📈 StepSecurity grew ARR more than 5x in 2024, more than 5x again in 2025, and the first half of 2026 just outpaced both. We closed roughly 7x more new customers in H1 2026 than in H1 2025, including the largest contracts in our history. Many customers expanded before their first renewal because they saw value within weeks.
🏢 Multiple Fortune 500 companies now run StepSecurity. Mercor, Dexcom, Miro, Circle, Mercari, Cresta, Kong, Utility Warehouse, Paddle, and many others are customers we can name publicly. And here is the proof point I am most proud of. Security companies chose StepSecurity to protect their own development infrastructure, including Chainguard, Checkmarx, Contrast Security, and XBOW.
🚨 Why is this happening now? A supply chain attack used to require a nation state team. Today one person with an AI coding agent can pull it off. Attackers no longer go after hardened production systems. They go after developer machines, code repositories, package registries, and CI/CD pipelines. Our threat intelligence team discovered several supply chain compromises such as the Axios npm compromise, the Shai-Hulud attack on TanStack, and the Nx Console breach. That research drove more than 100 media stories and citations in official CISA alerts.
🧩 Point solutions keep losing this fight. Malicious code moves through five stages: from a public registry, to a developer laptop, to a code repository, to a CI/CD pipeline, to your release. StepSecurity is end to end supply chain security with a control at every hop. Secure Registry screens packages before they reach dev machines or CI/CD. Dev Machine Guard protects laptops. Repo controls block use of compromised packages. Harden-Runner secures CI/CD at runtime on Linux, macOS, and Windows. If one layer misses, the next one catches.
🙏 Thank you to our customers, to the community, and to a small but mighty StepSecurity team. For the full mid-year update, refer to our blog post (link in comments).