Open source security startup WhiteSource raised $75 million in Series D funding that its CEO says will allow it to acquire other companies and expand its application security platform.

Pitango Growth led the funding round with participation by existing investors M12, Susquehanna Growth Equity, and 83North. This latest investment brings WhiteSource’s total funding to $121.2 million.

The Series D follows three years of growth for the company, which has seen a five-fold increase in customers and 800% revenue growth during that time. “We’re just on the cusp of 1,000 paying customers,” WhiteSource CEO Rami Sass said.

These customers include Microsoft, IBM, Nokia, Comcast, Pitney Bowes, Capital One, and Deloitte. In fact, 23% of Fortune 100 companies use its open source security management platform, the company claims. “We cater to some of the world’s largest companies, and if you are a large enough, you’re going to have software development going on somewhere in the company,” Sass said.

WhiteSource Technology

That is where WhiteSource’s auto-remediation software for open source vulnerabilities software fits in. The 10-year-old company pioneered software composition analysis, and it has been named a leader in the Forrester Wave Software Composition Analysis.

WhiteSource helps organizations developing software to monitor their use of open source code, Sass explained. “Especially around security vulnerabilities that may be lurking in some open source components, and then we help them manage all of the remediation, and anything else that has to do with open source dependencies that end up being embedded in their software, and then distributed to their customers,” he said.

This is now part of the larger application security sector, which is becoming increasingly important as organizations move their workloads and data to the cloud. In the last year alone, as the COVID-19 pandemic spurred companies’ cloud migration, a WhiteSource and Ponenmon Institute survey found more than 70% of enterprise application portfolios become more vulnerable to attacks, and this puts increasing pressure on developers to build security into their applications before they reach production.

Sass names Synopsys as WhiteSource’s top competitor. That vendor in 2017 bought a startup called Black Duck, and its technology automates the detection of vulnerabilities and compliance issues in open source software. It also provides automated alerts for newly discovered vulnerabilities affecting open source code. Synopsys folded this into its Software Integrity Platform.

“Our main differentiator with them, but also with everyone else, is that we focused most of our efforts around automating the remediation of the vulnerabilities,” Sass said. “Most other vendors pride themselves on their capability of finding vulnerabilities — they say they have better detection, more advanced, bigger databases, as do we. We don’t fall short on that, but the main benefit that we provide is our ability to automate the remediation of those problems, which is what we believe provides the most value at the end of the day for the customer.”

M&A, IPO on the Horizon

The latest investment will allow WhiteSource to acquire smaller companies with technology that can build on its auto remediation and vulnerability prioritization capabilities, Sass said. “We’re actively pursuing some acquisition targets right now, and we’re engaged with a few companies,” he added. And while an initial public offering is on the horizon, it’s still at least a couple years out, he said.

WhiteSource’s $75 million funding round is the latest example of investors and larger vendors throwing millions of dollars at application security startups.

As the COVID-19 pandemic increased the pace at which companies moved their workloads and data to public clouds, it also dramatically expanded their cloud security threats and amplified the need to protect these cloud-native applications. In the first few months of 2021, application security companies have reaped the benefits.

Four cloud-native security unicorns — Snyk, Aqua Security, Orca Security, and Wiz — announced massive funding rounds all in excess of $100 million in March alone. Additionally, in February Palo Alto Networks paid $156 million for DevOps security startup BridgeCrew, and a few weeks later VMware bought API security startup Mesh7 for an undisclosed amount.