In an exclusive interview with VMblog, James Wickett, co-founder and CEO of DryRun Security, reveals how the company is revolutionizing application security through its innovative Contextual Security Analysis platform. Fresh off an $8.7 million seed funding round led by LiveOak Ventures and Work-Bench, DryRun Security is tackling one of the biggest challenges facing AppSec teams today: identifying critical security risks in real-time during the code review process. By leveraging LLM-native technology to analyze pull requests and provide contextual security insights, the company helps development teams catch potential vulnerabilities before they reach production, while eliminating the noise and false positives that plague traditional security tools.
VMblog: As we begin, can you tell
readers what DryRun Security does?
James Wickett: At DryRun Security, we
help Application Security (AppSec) teams spot unknown risks before they ever
make it into production. We do this by analyzing pull requests in real-time,
using Contextual Security Analysis-our LLM-native approach to code analysis-to
highlight the critical changes that deserve a closer look. In other words, we
find the “needle in the haystack” for code reviews, so security teams can stay
ahead of vulnerabilities instead of playing catch-up.
We’ve
also made it straightforward for security teams and developers to collaborate.
Our Natural Language Code Policies let you create security checks without
complex scripting, so you can easily question critical areas-like how payments
are processed or how authentication flows are changed-and receive real-time
alerts. It’s all about empowering companies to ship secure software quickly,
without drowning developers in noise.
VMblog: Congratulations on your
recent funding! How much did you raise and from whom? Also, what do you plan to
do with the money?
Wickett: Thank
you! DryRun Security recently raised $8.7 million seed funding round from lead
investors LiveOak Ventures and Work-Bench as well as participation from Cannage
Capital. We plan to use the investment to increase engineering hires and grow
the Go To Market (GTM) function of the company.
VMblog: What problem does DryRun
Security solve?
Wickett: The core issue for most
AppSec teams is knowing which code merges truly merit a closer look. With
hundreds of changes happening daily, critical risks can easily slip by
undetected. At the same time, developers are often overwhelmed by lengthy
backlog queues and noisy scanner outputs, leading them to question the real
impact of each flagged issue. As a result, many teams end up bypassing or
ignoring security review, while security professionals scramble to patch
existing tools with pattern-matching rules that add complexity and technical
debt. DryRun Security tackles this head-on by focusing on the high-impact,
context-rich changes that matter most, so developers get meaningful, timely
guidance-and AppSec teams can confidently protect the codebase without drowning
in false positives.
VMblog: What makes DryRun Security
unique in the market?
Wickett: Unlike traditional
Application Security Posture Management (ASPM) tools that primarily focus on
sorting and prioritizing vulnerabilities and Static Application Security
Testing (SAST) tools that rely on matching known patterns, DryRun Security addresses
the more fundamental problem of how risk actually enters the codebase in the
first place. We’ve built a Contextual Security Analysis engine that’s
LLM-native and context-driven-meaning, we don’t just feed security scanner
outputs into a data model or rely on an outdated pattern list; we combine
AppSec insights with a holistic understanding of code changes, framework
details, and developer intent.
By
zooming in on the real “why” and “how” behind each pull request, we can
highlight the code modifications that genuinely matter. As a result, our users
can break free from the cycle of endless false positives and generic alerts,
focusing instead on the most critical issues that pose real threats to their
applications.
VMblog: Can you share any customer
feedback?
Wickett: Absolutely. Gary Gonzalez, CTO at PlanetArt, recently provided this
feedback saying, “With
DryRun Security, we’ve transformed how we manage application security across
our global development team. The GitHub integration ensures that our developers
get precise and instant feedback directly in their workflow, enabling them to
fix security issues without skipping a beat. The tool has not only helped us
catch risks like hardcoded credentials early but has also fostered a culture of
security among our developers. DryRun Security is an indispensable part of our
AppSec toolkit.”
VMblog: Is there anything else you
want to share?
Wickett: Absolutely!
We’re excited to share that we’re also launching Natural Language Code Policies
(NLCP). This new feature lifts the burden of crafting and maintaining scripted
policy rules, letting AppSec teams define their requirements in a more
intuitive, domain-focused way. Regardless of the language or framework, NLCP
zeroes in on the riskiest code changes so they don’t get drowned out by the
daily flood of pull requests.
Ultimately,
we see our customers as the heroes on the front lines of securing their
organizations. Our role is to empower them with actionable insights rather than
more noise. If you’re ready to stop playing whack-a-mole with security alerts
and want a more proactive approach to identifying real threats, we invite you
to reach out. Whether you’d like a personalized demo or just have questions,
we’re here to help you protect your code without sacrificing development speed.
##






