Startups

Valence Security raises new cash to secure the SaaS app supply chain

Comment

padlock over digital background depicting innovative technologies in security systems, data protection Internet technologies
Image Credits: MF3d / Getty Images

Valence Security, a company securing business app infrastructure, today announced that it raised $25 million in a Series A round led by M12, Microsoft’s corporate venture arm, with participation from YL Ventures, Porsche Ventures, Akamai Technologies, Alumni Ventures and former Symantec CEO Michael Fey. The new capital brings the company’s total raised to $32 million, and co-founder Shlomi Matichin says it’ll be put toward product development and doubling Valence’s 25-person headcount by the end of the year.

Matichin co-founded Valence Security with Yoni Shohet in 2021. A two-time entrepreneur, Shohet previously co-launched SCADAfence, an industrial Internet of Things security startup. Matichin, for his part, was one of the founding members of Capester, a platform for cataloging videos of civic violations.

“In recent years, malicious actors have placed their focus on the interconnectivity between software-as-a-service (SaaS) applications, leveraging its potential for their attack campaigns,” Matichin told TechCrunch in an email interview. “Organizations struggle to secure this [app] mesh — a growing, complex and interconnected environment of SaaS apps, third-party integrations, identities, privileges and data.”

Matichin and Shohet built Valence to address these challenges around visibility into the SaaS supply chain, including misconfigurations, risk prioritization and remediation. The platform attempts to detect all of a company’s SaaS apps and contextualize them with vendor risk assessments, offering tools to spot improperly configured security controls and drifts from established policies.

Valence can also help manage risky, inactive and overprivileged authentication keys, third-party integrations and no- and low-code workflows, Matichin says — in addition to potentially insecure public-facing files and emails forwarded externally. Identity security flows within Valence, meanwhile, aim to ensure users are managed by a central identity provider, using multi-factor authentication and are properly offboarded.

According to Matichin, driving the demand for these services is the increasing threats companies face — and general SaaS app sprawl. The average enterprise uses around 80 SaaS apps, with BetterCloud estimating that businesses with more than 1,000 employees use more than 150 apps. This opens firms to attack. According to a Dimensional Research survey commissioned by ReversingLabs, a cybersecurity vendor, just over half (51%) of IT security teams report being able to protect their software from supply chain attacks.

The impact of such attacks can be devastating. In a recent paper, Kaspersky estimated the cost of a supply chain software attack to an enterprise at $1.4 million. That doesn’t factor in the lost revenue from additional downtime arising during remediation, which can substantially add to costs (to the tune of thousands to millions of dollars) and affect a firm’s reputation.

“Beyond security concerns, the repercussions of SaaS supply chain attacks are at the top of business priorities in light of the growing number of high-profile SaaS supply breaches over the past two years,” Matichin said. “These breaches can expose multiple interconnected SaaS applications for a single organization as well as threaten the business-critical data stored in those applications. This risk to business objectives, as well as to business continuity and efficiency due to the significant impact these breaches have on SaaS use, should be top-of-mind for the C-suite.”

Tel Aviv-based Valence competes with a number of vendors in the supply chain SaaS app security space, including Canonic Security, Atmosec (which has raised $6 million), Astrix Security ($15 million), Wing Security ($26 million), AppOmni ($123 million), Obsidian Security ($119.5 million) and Adaptive Shield ($34 million). When asked whether that concerned him, Matichin responded by highlighting what he sees as a growing need for visibility and control over SaaS assets and remediation of the risks.

“As remote working conditions accelerated the adoption and use of SaaS applications, a unique and unaddressed risk surface uncovered a growing need for SaaS security solutions targeting the sprawling SaaS mesh,” Matichin said. “In this respect, Valence was strongly positioned to address the unique security and business needs at the height of the pandemic, [and] Valence will continue to set the standard for SaaS security going forward.”

Matichin didn’t reveal the size of Valence’s customer base or projected revenue. But even if it’s lower than that of the company’s close competitors, VCs seem ready and willing to throw their weight behind security vendors. In the first half of 2022, there was $12.5 billion in venture capital invested across more than 530 deals, according to a report from investment firm Momentum Cyber — in line with H1 2021’s $12.6 billion invested.

More TechCrunch

Payments giant Stripe has delayed going public for so long that its major investor Sequoia Capital is getting creative to offer returns to its limited partners. The venture firm emailed…

Major Stripe investor Sequoia confirms $70B valuation, offers its investors a payday

Alphabet, Google’s parent company, is in advanced talks to acquire Wiz for $23 billion, a person close to the company told TechCrunch. The deal discussions were previously reported by the…

Google’s Kurian approached Wiz, $23B deal could take a week to land, source says

Name That Bird determines individual members of a species by identifying distinguishing characteristics that most humans would be hard-pressed to spot.

Bird Buddy’s new AI feature lets people name and identify individual birds

YouTube Music is introducing two new ways to boost song discovery on its platform. YouTube announced on Monday that it’s experimenting with an AI-generated conversational radio feature, and rolling out…

YouTube Music is testing an AI-generated radio feature and adding a song recognition tool

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Elon Musk confirms Tesla ‘robotaxi’ event delayed due to design change

What this means for the space industry is that theory has become reality: The possibility of designing a habitation within a lunar tunnel is a reasonable proposition.

Moon cave! Discovery could redirect lunar colony and startup plays

Get ready for a prime week of savings at TechCrunch Disrupt 2024 with the launch of Disrupt Deal Days! From now to July 19 at 11:59 p.m. PT, we’re going…

Disrupt Deal Days are here: Prime savings for TechCrunch Disrupt 2024!

Deezer is the latest music streaming app to introduce an AI playlist feature. The company announced on Monday that a select number of paid users will be able to create…

Deezer chases Spotify and Amazon Music with its own AI playlist generator

Real-time payments are becoming commonplace for individuals and businesses, but not yet for cross-border transactions. That’s what Caliza is hoping to change, starting with Latin America. Founded in 2021 by…

Caliza lands $8.5 million to bring real-time money transfers to Latin America using USDC

Adaptive is a platform that provides tools designed to simplify payments and accounting for general construction contractors.

Adaptive builds automation tools to speed up construction payments

When VanMoof declared bankruptcy last year, it left around 5,000 customers who had preordered e-bikes in the lurch. Now VanMoof is up and running under new management, and the company’s…

How VanMoof’s new owners plan to win over its old customers

Mitti Labs aims to transform rice farming in India and other South Asian markets by reducing methane emissions by 50% and water consumption by 30%.

Mitti Labs aims to make rice farming less harmful to the climate, starting in India

This is a guide on how to check whether someone compromised your online accounts.

How to tell if your online accounts have been hacked

There is a general consensus today that generative AI is going to transform business in a profound way, and companies and individuals who don’t get on board will be quickly…

The AI financial results paradox

Google’s parent company Alphabet might be on the verge of making its biggest acquisition ever. The Wall Street Journal reports that Alphabet is in advanced talks to acquire Wiz for…

Google reportedly in talks to acquire cloud security company Wiz for $23B

Featured Article

Hank Green reckons with the power — and the powerlessness — of the creator

Hank Green has had a while to think about how social media has changed us. He started making YouTube videos in 2007 with his brother, novelist John Green, at a time when the first iPhone was in development, Myspace was still relevant and Instagram didn’t exist. Seventeen years later, posting…

Hank Green reckons with the power — and the powerlessness — of the creator

Here is a timeline of Synapse’s troubles and the ongoing impact it is having on banking consumers. 

Synapse’s collapse has frozen nearly $160M from fintech users — here’s how it happened

Featured Article

Helixx wants to bring fast-food economics and Netflix pricing to EVs

When Helixx co-founder and CEO Steve Pegg looks at Daisy — the startup’s 3D-printed prototype delivery van — he sees a second chance. And he’s pulling inspiration from McDonald’s to get there.  The prototype, which made its global debut this week at the Goodwood Festival of Speed, is an interesting proof…

Helixx wants to bring fast-food economics and Netflix pricing to EVs

Featured Article

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

India is struggling to get new smartphone buyers, as millions of Indians don’t go for an upgrade and continue to be on feature phones.

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

Roboticists at The Faboratory at Yale University have developed a way for soft robots to replicate some of the more unsettling things that animals and insects can accomplish — say,…

Meet the soft robots that can amputate limbs and fuse with other robots

Featured Article

If you’re an AT&T customer, your data has likely been stolen

This week, AT&T confirmed it will begin notifying around 110 million AT&T customers about a data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers. The stolen data contains phone numbers and AT&T records of calls and text messages during a six-month period in…

If you’re an AT&T customer, your data has likely been stolen

In the first half of 2024 alone, more than $35.5 billion was invested into AI startups globally.

Here’s the full list of 28 US AI startups that have raised $100M or more in 2024

Whistleblowers have accused OpenAI of placing illegal restrictions on how employees can communicate with government regulators, according to a letter obtained by The Washington Post. Lawyers representing anonymous whistleblowers sent…

Whistleblowers accuse OpenAI of ‘illegally restrictive’ NDAs

Business email compromise attacks are on the rise. Here’s how you can stay ahead of the hackers.

How to protect your startup from email scams

Featured Article

What exactly is an AI agent?

Regardless of how they’re defined, the agents are for helping complete tasks in an automated way with as little human interaction as possible.

What exactly is an AI agent?

Meta announced former President Donald Trump’s Facebook and Instagram accounts will no longer be subject to heightened suspension penalties, according to an updated blog post on Friday. The company says…

Meta removes special restrictions for Trump’s account ahead of 2024 elections

A Castro Valley resident was charged Thursday for allegedly slashing the tires of 17 Waymo robotaxis in San Francisco between June 24 and June 26, according to the city’s district…

Waymo cameras capture footage of person charged in alleged robotaxi tire slashings

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. This…

Defending Russia’s EU neighbors

Cat-Wells said she started this platform because traditional hiring processes are exclusionary and often overlook skilled, talented disabled people.

A VC told Keely Cat-Wells to get a male, non-disabled co-founder — she balked, nabbed a $2M pre-seed round

A new study examines whether AI could be an automated helpmeet in creative tasks, with mixed results: It appeared to help less naturally creative people write more original short stories…

Experiment finds AI boosts creativity individually — but lowers it collectively