 2015 in London. The product reframed VM around developer workflow: scan in IDE, scan on PR, fix via auto-PR rather than triage in a security console. Strengths: developer-first SCA (the category Snyk defined), strong PR-based remediation flow that engineering teams actually adopt, integrated container and IaC scanning, and a vulnerability database (Snyk Vulnerability DB) that meaningfully exceeds NVD on coverage and timeliness. Best fit for engineering-led security programs where developer adoption is the bottleneck. Trade-offs: valuation pressure has been visible (last primary $7.4B in Dec 2021; secondary share sales in Sept 2024 at flat-to-down marks reported); infrastructure VM coverage is meaningfully thinner than Tenable / Qualys (Snyk is application-layer, not infrastructure-layer); and pricing per-developer-seat escalates fast at engineering-team scale.

Best for

Engineering-led security programs (any company size with significant in-house development), particularly cloud-native SaaS companies, fintechs, and any org where developer adoption is the bottleneck for security tooling.

Worst for

Infrastructure-VM-first programs (Tenable / Qualys / Wiz broader on infra), Microsoft 365 E5 shops (Defender VM bundled for infra), or organizations with limited in-house engineering (Snyk's value proposition assumes a developer base).

Vendor Trust Score

Is Snyk a trustworthy vendor?

7.5/10
Mixed
Pricing transparency
Published rates; no hidden fees
7.0
Contract fairness
Reasonable terms; no auto-renew traps
7.5
Incident response
How they handle outages and breaches
8.0
Post-acquisition behavior
Customer treatment after M&A or PE
7.5
Executive stability
Leadership churn over 24 months
7.5
Roadmap honesty
Public commitments held
7.5
Trust signal log
  • 2021-12-09
    Series F raised $530M at $8.5B valuation; later marked at $7.4B
  • 2023-04-12
    Layoffs disclosed (~14% workforce reduction); growth-to-efficiency reset
  • 2024-09-18
    Secondary share sales reported at flat-to-down marks vs Dec 2021 primary; valuation pressure visible
  • 2025-04-22
    Snyk AppRisk ASPM platform GA; consolidates SCA + SAST + Container + IaC under unified application security posture
Vendor Trust is scored independently of product quality. A great product from an unfair vendor still earns a low trust score.
Review Intelligence

What 1,240 reviews actually say

Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.

Last synthesized
2026-04-29

Praise patterns

  • Developer-first SCA category leader
    87%
  • Strong PR-based remediation flow
    78%
  • Snyk Vulnerability DB exceeds NVD coverage
    64%
  • Mature freemium tier drives adoption
    51%

Complaint patterns

  • Per-developer-seat pricing escalates fast
    51%
  • Infrastructure VM coverage thinner than Tenable / Qualys
    47%
  • License model creates surprise costs
    41%
  • Valuation pressure flagged in vendor stability questions
    31%
Sentiment trend (6 months)
82/100 +1 pts
12
01
02
03
04
05
Patterns are extracted from review corpus and human-verified. We surface trends, not anecdotes.
Verified Pricing

What buyers actually pay

224 anonymized deal disclosures · last updated 2026-05-01

Contribute your deal price
Company size Median annual
50-200 contributing devs $84,000
200-1,000 contributing devs $360,000
1,000+ contributing devs $1,080,000
Verified pricing is crowdsourced from buyers under anonymity guarantees. Vendor-listed prices are validated against actual deals quarterly.
Compliance & Security

Auto-verified certifications

Verified 2026-05-01
SOC 2 Type II
ISO 27001
HIPAA
GDPR
CCPA
PCI DSS
FedRAMP In-Process

Editorial: Strengths

  • Developer-first SCA category leader
  • Strong PR-based remediation flow engineering teams actually adopt
  • Integrated container, IaC, and code (SAST) scanning
  • Snyk Vulnerability DB exceeds NVD on coverage and timeliness
  • Built for engineering-led security programs
  • Mature freemium tier drives bottom-up adoption
  • IDE plugins for VS Code, JetBrains, etc.

Editorial: Weaknesses

  • Valuation pressure visible (secondary marks flat-to-down vs Dec 2021 primary)
  • Infrastructure VM coverage thinner than Tenable / Qualys (application-layer focus)
  • Per-developer-seat pricing escalates fast at engineering-team scale
  • License model can create surprise costs as engineering teams grow
  • Acquisitions (DeepCode, Manifold, Helios) integration timeline mixed

Key features & integrations

  • +Snyk Open Source (SCA)
  • +Snyk Code (SAST)
  • +Snyk Container (image and Kubernetes)
  • +Snyk IaC (Terraform, CloudFormation, Kubernetes manifests)
  • +Snyk AppRisk (ASPM platform)
  • +Auto-fix PRs
  • +IDE plugins (VS Code, JetBrains, etc.)
  • +Snyk Vulnerability DB
200+ integrations
GitHubGitLabBitbucketJiraSlackJenkinsCircleCIAWSAzure
Geography supported
Global; strongest in US, UK, EU, IL
Best fit
50–500,000+ employees · Engineering-led security programs
Editorial deep-dive

Read our full ranking of Vulnerability Management Software

Snyk ranks #7 in our editorial review of 10 vulnerability management software platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.

Read the full ranking

Closest alternatives in Vulnerability Management Software

Help the next buyer

Contribute your verified deal price

Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for Snyk; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).

Submit anonymously