Salt Security, which develops tools that discover APIs and detect vulnerabilities, raises $30M Series B led by Sequoia Capital
Salt Security, which is developing a threat protection solution that discovers APIs and detects vulnerabilities, today raised $30 million.
Context & Ripple Effects
Salt Security is moving fast through the funding ladder: six months after its $20M Series A led by Tenaya Capital, it closes a $30M Series B with Sequoia Capital — a step up in lead investor tier for a company building AI-based API discovery and threat protection. Sequoia's bet lands in an application-security market where runtime-focused players like ShiftLeft have been raising since 2019, but API-specific defense is still being defined.
The round matters because the category it anchors is about to get crowded and expensive: Noname Security will reach a $1B valuation on a $135M Series C barely a year later, and Salt itself will keep compounding through a $70M Advent-led round and a $140M Series D at a $1.4B valuation.
First-order effects
- Salt Security gains both capital and Sequoia's brand validation, accelerating development of its API discovery and vulnerability detection platform against a rival set that includes Noname Security.
- Sequoia adds Salt to an application-security portfolio alongside earlier bets on pre-runtime scanning (ShiftLeft), positioning it across the code-to-runtime spectrum.
Second-order effects
- Noname Security's rapid ascent to a $1B valuation forces a capital-arms race in API security, with Salt's subsequent $70M and $140M rounds showing how quickly pricing for category leaders inflates.
- Adjacent appsec vendors such as Legit Security — which raised a $40M Series B for code-level vulnerability identification — face pressure to extend from code scanning toward the runtime API surface Salt and Noname cover.
Third-order effects
- If the funding pattern holds, API security consolidates from a feature inside broader appsec platforms into a standalone category with its own valuation benchmarks, squeezing point tools that cover only code or only runtime.
- Discovery-first architectures — mapping every API before defending it — become the category's baseline requirement, raising the bar for later entrants.
The trend: API security is separating from general application security as a capital-intensive, discovery-first category, with Salt Security and Noname Security racing to define its benchmarks.