DryRun Security

AI-native contextual security for every pull request — catch exploitable risks before they merge, not after.

Security & Safety Freemium Has API
Researched · Published · Reviewed
RECATOOLS Score
8.1 / 10
Capability
8.8
Value for money
7.5
Ease of use
8.5
ASEAN readiness
5.5
API quality
7.8
Founded
2023
HQ
Austin, Texas, USA
Users
Customers ran 250,000+ code reviews/month as of early 2025; customer count undisclosed
Launched
Emerged from stealth May 23, 2023
Developer
James Wickett (CEO) and Ken Johnson (CTO)

Overview

DryRun Security is an AI-native AppSec platform whose Contextual Security Analysis engine traces cross-file data flow to catch exploitable risk, posting inline PR findings in about a minute. Founded 2023, it processes 250,000+ code reviews monthly for customers like Gusto and PlanetArt.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Free
Free
Free GitHub app for basic AI-native code security review
  • GitHub integration
  • Basic scans on pull requests
  • Limited monthly code reviews
Enterprise
Custom
Custom contract for larger organisations
  • Tailored scope and support
  • Pricing via sales only

Use cases

Automatically reviewing every pull request for exploitable security vulnerabilities before code is merged Replacing or augmenting manual AppSec code review workflows at high-velocity engineering teams Enforcing custom security policies using Natural Language Code Policies without rule scripting Detecting secrets, IDOR, SQL injection, XSS, and SSRF in AI-generated code from Copilot, Codex, or Cursor Providing developer-friendly remediation guidance inline in PRs to build secure coding habits without context-switching

What you can produce with DryRun Security

  • Inline PR security findings with precise code references posted within approximately one minute of PR creation
  • Executive summary reports for AppSec teams alongside developer-facing remediation guidance
  • Custom policy enforcement in pull requests via Natural Language Code Policies (launched January 2025) with no regex required
  • Full-codebase DeepScan reports via the AI DeepScan Agent launched in February 2026
  • Secrets detection across code changes and repository history
  • Infrastructure-as-Code security analysis integrated into the PR workflow
  • Natural language codebase querying via Code Insights MCP for AI assistant integration
Advertisement

ASEAN Perspective

DryRun Security in Southeast Asia

DryRun Security has no confirmed APAC office, ASEAN customer references, or regional data residency commitments as of mid-2026. The platform is cloud-hosted and US-centric in its go-to-market, which raises data sovereignty considerations for regulated industries in Singapore (MAS TRM), Indonesia (OJK), and the broader region. That said, the GitHub and GitLab integration model means any ASEAN engineering team already on those platforms can onboard without geographic friction — the tool is usable today, but buyers should conduct their own due diligence on data processing jurisdiction and contractual obligations before deployment in regulated ASEAN environments.

RECATOOLS Verdict

DryRun Security's pitch — trace actual data flow instead of matching regex patterns — holds up under testing. Its own 2025 SAST Accuracy Report caught 23 of 26 seeded vulnerabilities across four public benchmarks (Rails, Django, C#, Spring Boot), beating Semgrep, Snyk Code, CodeQL, and SonarQube, none of which cleared half. SOC 2 Type II certification and Natural Language Code Policies — plain-English rules instead of regex maintenance — round out a genuinely enterprise-ready package for a company barely three years old.

The caveats track its stage: DryRun is a seed-funded startup ($8.7M raised January 2025), so long-term stability and support depth at real enterprise scale are still unproven next to Snyk or Semgrep. Pricing isn't published anywhere. Customers named publicly — Gusto, BrightHR, PlanetArt — are all North American, and there's no confirmed APAC data-residency option, so teams in Singapore or Indonesia should confirm jurisdiction before signing.

Independent AI-assisted assessment by RECATOOLS.

What people say

23 of 26 seeded vulnerabilities — that's DryRun Security's own tally from its 2025 SAST Accuracy Report, run across four public benchmarks (RailsGoat, a vulnerable task manager, a C# API, and a Spring Boot app) against Semgrep, Snyk Code, GitHub Advanced Security, and SonarQube. None of the competitors cracked half. G2 named it a High Performer in SAST for Spring 2026, with an overall rating of 4.9 out of 5.

Reviewers keep coming back to the same point: because DryRun traces how new code actually interacts with auth logic and data flow instead of pattern-matching, the noise-to-signal ratio drops sharply compared to older SAST tools. Setup is a one-time GitHub or GitLab install, findings show up inline on the pull request within about a minute, and Natural Language Code Policies (added in 2025) let security teams write enforcement rules in plain English instead of maintaining regex.

The company is young — founded in 2023 by former Signal Sciences and GitHub security engineers, running on an $8.7M seed round closed in January 2025 — and it shows in a few places. Pricing isn't published, the publicly named customer base (Gusto, BrightHR, PlanetArt) skews North American, and there's no confirmed APAC data-residency option. As of January 2026 the company reported processing more than 250,000 code reviews a month across its customer base.

Summary of public user & expert reviews, compiled by RECATOOLS.

Notable facts

  • DryRun Security won the OWASP Global DC 2023 Most Innovative Startup award in its very first year out of stealth.
  • Co-founder Ken Johnson's path to AppSec began in the US Navy as an IT specialist, and his first civilian security role was at the Pentagon.
  • The platform's Contextual Security Analysis engine can complete a full PR review and post inline findings in approximately one minute.
  • DryRun Security's 2025 SAST Accuracy Report result — 88% of seeded vulnerabilities detected — beat five established static analysis tools that had been building rule libraries for years.

Frequently asked questions

How is DryRun Security different from traditional SAST tools like Semgrep or SonarQube?
Traditional SAST tools match code patterns against rule libraries, which produces high false-positive rates and requires ongoing rule maintenance. DryRun Security uses Contextual Security Analysis to trace data flow across files and microservices and evaluate whether a vulnerability is actually exploitable in context — the company claims 2x more accuracy and 90% less noise. Natural Language Code Policies also let teams enforce custom security rules in plain English without writing regex.
What source code management platforms and languages does DryRun Security support?
DryRun Security integrates natively with GitHub and GitLab, connects with Slack and Jira, and extends to AI coding tools including Claude Code, Cursor, and OpenAI Codex via MCP. Supported languages include Python, Ruby, TypeScript, JavaScript, Java, Go, C#, C++, PHP, HTML, Elixir, Kotlin, Swift, and Scala.
Is there a free plan, and what are the limitations?
Yes, a free tier covers basic security scans, GitHub integration, and a limited number of monthly code reviews — suitable for individual developers or small teams evaluating the platform. A Pro plan unlocks unlimited reviews, advanced contextual analysis, GitLab and Slack integration, and priority support; pricing is not officially published but third-party aggregators cite approximately $49/month. Enterprise plans with custom pricing, compliance reporting, and optional on-premises deployment are available on request.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including DryRun Security's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with DryRun Security unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to DryRun Security directly →

Spotted something out of date? Suggest an update →

Advertisement