VDOO, a platform that detects and fixes vulnerabilities in IoT devices, raises $32M Series B led by WRVI Capital and GGV Capital
Context & Ripple Effects
VDOO's 2019 Series B put it among the first well-funded platforms aimed specifically at finding and patching vulnerabilities in connected devices rather than enterprise networks. The bet paid off on the buyers' side of the table: within two years, DevOps company JFrog acquired VDOO for $300M — roughly nine times the round announced here — folding IoT security into a broader software delivery stack.
The raise also landed in a category that kept drawing capital: Ordr later pulled in a $40M Series C for AI-based monitoring of suspicious device behavior, showing investors funding both the prevention side (VDOO) and the detection side (Ordr) of the same device-security problem.
First-order effects
- WRVI Capital and GGV Capital take lead positions in a startup whose customers are IoT device makers that currently ship products with unpatched flaws — VDOO gets the capital to automate what those vendors do manually, if at all.
- Rival device-security startups, most directly Ordr on the monitoring side, now compete against a peer with fresh Series B money to spend on sales into the same manufacturer base.
Second-order effects
- Device makers gain a credible build-vs-buy alternative to staffing internal security teams, pressuring incumbents' consulting-led security offerings on price and speed.
- A funded, productized fix-it platform makes IoT security an acquisition target for larger software companies seeking to bundle it — the path JFrog ultimately took.
Third-order effects
- If security keeps migrating from standalone appliances into the development pipeline, the endpoint is what the later funding wave shows: code-scanning players like Legit Security and Ox Security raising large rounds as vulnerability checking becomes a feature of DevOps toolchains rather than a separate market.
- For connected-device regulation and buyer expectations, automated patching platforms lower the excuse for shipping insecure hardware, tightening the standard manufacturers are held to.
The trend: IoT security is being absorbed from a standalone product category into the software supply chain, with specialist startups either scaling independently or getting consolidated by DevOps platforms.