ProjectDiscovery, a free vulnerability scanning service that monitors websites, apps, APIs, and cloud services for exploits, raised a $25M Series A led by CRV
Context & Ripple Effects
ProjectDiscovery enters a vulnerability-management market that already spans Detectify's ethical-hacker-powered scanning and Bugcrowd's researcher-mediated disclosure model, alongside tools that find flaws earlier in the software lifecycle.
Subsequent funding for Legit Security's code-level vulnerability platform underscores investor interest in covering more of the application-security workflow, from code through deployed services.
First-order effects
- The financing gives ProjectDiscovery added capacity to develop and operate its free scanning service across websites, applications, APIs and cloud services.
- CRV adds an application-security investment focused on broad vulnerability discovery rather than a single testing or disclosure channel.
Second-order effects
- Scanner vendors and adjacent AppSec platforms face greater pressure to differentiate through where they scan, how findings are prioritized and how their tools fit developer workflows.
- Security teams evaluating vulnerability tools gain another funded provider spanning multiple deployed-service surfaces, increasing the importance of integrating findings rather than simply generating more alerts.
Third-order effects
- If broad scanning becomes a baseline capability, value may shift toward consolidating, prioritizing and remediating findings—the layer represented by ArmorCode's vulnerability-data consolidation approach.
- The market could increasingly organize around connected application-security workflows that link discovery across code and deployed infrastructure, rather than isolated point scanners.
The trend: Application security is moving toward continuous, cross-surface vulnerability management that connects discovery with prioritization and remediation.