

Xygeni Security
بواسطة Xygeni
Xygeni is a leading cybersecurity company specializing in Software Supply Chain Security and Application Security Posture Management (ASPM). Headquartered in Madrid, Spain, the company has rapidly emerged as a disruptor in the AppSec market by focusing on the 'integrity' of the software lifecycle rather than just surface-level vulnerabilities. Xygeni’s mission is to provide organizations with complete visibility and control over their entire software ecosystem, from the first line of code to the final deployment in the cloud. The company positions itself as a partner to DevSecOps teams, helping them manage the growing complexity of modern CI/CD pipelines and the risks associated with open-source dependencies.
Xygeni was founded in 2021 by Jesús Martín (CEO) and Luis Rodríguez (CTO). Both founders brought extensive experience in enterprise software development and cybersecurity, having previously held leadership roles at security-focused organizations. Their original vision was to address the critical gaps left by traditional Application Security Testing (AST) tools, which were struggling to keep up with the speed of modern DevOps and the rise of supply chain attacks like SolarWinds. The founding team recognized that security needed to be contextual, automated, and deeply integrated into the developer's existing workflows to be effective. Since its inception, Xygeni has grown from a specialized tool provider into a comprehensive platform recognized by industry analysts and peer review sites.
Xygeni successfully closed a Series A funding round in June 2023, raising €4 million ($4.36 million). The round was led by Investing Profit Wisely (IPW), a Spanish investment firm specializing in B2B SaaS and cybersecurity companies. This funding milestone was pivotal for the company, enabling it to accelerate its product development roadmap and expand its international presence. The investment also brought strategic mentorship from IPW, which has a track record of scaling successful software companies. The capital has been utilized to enhance the platform's AI capabilities and to grow the sales and marketing teams in key markets like the United States and Europe.
Xygeni's product suite is structured around an 'All-in-One' philosophy, providing a unified platform for Application Security. Key offerings include Xygeni SCA (Software Composition Analysis) for managing open-source risks, Xygeni SAST (Static Analysis) for finding vulnerabilities in proprietary code, and Xygeni Secrets for preventing credential leakage. Beyond these core modules, the platform offers specialized capabilities for Infrastructure as Code (IaC) security, CI/CD pipeline hardening, and Malware Detection. All these modules feed into the Xygeni ASPM (Application Security Posture Management) dashboard, which serves as the central command center for risk prioritization and remediation management.
While founded in Spain, Xygeni has a clear global growth strategy. Following its 2023 Series A round, the company prioritized expansion into the United States and Northern European markets. Xygeni has established partnerships with regional technology integrators like Panorama Technologies to broaden its reach. The company is an active participant in global security conferences, serving as a Golden Sponsor for OWASP events and receiving accolades at the RSA Conference in San Francisco. This international focus is reflected in the product's support for global standards and its adoption by multinational companies in the finance, healthcare, and technology sectors.
In the last 12-18 months, Xygeni has introduced several significant enhancements to its platform. At Black Hat Europe 2023, the company launched its Build Security module, which automates the generation of SLSA (Supply-chain Levels for Software Artifacts) attestations. More recently, Xygeni has integrated advanced AI-powered remediation (Autofix), which allows developers to fix vulnerabilities directly from the platform with automated pull requests. Other recent additions include enhanced Anomaly Detection for monitoring developer behavior and a 'Malicious Code Digest' which provides real-time alerts on the latest supply chain threats detected by Xygeni's global sensor network.
The culture at Xygeni is driven by innovation, technical excellence, and a 'security-first' mindset. The company emphasizes a remote-friendly and collaborative work environment where researchers and engineers are encouraged to stay at the forefront of the threat landscape. Values such as transparency and customer-centricity are central to their operations, as evidenced by their 'no code upload' architectural choice which prioritizes customer privacy. Xygeni also fosters a culture of continuous learning, regularly publishing research on emerging supply chain threats to educate the broader cybersecurity community.
Xygeni actively engages with the cybersecurity and DevOps communities through multiple channels. The company maintains an active presence on GitHub, offering open-source tools like 'xygeni-goat' (a deliberately vulnerable repository) to help developers learn about supply chain attacks. They are frequent contributors to industry standards and participate in major forums such as OWASP, RSA, and Black Hat. Xygeni also provides a 'Resource Library' filled with whitepapers, webinars, and a 'Malicious Code Digest' that serves as a valuable intelligence source for security professionals worldwide. Their Slack community and developer documentation provide direct avenues for user engagement and support.