DryRun Security
AI-native contextual security for every pull request — catch exploitable risks before they merge, not after.
Overview
DryRun Security is an AI-native AppSec platform whose Contextual Security Analysis engine traces cross-file data flow to catch exploitable risk, posting inline PR findings in about a minute. Founded 2023, it processes 250,000+ code reviews monthly for customers like Gusto and PlanetArt.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- GitHub integration
- Basic scans on pull requests
- Limited monthly code reviews
- Full contextual security analysis
- Annual billing discounts
- Free security assessment to start
- Tailored scope and support
- Pricing via sales only
Use cases
What you can produce with DryRun Security
- Inline PR security findings with precise code references posted within approximately one minute of PR creation
- Executive summary reports for AppSec teams alongside developer-facing remediation guidance
- Custom policy enforcement in pull requests via Natural Language Code Policies (launched January 2025) with no regex required
- Full-codebase DeepScan reports via the AI DeepScan Agent launched in February 2026
- Secrets detection across code changes and repository history
- Infrastructure-as-Code security analysis integrated into the PR workflow
- Natural language codebase querying via Code Insights MCP for AI assistant integration
ASEAN Perspective
DryRun Security in Southeast Asia
DryRun Security has no confirmed APAC office, ASEAN customer references, or regional data residency commitments as of mid-2026. The platform is cloud-hosted and US-centric in its go-to-market, which raises data sovereignty considerations for regulated industries in Singapore (MAS TRM), Indonesia (OJK), and the broader region. That said, the GitHub and GitLab integration model means any ASEAN engineering team already on those platforms can onboard without geographic friction — the tool is usable today, but buyers should conduct their own due diligence on data processing jurisdiction and contractual obligations before deployment in regulated ASEAN environments.
DryRun Security's pitch — trace actual data flow instead of matching regex patterns — holds up under testing. Its own 2025 SAST Accuracy Report caught 23 of 26 seeded vulnerabilities across four public benchmarks (Rails, Django, C#, Spring Boot), beating Semgrep, Snyk Code, CodeQL, and SonarQube, none of which cleared half. SOC 2 Type II certification and Natural Language Code Policies — plain-English rules instead of regex maintenance — round out a genuinely enterprise-ready package for a company barely three years old.
The caveats track its stage: DryRun is a seed-funded startup ($8.7M raised January 2025), so long-term stability and support depth at real enterprise scale are still unproven next to Snyk or Semgrep. Pricing isn't published anywhere. Customers named publicly — Gusto, BrightHR, PlanetArt — are all North American, and there's no confirmed APAC data-residency option, so teams in Singapore or Indonesia should confirm jurisdiction before signing.
What people say
23 of 26 seeded vulnerabilities — that's DryRun Security's own tally from its 2025 SAST Accuracy Report, run across four public benchmarks (RailsGoat, a vulnerable task manager, a C# API, and a Spring Boot app) against Semgrep, Snyk Code, GitHub Advanced Security, and SonarQube. None of the competitors cracked half. G2 named it a High Performer in SAST for Spring 2026, with an overall rating of 4.9 out of 5.
Reviewers keep coming back to the same point: because DryRun traces how new code actually interacts with auth logic and data flow instead of pattern-matching, the noise-to-signal ratio drops sharply compared to older SAST tools. Setup is a one-time GitHub or GitLab install, findings show up inline on the pull request within about a minute, and Natural Language Code Policies (added in 2025) let security teams write enforcement rules in plain English instead of maintaining regex.
The company is young — founded in 2023 by former Signal Sciences and GitHub security engineers, running on an $8.7M seed round closed in January 2025 — and it shows in a few places. Pricing isn't published, the publicly named customer base (Gusto, BrightHR, PlanetArt) skews North American, and there's no confirmed APAC data-residency option. As of January 2026 the company reported processing more than 250,000 code reviews a month across its customer base.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- DryRun Security won the OWASP Global DC 2023 Most Innovative Startup award in its very first year out of stealth.
- Co-founder Ken Johnson's path to AppSec began in the US Navy as an IT specialist, and his first civilian security role was at the Pentagon.
- The platform's Contextual Security Analysis engine can complete a full PR review and post inline findings in approximately one minute.
- DryRun Security's 2025 SAST Accuracy Report result — 88% of seeded vulnerabilities detected — beat five established static analysis tools that had been building rule libraries for years.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including DryRun Security's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with DryRun Security unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to DryRun Security directly →
Spotted something out of date? Suggest an update →
DryRun Security in the news
Cybersecurity
Miasma Returns With 'Phantom Gyp': npm Worm Sidesteps the Install-Script Defences Teams Ju...
Developer Tools
Miasma: How a Hijacked CI Pipeline Shipped Malicious npm Packages With Valid Provenance
Cybersecurity
Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub A...
More in Security & Safety