PortSwigger, the startup behind the Burp Suite of security testing tools founded by security expert “Daf”, raised $112M, its first outside investment
Sometimes the most successful startup ideas come from people building tools to solve their own needs.
Context & Ripple Effects
PortSwigger’s funding arrives as security-tool vendors are attracting capital around different parts of the vulnerability-management stack. Socket had already raised a $20M Series A for open-source vulnerability scanning, highlighting investor interest in tools aimed at finding software risk.
The distinction matters: PortSwigger is the developer of Burp Suite, while Socket’s focus is open-source code. The new funding gives a long-standing testing-tool maker its first external capital base rather than extending a prior venture-backed financing sequence.
First-order effects
- PortSwigger gains $112M of outside funding, giving the company new resources to support the Burp Suite business and its security-testing users.
- The investment establishes an external investor relationship for a company that had previously not taken outside funding, changing its ownership and operating context.
Second-order effects
- The round strengthens the case for funding specialized security products alongside newer vulnerability-scanning vendors such as Socket’s open-source security platform.
- Security buyers may see more vendor investment across adjacent testing and code-vulnerability workflows, increasing pressure for tools to show where they fit in a customer’s security stack.
Third-order effects
- If comparable investments continue, security tooling could become more segmented by the type of risk and development workflow each product addresses, rather than consolidating around a single broad category.
- The pattern points to a market where established, founder-built tools can become institutionalized businesses without necessarily originating as venture-backed startups.
The trend: Security investment is increasingly backing focused tools for distinct software-risk workflows, including companies that reach scale before taking external capital.