Diamond Exhibitors

Arnica

www.arnica.io

Surface the right risk to the right owner at the right time with pipelineless, developer-native workflows that foster collaboration, increase development velocity, and reduce overall risk.

Gold Exhibitors

Aikido Security

www.aikido.dev/

Aikido is your no-nonsense security platform. One central system that shows you what matters and how to fix it, from code-to-cloud.‍ Get security done 🤝 get back to building.

Secure Code Warrior

www.securecodewarrior.com/

Secure Code Warrior is a Developer Risk Management platform that transforms the way your software is created. We enable enterprises to implement new standards for secure code throughout the software development life cycle allowing the cyber security teams and CISOs to measure, mitigate and manage security risk.

We achieve this through an integrated approach: benchmarking with a Trust Score, governance via quality gates, and agile learning to cut vulnerabilities by 53%, reduce MTTR by 2-3x, lower technical debt, and accelerate development for more innovation.

SecureFlag

www.secureflag.com/support@secureflag.com

SecureFlag empowers organizations in 30 plus countries to implement secure coding training. The platform offers thousands of hands-on labs in over 45 programming languages, hosted in virtualized environments. Developers gain skills to identify and remediate vulnerabilities, building secure software from the start. Through plugins, we integrate with the Software Development Life Cycle, embedding secure practices into workflows. Our customer success team designs bespoke training programs tailored to organizational needs. SecureFlag also offers ThreatCanvas, an automated threat modeling solution enabling developers to assess and mitigate design risks independently, reducing reliance on security teams.

Security Journey

www.securityjourney.com/
Silver Exhibitors

Checkmarx

checkmarx.com/

Checkmarx helps the world’s largest enterprises get ahead of application risk without slowing down development. We end the guesswork by identifying the most critical issues to fix and give AppSec the tools they need, all while letting developers work the way they want. From DevSecOps to developer experience, security and development teams can now work better together. That’s why 1700+ customers rely on Checkmarx to scan over 1 trillion lines of code annually, improve developer productivity by 50%, and deliver 2X AppSec ROI.
Checkmarx. Always Ready To Run.

Endor Labs

www.endorlabs.com/

Endor Labs is a consolidated AppSec platform for teams that are frustrated with the status quo of “alert noise” without any real solutions. Upstarts and Fortune 500 alike use Endor Labs to make smart risk decisions. We eliminate findings that waste time (but track for transparency!), and enable AppSec and developers to fix vulnerabilities quickly, intelligently, and inexpensively. Get SCA with 92% less noise, fix code 6.2x faster, and comply with standards like FedRAMP, PCI, SLSA, and NIST SSDF.

NDC Security

ndc-security.com/info@ndcconferences.com

NDC Conferences is renowned for its highly technical events in the software development community, focusing on a wide range of topics including Security, .NET, Embedded, AI, and more. These conferences bring together industry experts, developers, and enthusiasts to share knowledge, network, and discuss the latest trends and technologies in software development.

The conferences are held in various locations around the world, such as Oslo, London, and Sydney, and feature a mix of keynote speeches, workshops, and breakout sessions. They are known for their high-quality content and engaging presentations, making them a valuable resource for anyone in the tech industry.

Phoenix Security

phoenix.security/ask@phoenix.security

Phoenix Security is an Actionable ASPM that empowers enterprises to connect security and engineering teams, delivering precise, risk-based actions from code to cloud. Our platform unifies threat intelligence, application security, and cloud security to prioritize fixes that matter most.
What makes our blood flow:
We love our clients and are trusted by industry leaders like ClearBank, LastPass, and IAS, Phoenix Security automates the discovery and attribution of assets, scales security teams’ impact by 4x, and accelerates vulnerability prioritization by 10x. With 4D risk quantification and contextual traceability, we help teams focus on fixing the right vulnerabilities first, reducing alert fatigue, and improving efficiency.

ProjectDiscovery

projectdiscovery.iosales@projcetdiscovery.io

ProjectDiscovery is revolutionizing vulnerability management with an open-source-powered solution built for modern security teams. At its core is Nuclei, a globally popular open source scanner that enables precise, exploitable vulnerability detection with zero false positives. ProjectDiscovery’s commercial offering integrates over 10 open source tools for continuous exposure monitoring, asset management, and automated security testing. With AI-generated templates and vulnerability-as-code, security teams eliminate noise, detect real threats, and shift security left. Trusted by enterprises like PepsiCo, Elastic, and Asana, ProjectDiscovery delivers actionable insights, automation, and scalability to stay ahead of today’s cyber threats.

Start-Up Exhibitors

AIceberg

aiceberg.aiinfo@aiceberg.ai

AIceberg is the only AI trust platform purpose-built with non-generative, explainable models that power safe, secure, and compliant adoption of generative and agentic AI. AIceberg monitors user prompts and model/agent responses for risk signals and enforces your security and organizational policies. We are dedicated to empowering enterprises on their AI journey—from day zero to scale—unlocking transformative value at every stage.

Akto

www.akto.io/

Akto is the best platform for appsec teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — API discovery, API security posture management, sensitive data exposure, and API security testing solutions enables organizations to gain visibility in their API security posture. 1,000+ appsec teams globally trust Akto for their API security needs.

AppSentinels

appsentinels.ai/marketing@appsentinels.ai

AppSentinels protects your APIs by securing the business logic that drives your operations. Continuous discovery, automated API pen testing, and real-time defense stop hidden threats before they disrupt your business, ensuring seamless, risk-free innovation without slowing development.

Backslash

www.backslash.security/

Backslash introduces a disruptive approach to application security by creating its App Graph, a "digital twin" of your application. App Graph organizes security findings based on business processes, shows only “triggerable” vulnerabilities, and enables simulations of the business and security impact of upgrades—without the need to apply patches and re-scan the application. Innovation-driven organizations use Backslash to dramatically improve their application security, eliminating the frustration and friction caused by legacy SAST and SCA tools.

Raven.io

raven.io/lori@raven.io

Raven helps companies protect cloud native applications by focusing on runtime.
With Raven, organizations de-prioritize over 99% of vulnerabilities with runtime reachability while preventing supply-chain attacks, cloud malware, ransomware and runtime exploits with intelligent, library-level policies.

Seal Security

www.seal.security/