Company profile
Heeler
ASPM built on a live service model that joins code, dependencies, secrets, IaC, images and cloud: findings ranked by what is running and reachable, routed to the owning team, fixed via PR guardrails; now traces cloud…
- Status
- PrivateListed on CyberMerge Startup Radar (private vendors), snapshot Oct 7, 2026
- Valuation
- Undisclosed
- Latest funding
- Undisclosed
- HQ
- US (Startup Radar)
- Last updated
Categories
Funding & valuation
Funding: Undisclosed — no round recorded in the CyberMerge Funding Tracker.
Latest signals
- Startup Radar · Application Security · snapshot Oct 7, 2026 6 Oct 2026: launched Heeler Cloud Security, CSPM with prompt-to-production lineage (Workstation Sensor records Claude Code/Codex/Cursor sessions and ties agent commits to deployed resources), live internet-exposure tests, near real-time CloudTrail/Audit Log change detection and IaC-to-resource matching (company blog). Last disclosed equity: $8.5M seed (Jul 2024, Norwest Venture Partners lead, Storm Ventures). Valuation Undisclosed. Source
Competitors
Same-category peers from CyberMerge Research maps, Startup Radar and What's The Use tags.
- ArmadinPrivateAI-native offensive security: autonomous agent swarms chain low-severity weaknesses into validated kill…
- OX SecurityPrivateAI-native AppSec from prompt to runtime: ASPM/PBOM, VibeSec for AI-generated code, plus OX Cloud CNAPP with…
- HadrianPrivateAgentic offensive security: Atlas continuously maps the external attack surface and uses AI agents to…
- Fleuret AIPrivateAgentic continuous pentesting: two AI agents (Emile and Champollion) map exposed apps, APIs and…
- GitGuardianPrivateSecrets detection + non-human identity / AI-agent credential governance across SDLC.
- ArmorCodePrivateUnified exposure / ASPM orchestration across AppSec, cloud, and AI findings.
- Aikido SecurityPrivateUnified developer AppSec suite (SAST/SCA/secrets/cloud/runtime) with autofix; European unicorn.
- AnchorePrivateSBOM-centric software supply-chain security for containers and cloud-native builds.
- Backslash SecurityPrivateSecures the AI-native SDLC: IDEs, coding agents, MCP, prompt rules.
- ChainguardPrivateSafe-source open-source: zero-CVE container images, libraries, and supply-chain factory.
- CytixPrivateChange-risk AppSec: monitors AI-accelerated SDLC change for exploitability and audit evidence.
- FAZE SecurityPrivateOffensive Security Orchestration with Agentic Red Team: continuous agentic testing of web apps, APIs, and…
Figures appear only as recorded in CyberMerge data, with source and date. “Undisclosed” means no published figure in our data. Editorial, not investment advice. Last updated . Spot an error? Tell the desk.
