Skip to main content
World Wide TechnologyBenchAI tool benchmarks
Workflow Tool
StatusEmerging
SignalTracked
EvidenceGrade B

Arnica

58
C 0 vs last quarter

Pipelineless AppSec platform differentiated by the Arnie AI suite (Agentic Rules Enforcer + multi-agent AI SAST) and extended by DepsGuard, a free Rust/MIT OSS CLI (Apr 14, 2026) that hardens npm/pnpm/yarn/bun/uv configs against supply-chain attacks.

UX / DXCapabilityReliabilityValueCommunityEnterpriseAutonomyIntegration

Dimension breakdown

Score · confidence
UX / DX
50% conf40
Capability
50% conf60
ReliabilityIncomplete data at this time
Value
50% conf45
CommunityIncomplete data at this time
Enterprise / Compliance
50% conf80
Autonomy
50% conf50
Integration
50% conf70
Sources blend review platforms, community sentiment, the Signal Radar and practitioner ratings. Scores re-blend each quarter.

Pipelineless AppSec platform differentiated by the Arnie AI suite (Agentic Rules Enforcer + multi-agent AI SAST) and extended by DepsGuard, a free Rust/MIT OSS CLI (Apr 14, 2026) that hardens npm/pnpm/yarn/bun/uv configs against supply-chain attacks. AI SAST now traces taint source-to-sink across the full repository, with AI-Powered False-Positive Reduction (May 15) reasoning over codebase context; newest ship is the Snooze finding-status (May 27) for audited, time-boxed developer unblocks.

NEW (PREVIEW): 'Arnica Code Review' (PR-time AI review) was previewed at OWASP AppSec EU (June 25-26 2026) — NOT yet GA; if it ships GA it would lift integration toward band 4 (currently 14). Audit Log remains Enterprise Early Access (90-day rolling), not GA. Agentic Rules Enforcer injects security policy into Claude, Cursor, Copilot, and Gemini at generation time — no IDE plugin or CI pipeline required.

SOC 2 Type 2 + ISO 27001, on-prem deployment, SAML v2 + RBAC, AWS Marketplace procurement. Frost Radar 2025 Leader; added to Gartner's 2026 Hype Cycle for Platform Engineering; Gartner Peer Insights 4.6/5 (admin UX is the recurring critique).

Caution

funding picture unresolved — vendor press confirms only the $7M Oct-2022 seed and no Series A, so PitchBook's $21.1M figure stays [Unverified]; headcount conflicts across aggregators (PitchBook 23 / Tracxn 11-50 / StartupHub 58).

Near-zero Reddit/HN footprint and no independent AI SAST benchmark.

Recommended

Use cases

Not yet assessed — this section fills in as ACES research covers the tool.

Score caps

Risk flags

No active caps — no risk flags apply to this tool right now.

Assessment

Status rationale

Tracked status unchanged under the Opus 4.8 re-baseline. Novel agentic security enforcement (Agentic Rules Enforcer + multi-agent AI SAST) remains technically differentiated; enterprise-grade compliance posture (SOC 2 Type 2 + ISO 27001 + on-prem + SAML/RBAC + AWS Marketplace) remains strong; product velocity is healthy (Snooze May 27, AI-Powered False-Positive Reduction May 15, AI SAST Multi-File May 14, plus the Apr 14 DepsGuard OSS launch).

Analyst recognition broadened (Frost Radar 2025 Leader; Gartner 2026 Hype Cycle for Platform Engineering). However, the company remains small with conflicting headcount data, the funding picture stays contested ($7M Crunchbase/primary-confirmed vs. $21.1M PitchBook still unverified), it is absent from independent AI SAST benchmark roundups, and direct community presence is near-zero (no significant Reddit/HN footprint).

No band changes, no caps triggered, score delta below threshold — remains Tracked, rating 63. Evidence grade lifts C → B on thorough full-research depth and a fresh evaluation date.

Watch for

Movement triggers

Upgrade to Watch if: PitchBook $21.1M funding figure is independently corroborated by primary source (vendor press release or TechCrunch coverage), AI SAST accuracy independently validated by third-party benchmark (EASE/MITRE/SecurityWeek), DepsGuard CLI architecture extended to core scanning interface, headcount stabilizes or grows with named enterprise hiring, Audit Log reaches GA, broader community visibility in Reddit/HN/analyst reports.

Watch

'Arnica Code Review' (PR-time AI review, previewed at OWASP AppSec EU June 25-26 2026) reaching GA would lift integration toward band 4 — upgrade integration dim on confirmed GA with positive adoption signal.

Downgrade if: layoff signals emerge, key personnel depart (especially Nir Valtman/CEO), development velocity stalls (no announcements for 90+ days), accuracy complaints emerge in community channels, or pricing opacity creates customer churn.

Caution

Risks & limitations

Not yet assessed — this section fills in as ACES research covers the tool.

Capabilities

Integration surface

Not yet assessed — this section fills in as ACES research covers the tool.

Proof points

Adoption & benchmarks

Not yet assessed — this section fills in as ACES research covers the tool.

Spotted something wrong or missing here? Suggest a change →

Per-source contributions

Click any dimension to see the underlying sources and citations.