Snyk

Snyk

Snyk finds vulnerabilities in code, dependencies, containers, and infrastructure definitions.

Oximy ResearchUpdated 19 September 2026

Overview

A+
Transparency
7 / 10
Trust
98 / 100

Trains on your data

Free
No
Paid
No
Opt-out
Not captured

Incidents

0

0

Assessed SEP 21, 2026 · Checked by hand SEP 21, 2026

Snyk confirms SOC 2, ISO 27001, ISO 27017, GDPR and no training on customer code; its terms, subprocessors and three hosting regions were verified.

Trust breakdown

A+

98 / 100

Overall trust score

Data safetyComplianceIncidentsLegal
Data safety100
Compliance92
Incidents100
Legal100

Data and privacy

Trains on your data

No training on user data

Storage regions

USGermanyAustralia

Sub-processors

Amplitude, Inc.Akamai Technologies Limited and its affiliatesAmazon Web Services, Inc. and Amazon Web Services EMEA SARLAmazon Web Services, Inc. and Amazon Web Services EMEA SARL (Bedrock)Okta, Inc. (Auth0)Confluent, Inc.CrowdStrike, Inc.Datadog, Inc.DBT Labs, Inc.Functional Software, Inc. (Sentry)Google Cloud PlatformGoogle Cloud Platform (Vertex)Google WorkspaceLookerMongoDB Ltd.Shoreline Labs, Inc. (d/b/a Nightfall)OpenAI, LLCOrca Security UK LtdSalesforce.com, Inc.Slack Technologies LimitedSnowflake, Inc.Sublime, Security Inc.Twilio Ireland Limited (Segment.io)BastionX, IncSentry LLC

Data retention

Snyk accesses your repository code for a one-time analysis and caches the source code according to the Cloud provider's storage minimum policy.

Deletion: You may request that we delete your personal information.

Powered by

OpenAIAnthropic's ClaudeGoogle's GeminiSnyk DeepCode AI
Proprietary model

Snyk uses a hybrid approach, combining proprietary AI (DeepCode AI) with third-party large language models (LLMs) from providers like OpenAI, Anthropic (Claude models via AWS Bedrock and GCP Vertex), and Google (Gemini models via AWS Bedrock and GCP Vertex).

Integrations and access

Integrations

API: YesJiraGitHubBitbucketAzure DevOpsSlack

Available on

Web
iOS
Android
macOS
Windows
Linux
Extension
CLI

Pricing

Free

$0/month

200 Open Source tests/month, 100 Code tests/month, 300 IaC tests/month, 100 Container tests/month

Team

$25/month

Increased test limits per product, Jira Integration, Next business day support. Minimum 5, maximum 10 contributing developers per org. 1,000 Open Source tests/month, up to 1,000 Code tests/month, unlimited IaC and Container tests.

Ignite

$1,260/year

Full platform capabilities access, unlimited code tests, custom security rules & risk-based prioritization. Up to 50 contributing developers.

Enterprise

Custom

Contact Sales for pricing. Includes Zero-day risk prevention, unified AppSec control & strategic security oversight, full SDLC automation, SSO/SAML, custom RBAC, compliance reports, unlimited testing, 24/7 support.

Prices as listed on SEP 21, 2026; check the vendor's page.

Moat and openness

7/ 10
Moat 7 out of 10

Moat

  • Proprietary Model
  • Proprietary Data
  • Network Effects
  • Switching Costmoderate
  • Unique UX
  • Distributionstrong

Snyk demonstrates a strong moat, primarily driven by its hybrid AI approach combining proprietary DeepCode AI with leading LLMs, and its comprehensive platform covering the entire SDLC. Its market leadership, extensive integrations, and focus on AI-native application security create significant switching costs and a unique value proposition for developers and security teams.

6/ 10
Openness 6 out of 10

Openness

  • Open model weights
  • Published research
  • Open source contributions
  • Transparency reports
  • Public safety evals

Snyk demonstrates a moderate level of openness and transparency, particularly concerning data handling, security, and governance. They publish detailed information on how they handle user data, including data types accessed, storage practices, and security measures like encryption and adherence to SOC 2 and ISO 27001 standards. Snyk also provides a 'Trust Center' and an annual 'Impact Report' which outlines their commitment to ESG, ethical conduct, and governance, including updates to their Code of Conduct and whistleblowing platforms. They are transparent about their AI governance, stating that customer code is not used for AI model training and that AI capabilities are designed to align with emerging AI regulations. While they encourage vulnerability reporting in open-source packages, there's no explicit mention of open-sourcing their own models or publishing public safety evaluations of their AI.

Company

Snyk

Founded
2015
HQ
Boston, Massachusetts, USA

Popularity

Not disclosed

monthly visits

Notable customers

SnowflakeSpotifyICE/NYSELabelboxTechnologyOneMercato SolutionsRelay NetworkAtlassianRedditSASMolliePomeloDFDSShopBack GroupVaroSeismicSkyscannerMongoDBAuth0CoveoLunarHelvetiaOverstockRevolut

Snyk is recognized as a market leader in the Developer Tools sector and in application security testing, with a strong presence and customer trust.

Value and ROI

What it should move: It shortens remediation and finds more security issues before release.

Best fit

It fits teams that assign findings inside repositories and delivery pipelines.

The catch

Scanning can create a large backlog. Teams need rules for access, false positives, priorities, and remediation owners.

  • Salesforce: Uses Snyk to scan repositories for open-source vulnerabilities during software review.[1]
  • Pearson: Uses Snyk for automated dependency scanning across application development.[2]

In our stacks for

References