Arnica
Pipelineless AppSec platform differentiated by the Arnie AI suite (Agentic Rules Enforcer + multi-agent AI SAST) and extended by DepsGuard, a free Rust/MIT OSS CLI (Apr 14, 2026) that hardens npm/pnpm/yarn/bun/uv configs against supply-chain attacks.
Dimension breakdown
Score · confidencePipelineless AppSec platform differentiated by the Arnie AI suite (Agentic Rules Enforcer + multi-agent AI SAST) and extended by DepsGuard, a free Rust/MIT OSS CLI (Apr 14, 2026) that hardens npm/pnpm/yarn/bun/uv configs against supply-chain attacks. AI SAST now traces taint source-to-sink across the full repository, with AI-Powered False-Positive Reduction (May 15) reasoning over codebase context; newest ship is the Snooze finding-status (May 27) for audited, time-boxed developer unblocks.
NEW (PREVIEW): 'Arnica Code Review' (PR-time AI review) was previewed at OWASP AppSec EU (June 25-26 2026) — NOT yet GA; if it ships GA it would lift integration toward band 4 (currently 14). Audit Log remains Enterprise Early Access (90-day rolling), not GA. Agentic Rules Enforcer injects security policy into Claude, Cursor, Copilot, and Gemini at generation time — no IDE plugin or CI pipeline required.
SOC 2 Type 2 + ISO 27001, on-prem deployment, SAML v2 + RBAC, AWS Marketplace procurement. Frost Radar 2025 Leader; added to Gartner's 2026 Hype Cycle for Platform Engineering; Gartner Peer Insights 4.6/5 (admin UX is the recurring critique).
funding picture unresolved — vendor press confirms only the $7M Oct-2022 seed and no Series A, so PitchBook's $21.1M figure stays [Unverified]; headcount conflicts across aggregators (PitchBook 23 / Tracxn 11-50 / StartupHub 58).
Near-zero Reddit/HN footprint and no independent AI SAST benchmark.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
No active caps — no risk flags apply to this tool right now.
Status rationale
Tracked status unchanged under the Opus 4.8 re-baseline. Novel agentic security enforcement (Agentic Rules Enforcer + multi-agent AI SAST) remains technically differentiated; enterprise-grade compliance posture (SOC 2 Type 2 + ISO 27001 + on-prem + SAML/RBAC + AWS Marketplace) remains strong; product velocity is healthy (Snooze May 27, AI-Powered False-Positive Reduction May 15, AI SAST Multi-File May 14, plus the Apr 14 DepsGuard OSS launch).
Analyst recognition broadened (Frost Radar 2025 Leader; Gartner 2026 Hype Cycle for Platform Engineering). However, the company remains small with conflicting headcount data, the funding picture stays contested ($7M Crunchbase/primary-confirmed vs. $21.1M PitchBook still unverified), it is absent from independent AI SAST benchmark roundups, and direct community presence is near-zero (no significant Reddit/HN footprint).
No band changes, no caps triggered, score delta below threshold — remains Tracked, rating 63. Evidence grade lifts C → B on thorough full-research depth and a fresh evaluation date.
Movement triggers
Upgrade to Watch if: PitchBook $21.1M funding figure is independently corroborated by primary source (vendor press release or TechCrunch coverage), AI SAST accuracy independently validated by third-party benchmark (EASE/MITRE/SecurityWeek), DepsGuard CLI architecture extended to core scanning interface, headcount stabilizes or grows with named enterprise hiring, Audit Log reaches GA, broader community visibility in Reddit/HN/analyst reports.
'Arnica Code Review' (PR-time AI review, previewed at OWASP AppSec EU June 25-26 2026) reaching GA would lift integration toward band 4 — upgrade integration dim on confirmed GA with positive adoption signal.
Downgrade if: layoff signals emerge, key personnel depart (especially Nir Valtman/CEO), development velocity stalls (no announcements for 90+ days), accuracy complaints emerge in community channels, or pricing opacity creates customer churn.
Risks & limitations
Not yet assessed — this section fills in as ACES research covers the tool.
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category