Kodem website screenshot

Kodem

Kodem Security is an AI-native application security platform built on runtime intelligence, founded in 2021 by Aviv Mussinger, Idan Bartura, and Pavel Furman. Kodem connects code analysis, runtime evidence, AI reasoning, and runtime protection into a single system so security teams prioritize and fix what is actually exploitable in production rather than triaging every theoretical finding. The platform spans runtime-powered software composition analysis (SCA) across transitive and OS-level dependencies, native SAST powered by Opengrep with 1,000+ rules plus secrets detection, and Application Detection & Response (ADR) that detects exploit attempts at the application layer without signatures. Its AI layer, Kai, is grounded in function-level runtime evidence to accelerate triage, prioritization, and repository-grounded remediation. Kodem is SOC 2 Type II and deploys across cloud and on-premise environments in about five minutes.

Kodem publishes 1 API on the APIs.io network. Tagged areas include Company, Cybersecurity, Application Security, Runtime Security, and Software Composition Analysis.

Kodem’s developer surface includes documentation, signup flow, pricing, engineering blog, support, authentication, and 11 more developer resources.

26.7/100 emerging ▬ flat Agent 14/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
1 APIs
CompanyCybersecurityApplication SecurityRuntime SecuritySoftware Composition AnalysisStatic AnalysisVulnerability ManagementDevSecOpsSBOMAI Security

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 26.7/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 7.0 / 20
Commercial Clarity 8.4 / 20
Operational Transparency 2.1 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 14/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/kodem: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Kodem API

The Kodem platform API. The service is reachable at https://api.kodemsecurity.com and is fully authenticated — every path returns HTTP 401 with a JSON {"detail":"Unauthorized"} ...

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Kodem Authentication

apiKey · 2 schemes

SECURITY

Kodem Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Access & Security 3

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: kodem
name: Kodem
description: Kodem Security is an AI-native application security platform built on runtime intelligence, founded in 2021 by
  Aviv Mussinger, Idan Bartura, and Pavel Furman. Kodem connects code analysis, runtime evidence, AI reasoning, and runtime
  protection into a single system so security teams prioritize and fix what is actually exploitable in production rather than
  triaging every theoretical finding. The platform spans runtime-powered software composition analysis (SCA) across transitive
  and OS-level dependencies, native SAST powered by Opengrep with 1,000+ rules plus secrets detection, and Application Detection
  & Response (ADR) that detects exploit attempts at the application layer without signatures. Its AI layer, Kai, is grounded
  in function-level runtime evidence to accelerate triage, prioritization, and repository-grounded remediation. Kodem is SOC
  2 Type II and deploys across cloud and on-premise environments in about five minutes.
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://cdn.prod.website-files.com/63da9726cdbeda469366f7f2/69446ff571232a027ec80a33_kodem-global-opengraph.png
url: https://raw.githubusercontent.com/api-evangelist/kodem/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- greylock
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-19'
tags:
- Company
- Cybersecurity
- Application Security
- Runtime Security
- Software Composition Analysis
- Static Analysis
- Vulnerability Management
- DevSecOps
- SBOM
- AI Security
apis:
- aid: kodem:kodem-api
  name: Kodem API
  description: The Kodem platform API. The service is reachable at https://api.kodemsecurity.com and is fully authenticated
    — every path returns HTTP 401 with a JSON {"detail":"Unauthorized"} envelope until a credential is supplied. The CORS
    preflight advertises an x-kodem-apikey request header alongside authorization, and the allowed methods are GET, POST,
    PUT, DELETE, and OPTIONS. No OpenAPI, Swagger, or public reference is published; product documentation sits behind the
    application login at docs.kodemsecurity.com.
  humanURL: https://docs.kodemsecurity.com/
  baseURL: https://api.kodemsecurity.com
  tags:
  - Application Security
  - Runtime Security
  - Vulnerability Management
  properties:
  - type: Authentication
    url: authentication/kodem-authentication.yml
common:
- type: Website
  url: https://www.kodemsecurity.com/
- type: DeveloperPortal
  url: https://app.kodemsecurity.com/
- type: Documentation
  url: https://docs.kodemsecurity.com/
- type: SignUp
  url: https://app.kodemsecurity.com/
- type: Pricing
  url: https://www.kodemsecurity.com/pricing
- type: PrivacyPolicy
  url: https://www.kodemsecurity.com/privacy-policy
- type: Blog
  url: https://www.kodemsecurity.com/resources
- type: Support
  url: https://www.kodemsecurity.com/book-a-demo
- type: LinkedIn
  url: https://www.linkedin.com/company/kodem/
- type: StatusPage
  url: https://status.kodemsecurity.com/
- type: Compliance
  url: conformance/kodem-conformance.yml
- type: LLMsTxt
  url: llms/kodem-llms.txt
- type: WellKnown
  url: well-known/kodem-well-known.yml
- type: Authentication
  url: authentication/kodem-authentication.yml
- type: Conformance
  url: conformance/kodem-conformance.yml
- type: Lifecycle
  url: lifecycle/kodem-lifecycle.yml
- type: DomainSecurity
  url: security/kodem-domain-security.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
x-enrichment:
  date: '2026-07-19'
  status: backfilled
  pass: local-v1
  note: backfilled from .gitignore signal + verified work evidence