From Startup to AI-Powered Security Platform: CodeThreat Transforms Application Security Landscape
CodeThreat stands out in the application security landscape with its innovative approach to secure coding. From its 2023 origins as a self-funded startup to its 2024 stable release featuring AI enhancements across multiple programming languages, CodeThreat has evolved significantly—starting with research-driven benchmark analysis and evolving into a comprehensive security assessment platform.
CodeThreat's journey began in 2023 as a small, self-funded team dedicated to transforming application security through rigorous research and benchmark analysis. Focusing initially on evaluating existing AppSec programs, the team developed foundational projects like FlowBlot.NET, which would later evolve into their comprehensive security assessment tool.
The company's success led to the creation of their program analysis framework, ShiftQL, which emerged from extensive testing over several years. Emphasizing continuous improvement through transparent workflows and data-driven decision-making, CodeThreat has grown from its 2020 pre-alpha scanner development to its anticipated stable release in 2024, which will feature AI enhancements across multiple programming languages.
Headquartered in Turkey, the young and dynamic team brings diverse technical expertise to the company. Led by co-founders Oğulcan Gürçağlar and Serhan Öztuna, along with key engineers Alperen Özdemir, Yusuf Dönmez, and Taha Yıldırım, the team operates under a collaborative culture that encourages continuous learning and skill development.
In their mission to deliver practical security solutions, CodeThreat's customer-centric approach prioritizes understanding specific needs before offering tailored recommendations. The company provides multiple pricing tiers to accommodate different scales of operation, from free community access for individual developers to comprehensive enterprise solutions supporting thousands of team members and on-premise deployment.
CodeThreat's security assessment tool delivers detailed metrics across multiple dimensions to help users understand their application's security posture. The platform continuously tracks the current number of unresolved security issues, volume of code scanned, and number of projects being monitored, providing a comprehensive view of ongoing security efforts.
A key feature of the tool is the Dynamic Issue Trend graph, which visualizes the evolution of security issues over time. This graph helps users identify patterns and trends in their security landscape, enabling more targeted prevention and resolution strategies.
The cornerstone of the security assessment methodology is the Risk Score, a composite metric rated on a scale from A to F. This score is derived from 16 weighted factors that collectively evaluate various aspects of the application's security architecture. Each factor is assigned a weight based on its potential impact on security, with the scores combined to provide a holistic view of the application's security posture.
The 16 factors included in the Risk Score calculation are:
Number of Sources (data entry points)
Number of Sinks (data exit points)
Number of Cryptographic Methods
Number of Try/Catch Blocks
Number of Executable Lines of Code
Number of Lines for Logging
Number of Session Add/Remove Statements
Number of Access Control Methods/Libraries
Number of Third Party Libraries Used
Number of Source Code Files
Number of Methods
Number of Authentication API Calls
Number of Appsetting Params in Web.Config
Number of Null Checks
Number of Views (aspx, cshtml, etc)
Number of Financial & Privacy Related API Calls
This comprehensive approach allows users to understand how different aspects of their codebase contribute to overall security, enabling more informed decisions about where to focus their security efforts. The methodology is designed to evolve with security standards, with the company regularly updating factor weights to reflect the latest best practices and threats.
From its 2020 pre-alpha scanner version to its 2024 stable release, CodeThreat's development journey reflects a commitment to continuous improvement through rigorous testing and iterative refinement. The company's research-driven approach, which emphasizes benchmarks and critical thinking, has guided their technical developments from the ground up.
The timeline demonstrates a deliberate progression through early testbeds and closed testing phases before reaching broader deployment. The 2020 initial version focused on establishing foundational capabilities, while 2021 marked a significant milestone with full C# language support in alpha form. Pre-Beta testing in 2022 continued to expand language support and test-bed functionality, establishing a robust foundation for subsequent development phases.
The company's 2023 beta release launched their full-fledged AppSec platform, followed by ongoing improvements in 2024 that introduced AI features while expanding language support and analyzer capabilities. This phase also refined their existing tools, particularly in SCA (Software Composition Analysis) and license scanning, to address emerging security needs.
Throughout their development process, CodeThreat maintained a startup mentality characterized by rapid iteration and data-driven decision-making. The team's approach intentionally embraces disorder and uncertainty to foster innovation, allowing them to adapt quickly to new technologies and security challenges. This flexible development model enables the company to maintain both technical agility and a strong foundation for long-term growth in the ever-evolving cybersecurity landscape.
The team's composition reflects a blend of practical engineering experience and theoretical security knowledge. Co-founders Oğulcan Gürçağlar and Serhan Öztuna bring a combined wealth of software engineering and security expertise to their roles, while software engineers Alperen Özdemir, Yusuf Dönmez, and Taha Yıldırım contribute essential technical capabilities. The team also includes experienced professionals like Arif Karakılıç, who brings valuable software development insights to the group.
The company's mentor, Bedirhan Urgun, provides strategic guidance and support, helping the team navigate the complexities of software security research and development. Under Urgun's mentorship, team members actively engage in continuous learning and professional development, attending industry events and pursuing certifications to deepen their expertise.
This dynamic and energetic team approach has been fundamental to CodeThreat's success, combining a startup mentality with rigorous technical standards. The team's youthful spirit and passion for cybersecurity thrive on the challenges of the evolving field, allowing them to maintain both technical innovation and operational efficiency.
The company's culture prioritizes transparency and trust in all customer interactions, demonstrating a commitment to building long-term relationships based on mutual success. This focus on clear communication and shared goals has helped establish CodeThreat as a reliable partner in the cybersecurity ecosystem.
The company's pricing tiers offer increasing capabilities for different sized organizations, with options for free community use up to custom enterprise deployments. The Community plan provides essential features at no cost, including analysis of up to five team members across both public and private repositories, access to all analyzers, and basic AI support, with analysis requests handled on a best-effort basis.
For growing teams, the Pro plan scales to support up to 25 users and adds significant features like role-based access control, comprehensive risk reports, and enhanced AI assistance. This tier also includes essential security compliance features such as software bill of materials (SBOM) support, Jira integration, and detailed license compliance analysis.
Enterprise customers benefit from additional customization options, including self-hosting capabilities and manual invoicing. The highest tier supports unlimited team members, advanced security policies, and detailed project monitoring, with enhanced features for enterprise-level security management including custom role creation, advanced scan policy development, and parallel scan limits.
The platform accommodates various payment preferences, offering both monthly and annual subscription options. Additional services can be purchased to unlock features like custom role development, extended scan capabilities, and advanced project limits, allowing organizations to scale their security investments precisely as needed.