Startups

Valence Security raises new cash to secure the SaaS app supply chain

Comment

padlock over digital background depicting innovative technologies in security systems, data protection Internet technologies
Image Credits: MF3d / Getty Images

Valence Security, a company securing business app infrastructure, today announced that it raised $25 million in a Series A round led by M12, Microsoft’s corporate venture arm, with participation from YL Ventures, Porsche Ventures, Akamai Technologies, Alumni Ventures and former Symantec CEO Michael Fey. The new capital brings the company’s total raised to $32 million, and co-founder Shlomi Matichin says it’ll be put toward product development and doubling Valence’s 25-person headcount by the end of the year.

Matichin co-founded Valence Security with Yoni Shohet in 2021. A two-time entrepreneur, Shohet previously co-launched SCADAfence, an industrial Internet of Things security startup. Matichin, for his part, was one of the founding members of Capester, a platform for cataloging videos of civic violations.

“In recent years, malicious actors have placed their focus on the interconnectivity between software-as-a-service (SaaS) applications, leveraging its potential for their attack campaigns,” Matichin told TechCrunch in an email interview. “Organizations struggle to secure this [app] mesh — a growing, complex and interconnected environment of SaaS apps, third-party integrations, identities, privileges and data.”

Matichin and Shohet built Valence to address these challenges around visibility into the SaaS supply chain, including misconfigurations, risk prioritization and remediation. The platform attempts to detect all of a company’s SaaS apps and contextualize them with vendor risk assessments, offering tools to spot improperly configured security controls and drifts from established policies.

Valence can also help manage risky, inactive and overprivileged authentication keys, third-party integrations and no- and low-code workflows, Matichin says — in addition to potentially insecure public-facing files and emails forwarded externally. Identity security flows within Valence, meanwhile, aim to ensure users are managed by a central identity provider, using multi-factor authentication and are properly offboarded.

According to Matichin, driving the demand for these services is the increasing threats companies face — and general SaaS app sprawl. The average enterprise uses around 80 SaaS apps, with BetterCloud estimating that businesses with more than 1,000 employees use more than 150 apps. This opens firms to attack. According to a Dimensional Research survey commissioned by ReversingLabs, a cybersecurity vendor, just over half (51%) of IT security teams report being able to protect their software from supply chain attacks.

The impact of such attacks can be devastating. In a recent paper, Kaspersky estimated the cost of a supply chain software attack to an enterprise at $1.4 million. That doesn’t factor in the lost revenue from additional downtime arising during remediation, which can substantially add to costs (to the tune of thousands to millions of dollars) and affect a firm’s reputation.

“Beyond security concerns, the repercussions of SaaS supply chain attacks are at the top of business priorities in light of the growing number of high-profile SaaS supply breaches over the past two years,” Matichin said. “These breaches can expose multiple interconnected SaaS applications for a single organization as well as threaten the business-critical data stored in those applications. This risk to business objectives, as well as to business continuity and efficiency due to the significant impact these breaches have on SaaS use, should be top-of-mind for the C-suite.”

Tel Aviv-based Valence competes with a number of vendors in the supply chain SaaS app security space, including Canonic Security, Atmosec (which has raised $6 million), Astrix Security ($15 million), Wing Security ($26 million), AppOmni ($123 million), Obsidian Security ($119.5 million) and Adaptive Shield ($34 million). When asked whether that concerned him, Matichin responded by highlighting what he sees as a growing need for visibility and control over SaaS assets and remediation of the risks.

“As remote working conditions accelerated the adoption and use of SaaS applications, a unique and unaddressed risk surface uncovered a growing need for SaaS security solutions targeting the sprawling SaaS mesh,” Matichin said. “In this respect, Valence was strongly positioned to address the unique security and business needs at the height of the pandemic, [and] Valence will continue to set the standard for SaaS security going forward.”

Matichin didn’t reveal the size of Valence’s customer base or projected revenue. But even if it’s lower than that of the company’s close competitors, VCs seem ready and willing to throw their weight behind security vendors. In the first half of 2022, there was $12.5 billion in venture capital invested across more than 530 deals, according to a report from investment firm Momentum Cyber — in line with H1 2021’s $12.6 billion invested.

More TechCrunch

French AI startup Mistral is introducing new AI model customization options, including paid plans, to let developers — and enterprises — fine-tune its generative models for particular use cases. The…

Mistral launches new services, SDK to let customers fine-tune its models

The warning for the Ai Pin was issued “out of an abundance of caution,” according to Humane.

Humane urges customers to stop using charging case, citing battery fire concerns

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Welcome to Elon Musk’s X. The social network formerly known as Twitter where the rules are made up and the check marks don’t matter. Or do they? The Tesla and…

Elon Musk’s X: A complete timeline of what Twitter has become

TechCrunch has kept readers informed regarding Fearless Fund’s courtroom battle to provide business grants to Black women. Today, we are happy to announce that Fearless Fund CEO and co-founder Arian…

Fearless Fund’s Arian Simone coming to Disrupt 2024

Bridgy Fed is one of the efforts aimed at connecting the fediverse with the web, Bluesky and, perhaps later, other networks like Nostr.

Bluesky and Mastodon users can now talk to each other with Bridgy Fed

Zoox, Amazon’s self-driving unit, is bringing its autonomous vehicles to more cities.  The self-driving technology company announced Wednesday plans to begin testing in Austin and Miami this summer. The two…

Zoox to test self-driving cars in Austin and Miami 

Called Stable Audio Open, the generative model takes a text description and outputs a recording up to 47 seconds in length.

Stability AI releases a sound generator

It’s not just instant-delivery startups that are struggling. Oda, the Norway-based online supermarket delivery startup, has confirmed layoffs of 150 jobs as it drastically scales back its expansion ambitions to…

SoftBank-backed grocery startup Oda lays off 150, resets focus on Norway and Sweden

Newsletter platform Substack is introducing the ability for writers to send videos to their subscribers via Chat, its private community feature, the company announced on Wednesday. The rollout of video…

Substack brings video to its Chat feature

Hiya, folks, and welcome to TechCrunch’s inaugural AI newsletter. It’s truly a thrill to type those words — this one’s been long in the making, and we’re excited to finally…

This Week in AI: Ex-OpenAI staff call for safety and transparency

Ms. Rachel isn’t a household name, but if you spend a lot of time with toddlers, she might as well be a rockstar. She’s like Steve from Blues Clues for…

Cameo fumbles on Ms. Rachel fundraiser as fans receive credits instead of videos  

Cartwheel helps animators go from zero to basic movement, so creating a scene or character with elementary motions like taking a step, swatting a fly or sitting down is easier.

Cartwheel generates 3D animations from scratch to power up creators

The new tool, which is set to arrive in Wix’s app builder tool this week, guides users through a chatbot-like interface to understand the goals, intent and aesthetic of their…

Wix’s new tool taps AI to generate smartphone apps

ClickUp Knowledge Management combines a new wiki-like editor and with a new AI system that can also bring in data from Google Drive, Dropbox, Confluence, Figma and other sources.

ClickUp wants to take on Notion and Confluence with its new AI-based Knowledge Base

New York City, home to over 60,000 gig delivery workers, has been cracking down on cheap, uncertified e-bikes that have resulted in battery fires across the city.  Some e-bike providers…

Whizz wants to own the delivery e-bike subscription space, starting with NYC

This is the last major step before Starliner can be certified as an operational crew system, and the first Starliner mission is expected to launch in 2025. 

Boeing’s Starliner astronaut capsule is en route to the ISS 

TechCrunch Disrupt 2024 in San Francisco is the must-attend event for startup founders aiming to make their mark in the tech world. This year, founders have three exciting ways to…

Three ways founders can shine at TechCrunch Disrupt 2024

Google’s newest startup program, announced on Wednesday, aims to bring AI technology to the public sector. The newly launched “Google for Startups AI Academy: American Infrastructure” will offer participants hands-on…

Google’s new startup program focuses on bringing AI to public infrastructure

eBay’s newest AI feature allows sellers to replace image backgrounds with AI-generated backdrops. The tool is now available for iOS users in the U.S., U.K., and Germany. It’ll gradually roll…

eBay debuts AI-powered background tool to enhance product images

If you’re anything like me, you’ve tried every to-do list app and productivity system, only to find yourself giving up sooner than later because sooner than later, managing your productivity…

Hoop uses AI to automatically manage your to-do list

Asana is using its work graph to train LLMs with the goal of creating AI assistants that work alongside human employees in company workflows.

Asana introduces ‘AI teammates’ designed to work alongside human employees

Taloflow, an early stage startup changing the way companies evaluate and select software, has raised $1.3M in a seed round.

Taloflow puts AI to work on software vendor selection to reduce costs and save time

The startup is hoping its durable filters can make metals refining and battery recycling more efficient, too.

SiTration uses silicon wafers to reclaim critical minerals from mining waste

Spun out of Bosch, Dive wants to change how manufacturers use computer simulations by both using modern mathematical approaches and cloud computing.

Dive goes cloud-native for its computational fluid dynamics simulation service

The tension between incumbents and fintechs has existed for decades. But every once in a while, the two groups decide to put their competition aside and work together. In an…

When foes become friends: Capital One partners with fintech giants Stripe, Adyen to prevent fraud

After growing 500% year-over-year in the past year, Understory is now launching a product focused on the renewable energy sector.

Insurance provider Understory gets into renewable energy following $15M Series A

Ashkenazi will start her new role at Google’s parent company on July 31, after 23 years at Eli Lilly.

Alphabet brings on Eli Lilly’s Anat Ashkenazi as CFO

Tobiko aims to reimagine how teams work with data by offering a dbt-compatible data transformation platform.

With $21.8M in funding, Tobiko aims to build a modern data platform