Identity
Unverified · 0 matching sources · 2026-07-06No accepted supporting source is recorded for this field.
Agenova records depthfirst as a coding agents product from depthfirst.com. No capability, pricing, or deployment field currently has publication-qualified Evidence; those claims remain Unknown.
Agenova verified this product identity, but accepted official evidence is currently insufficient for specific capability, pricing, integration, deployment, privacy, or enterprise-control claims. Unverified fields remain Unknown.
depthfirst is an applied AI lab building what it calls General Security Intelligence, a platform of custom AI agents that detect, triage, and remediate software vulnerabilities across code, dependencies, secrets, infrastructure, and runtime. Founded in 2024 by Qasim Mithani, former head of infrastructure security at Databricks, and Andrea Michi, who spent nearly seven years building AI at Google DeepMind, with a founding team drawn from DeepMind, Databricks, and Faire, the San Francisco company has raised 120 million dollars in total. An 80 million dollar Series B led by Meritech in March 2026, at a 580 million dollar valuation, came less than ninety days after its 40 million dollar Series A led by Accel, with angels including Jeff Dean. The thesis is that winning in the AI era of security requires security specific models rather than general language models bent to the task. depthfirst builds its own models from scratch, trained through reinforcement learning in security environments, and shipped its first, dfs-mini1, for smart contract vulnerabilities, which it says beat frontier models at a fraction of the cost. On top of the models sit agents that work as a continuous loop: a Security Reviewer checks every human and agent code change, a Dependency Firewall blocks malicious packages, and an Agentic Pentester validates findings against the running application with real attack paths so only exploitable risk reaches the queue. Fixes arrive as pull requests developers can merge without leaving their workflow. The results the company reports are the kind security teams care about: many times more true vulnerabilities than static analysis, roughly eighty five percent fewer false positives, and about eighty percent of its fix suggestions accepted and merged, with one customer citing a seventy percent cut in security engineering load. Since going generally available in late 2025 it has signed customers including Lovable, Supabase, Moveworks, AngelList, ClickUp, and incident.io. For an engineering organization shipping AI generated code faster than it can secure it, depthfirst is a leading agentic option that validates and fixes rather than just flags; teams wanting a traditional scanner or bring your own model approach will find it a purpose built, model owning platform instead.
No decision field has accepted public evidence yet.
0 of 8 decision fields supported. Evidence coverage is not a product score.
Known identity and product metadata appear below. The eight decision fields remain Unverified until accepted evidence supports them.
Request evidence →Documented product facts and Source-Backed claims do not establish execution quality or performance. Only publication-approved execution evidence can create an Execution-Verified state.
Documented product intelligence is not execution evidence or a performance claim. No publication-approved Execution-Verified edge appears unless its governed evidence passes.
No evidence-qualified capability edge is published for this profile. Provider-listed labels are not promoted as verified capabilities.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
No accepted supporting source is recorded for this field.
These sources support only the fields named below. A missing source is reported as unknown, not as a negative product claim.