Salt Security, an API vulnerability and protection service, raises a $140M Series D led by CapitalG at a $1.4B valuation, bringing its total funding to $271M
Salt Security, an API vulnerability and protection platform used by companies such as Equinix and Telefónica, has raised $140 million in a series D round of funding.
Context & Ripple Effects
Salt Security has compressed its funding arc dramatically: from a $20M Series A in mid-2020, to a $70M Series C under a year later, and now a $140M Series D led by CapitalG at a $1.4B valuation — $271M raised in under two years for its AI-based API discovery and protection platform.
The round lands two months after rival Noname Security's $135M raise at a $1B valuation, confirming API protection as a separately funded category rather than a feature of broader appsec tooling. Salt's customer roster already includes Equinix and Telefónica, both of which are expanding their own infrastructure and network footprints, giving the startup reference accounts in exactly the sectors building out more APIs.
First-order effects
- Salt Security gains $140M to scale its API vulnerability and protection platform across an enterprise base that already runs it at Equinix and Telefónica.
- CapitalG leading the round marks a step up from earlier backers Tenaya, Sequoia, and Advent, moving Salt firmly into late-stage growth territory at a tenfold-plus jump in cumulative funding.
Second-order effects
- Noname Security, which reached a $1B valuation on its own $135M round just two months ago, now faces a better-capitalized direct competitor and pressure to match Salt's funding pace and product breadth.
- Enterprise buyers like Equinix and Telefónica gain a vendor with runway to deepen platform investment, raising the bar for smaller API-security point tools competing for the same budgets.
Third-order effects
- If the Salt–Noname escalation pattern holds, API security hardens into a distinct procurement category where large enterprises consolidate spending around AI-based discovery platforms instead of bolting API checks onto legacy application-security suites.
The trend: API security is emerging as a standalone, heavily capitalized category, with rival platforms racing through mega-rounds within months of each other.