# Kodem

**Canonical:** https://apis.io/providers/kodem/  
**Website:** https://www.kodemsecurity.com/  
**APIs profiled:** 1

Kodem Security is an AI-native application security platform built on runtime intelligence, founded in 2021 by Aviv Mussinger, Idan Bartura, and Pavel Furman. Kodem connects code analysis, runtime evidence, AI reasoning, and runtime protection into a single system so security teams prioritize and fix what is actually exploitable in production rather than triaging every theoretical finding. The platform spans runtime-powered software composition analysis (SCA) across transitive and OS-level dependencies, native SAST powered by Opengrep with 1,000+ rules plus secrets detection, and Application Detection & Response (ADR) that detects exploit attempts at the application layer without signatures. Its AI layer, Kai, is grounded in function-level runtime evidence to accelerate triage, prioritization, and repository-grounded remediation. Kodem is SOC 2 Type II and deploys across cloud and on-premise environments in about five minutes.

## Kin Score — 26.5 / 100 (emerging)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 26.5).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 0.0 |
| Governance | 12.5 |
| Operational Transparency | 15.8 |
| Developer Ergonomics | 34.8 |
| Commercial Clarity | 42.1 |

## Agent readiness — 9.0 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Kodem API** — The Kodem platform API. The service is reachable at https://api.kodemsecurity.com and is fully authenticated — every path returns HTTP 401 with a JSON {"detail":"Unauthorized"} ...

## Security (2)

- **Kodem Authentication** — apiKey · 2 schemes
- **Kodem Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Tags

Company, Cybersecurity, Application Security, Runtime Security, Software Composition Analysis, Static Analysis, Vulnerability Management, DevSecOps, SBOM, AI Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/kodem/). Scores are computed from the provider's own public artifacts under a published rubric.
