Bishop Fox, which offers tools for dynamic application security testing, has raised a $75M Series B led by Carrick Capital Partners
Context & Ripple Effects
Bishop Fox's $75M Series B lands mid-wave in application security tooling: two months earlier, Bright Security raised a $20M Series A for dynamic app security testing, and Bionic followed with a $65M Series B after coming out of stealth with $17M in late 2020. The category is drawing increasingly large checks at each stage.
The raise also extends a broader security-funding arc that includes SecurityScorecard's $180M Series E in 2021 and Testim's earlier automated-testing round — investors are treating automated testing of running applications as a distinct, fundable market rather than a feature of broader security platforms.
First-order effects
- Bishop Fox gains the capital to scale its dynamic application security testing business, while lead investor Carrick Capital Partners takes a significant position in one of the better-funded players in the DAST segment.
- Bright Security and other DAST-focused startups now face a rival with roughly 3-4x their most recent round size, changing the resource balance in head-to-head enterprise deals.
Second-order effects
- Competitors in dynamic and application-layer testing will be pushed toward larger rounds or differentiated positioning to keep pace, continuing the escalation visible from Bright's $20M to Bionic's $65M to Bishop Fox's $75M.
- Enterprise security buyers gain negotiating leverage as funded vendors compete on coverage and bundling, pressuring pricing across the automated appsec testing category.
Third-order effects
- If the funding cadence holds, application security testing consolidates around a handful of heavily capitalized platform vendors, squeezing out sub-scale point tools much as security ratings did around SecurityScorecard's late-stage raise.
- Sustained capital inflows into automated testing signal that continuous security validation of live applications is becoming a standard line item in enterprise budgets rather than an optional add-on.
The trend: Venture capital is concentrating behind automated application security testing, with round sizes escalating rapidly as enterprises shift from periodic scans to continuous validation of running software.