Who buys, and what they pay
Engineering, not the CISO, signs most AI code-security deals, at $45-105/dev/month, and false positives are still the top complaint.
Nearly every AI-native code-security vendor prices per developer, not per enterprise license — which means the buyer that matters most, in a large share of deals, is VP Engineering, not the CISO. Real median ACVs run $24K-$61K, list price runs $15-105/dev/month, and the single most consistently documented complaint across the SAST category is false positives, unchanged from the pre-AI era. Enterprise deals now carry an extra AI-governance review layer on top of the usual SOC 2/DPA gauntlet, stretching regulated-buyer cycles to 3-9 months.
#Market sizing — and a warning about mixing definitions
There is no single agreed number for "the AppSec market" or "the AI security market." Definitions vary by analyst firm, and figures that look comparable often aren't measuring the same thing.
| Segment | 2026 figure | Growth | Source |
|---|---|---|---|
| Global cybersecurity spend | $302.0B | 11.9% CAGR to 2033 | Grand View Research |
| Application security (SAST/SCA/DAST/etc.) | $12.6B (est.) | 18.8% CAGR to 2033 | Grand View Research |
| Penetration testing services | $2.72B | 15.3% CAGR to 2031 | Mordor Intelligence |
| MDR (managed detection & response) | $6.6B (est.) | 23.5% CAGR to 2030 | Grand View Research |
| "Securing AI" (Gartner's category) | $2.835B → $4.783B in 2027 | 83.0% growth in 2026 alone | Gartner, 25 Aug 2026 |
Do not conflate "securing AI" with "AI-powered AppSec." Gartner's $2.8B-in-2026 "securing AI" figure covers products that protect AI systems — AI application firewalls, prompt-injection defense, AI governance platforms, agent access control. It does not include AI-powered tools that secure ordinary code, like Snyk's AI triage or Corgea's AI autofix — those sit inside the $12.6B AppSec figure above. Gartner's own 2027 segment breakdown makes the boundary explicit: AI Application Security $851M, AI Usage Control $749M, AI Governance Platforms $462M, AI Gateway $429M, Other Securing AI $2.292B. A pitch deck that quotes "the $5B AI security market" as the addressable market for an AI-powered SAST tool is citing the wrong number — it's roughly 20-40% the size of the real target (AppSec, $12.6B), not the whole thing plus a bonus.
Gartner's own headline "worldwide security and risk management spending" figure — the most-cited number in the industry, historically around $212B — could not be located via direct fetch in the underlying research, and Gartner's narrower scope (excluding physical security and some risk/compliance software) is a large part of why it and Grand View's $302B "don't agree." Expect any cross-cited "global cybersecurity market" figure to be off by 30-50% from another equally reputable source depending on scope Where the gaps actually are. The pentest services market ($2.72B) is roughly one-fifth the AppSec software market and the same order of magnitude as Gartner's "securing AI" figure — small relative to total cyber spend, the structural reason pentest and AppSec deals tend toward small-to-mid ACVs (below) rather than seven-figure SIEM/XDR-style platform deals.
#Budget owners: engineering signs the check
The clearest structural fact in this market: every AI-native code-security vendor checked (Snyk, Semgrep, Socket, Aikido, ZeroPath, Corgea, Endor Labs, GHAS) prices per developer, contributor, or committer — not per CISO-negotiated enterprise license. That pricing-unit choice is itself the evidence of who the intended buyer is: someone counting developers, not someone counting risk-dollars.
The practical buying pattern splits by deal size:
- Sub-$50K ACV, self-serve or lightly assisted. A VP Engineering, Head of Platform Engineering, or a staff engineer swipes a card or gets a Team-tier PO approved without procurement — days to weeks. Budget comes out of an engineering tooling line, not the security budget. No SOC 2 requirement, no formal security review, no DPA negotiation.
- $50K-$250K ACV. Head of AppSec or a Product Security lead is the economic buyer, reporting to the CISO, with VP Eng as required technical sign-off because the tool sits in CI/CD and can add deploy-pipeline friction. Engineering can effectively veto a tool it doesn't like.
- $250K+ ACV, multi-year. CISO is the named economic buyer, with procurement, SOC 2 report exchange, DPA/MSA redlines, and a budget-committee sign-off for a new category.
This is the single biggest thing that changes about the product and the go-to-market motion versus a pre-AI-era AppSec vendor: you are building a developer tool that happens to do security, not a security tool that happens to touch developers. Time-to-value inside the IDE/CI matters more than a feature-parity checklist against Checkmarx. A product a developer actively dislikes running gets uninstalled or ignored before a CISO ever sees the dashboard — the well-documented reason AppSec tools historically failed to deliver value is that developer-adoption friction, not detection gaps, killed them Where the gaps actually are.
The general shift over the last several years — budget ownership moving from purely CISO-owned to co-owned or primarily engineering-owned — is why vendors price per-developer: it aligns cost with the audience that actually has to run the tool, and it gives Engineering a natural seat at the negotiating table rather than a veto exercised after the fact. Any founder building for this market should assume the first buyer conversation happens with an engineering leader, not a CISO, unless the deal starts above $250K.
[UNVERIFIED] commonly repeated rules of thumb — AppSec spend at 5-15% of total security budget (higher at SaaS/fintech), per-developer AppSec tooling spend of $300-$1,500/developer/year blended across SCA+SAST+secrets+container scanning — could not be confirmed against a live 2026 survey in the underlying research and should not be cited as sourced figures, though they are broadly consistent with the real pricing shown below.
#The pricing table
List prices across the AI-native code-security category cluster tightly. All figures fetched from vendor pricing pages in August 2026.
| Vendor | Entry paid tier | Price | Unit |
|---|---|---|---|
| Snyk | Team | $25 | /dev/mo |
| Snyk | Ignite | $105 (~$1,260/yr) | /dev/mo |
| Semgrep | Teams | $30 (Code/SCA) or $15 (Secrets) | /contributor/mo |
| Socket | Team | $25 (min. 5 devs) | /dev/mo |
| Socket | Business | $50 (min. 20 devs) | /dev/mo |
| ZeroPath | Team | $1,000/mo base + $60/dev | /org + /dev/mo |
| Corgea | Growth | $39 (min. 5 devs) | /dev/mo |
| Corgea | Scale | $49 (min. 20 devs) | /dev/mo |
| GHAS | — | $30-$60 negotiated | /active committer/mo |
That's the $15-105/dev/month range referenced across this wiki. But list price is not what buyers actually pay — Vendr's deal-level database, which aggregates real negotiated contracts, tells a different and more useful story:
| Vendor | Real median ACV | Range | Sample |
|---|---|---|---|
| Snyk | $45,030 | $13,063-$182,535 | 278 purchases |
| GitHub (Enterprise Cloud + GHAS, blended) | $53,758 | $14,145-$157,178 | 762-974 transactions |
| Veracode | $23,774 | $9,840-$143,693 | 87 purchases |
| Checkmarx | $60,950 | $26,400-$205,350 | 32-34 deals |
Source: Vendr marketplace pages for each vendor, fetched Aug 2026.
Real-world Snyk street price runs $52-98/developer/month once SCA+SAST+container+IaC are bundled — 2-4x the advertised $25/mo single-product list price. A 50-developer deployment runs $30K-$54K/yr (Team) or $48K-$84K/yr (Enterprise). Checkmarx volume discounts of 20-40% below list are common above 50 developers, but hidden costs (professional services, premium support, overage) add another 15-35% to first-year spend. GHAS negotiated street price is $30-60/active committer/month — a 200-active-committer enterprise deployment adds $72K-$144K/yr on top of the base Enterprise Cloud license. All figures: Vendr, Aug 2026.
Veracode's pricing model is a structural outlier: it scales by portfolio (application count), not developer count — $50K-$120K/yr for 5-20 apps, up to $250K-$500K+/yr for 50+ apps. This app-count-based licensing, an artifact of an older scan-based model, is increasingly mismatched to monorepo/microservices architectures where "number of applications" is an awkward unit — a real weakness a per-developer-priced challenger can exploit against Veracode specifically.
Pentest pricing sits in a different band entirely. Traditional manual engagements run $5,000-$50,000 per engagement (web app, cloud, mobile, SaaS, API — Astra Security, Aug 2026), with network pentests priced per-device ($150-$1,000). None of the three AI-native/autonomous pentest vendors checked — XBOW, Horizon3.ai NodeZero, Pentera — publish list pricing; all are quote-only, enterprise-sales motions Offensive AI security companies. XBOW's own positioning is explicit: "usage-based pricing that scales with your coverage, not a fixed annual engagement" (xbow.com/pricing) — a direct attempt to reshape the buying unit from "an engagement" to "coverage/usage," not just undercut the old unit's price. This is worth watching as a template other AI-native security categories may follow, and it's the clearest evidence in this market of a vendor trying to move toward consumption pricing rather than seat pricing.
#Sales friction by company size
At a 100-person company, a Team-tier plan ($25-60/dev/mo) can be bought on a credit card or a single PO by an engineering lead in days to a few weeks — no SOC 2 requirement, no formal security review, no pentest-report exchange, no data-residency negotiation. The main friction is budget approval, not procurement process.
At a 5,000-person or regulated company (a bank, an EU enterprise), the picture is entirely different:
- Enterprise tier only — every vendor above gates SSO/SAML, SCIM, audit logs, and self-hosting/on-prem behind Enterprise, which is itself evidence vendors know large/regulated buyers require these as baseline, not nice-to-have.
- A formal vendor security review: SOC 2 Type II report exchange, a security questionnaire (SIG or CAIQ), often a request for the vendor's own pentest report.
- EU buyers, especially regulated ones under DORA and NIS2, frequently require EU-region hosting or a documented data-flow map.
- Procurement, legal (MSA/DPA redlines), and budget-cycle alignment combine to produce [UNVERIFIED but consistent with well-documented enterprise-software norms] a 3-9 month sales cycle at a 5,000+ person regulated company, versus weeks at a 100-person startup.
The AI-governance/model-risk review is new relative to 2023-era AppSec purchases and specific to AI security tooling: a genuinely new category (autonomous fixing) at a bank now typically triggers a model-risk review layered on top of the standard security review. It's not just "is this vendor secure" anymore — it's "what does your AI do with our code, can we turn off calls to third-party LLM providers." This is probably the single biggest incremental friction AI-native AppSec vendors face versus pre-AI predecessors, and it directly explains why BYOK and self-hosted/on-prem deployment are now Enterprise-tier features at ZeroPath, Corgea, and Aikido — the direct product answer to a specific new procurement blocker.
For a Berlin-based founder selling into EU-regulated buyers, BYOK and self-hosting are table stakes at the enterprise tier for exactly this reason, and doubly so given the German and EU sovereignty preference discussed in Go to market.
#What buyers actually complain about
The most useful live data point is G2's aggregate SAST category page — 118 products, 5,500+ reviews, 4.54/5.0 average — which surfaces specific, named-vendor complaint text:
- GitGuardian: users report "excessive notifications," alerts described as "overwhelming."
- SonarQube: "false positives that complicate usage" despite good customization tooling.
- Snyk: users explicitly cite "false positives in Snyk, which can hinder efficiency."
- Checkmarx: "significant number of false positives," particularly bad for Kotlin projects.
- Semgrep: "difficult learning curve" for custom rule creation — a friction complaint, not a noise complaint.
This is real, dated (2026), multi-vendor evidence that false positives remain the single most consistently repeated complaint across the SAST category, cutting across legacy tools (Checkmarx, SonarQube) and modern AI-era tools (Snyk, GitGuardian) alike. Notably, several AI-native entrants score well on ease-of-use/support in the same review base — Aikido 9.2/10 support, Semgrep 9.6/10 "partnership rating" — suggesting the false-positive problem is somewhat independent of support quality: even well-liked, well-supported vendors still get dinged for FP rates.
Specific quantified statistics — SAST false-positive rate as a percentage, average time-to-fix, fraction of findings ever remediated — could not be verified in the underlying research. The usual primary sources (Veracode's State of Software Security report, Contrast Security's AppSec survey) returned errors on direct fetch. Figures in the 60-80%+ range for "share of raw findings that are false or low-priority positives" are widely repeated across the AppSec industry but not independently confirmed here — do not present a specific percentage as sourced without re-verifying against the primary report directly.
A related, better-sourced data point from the adjacent AI-code-review category: an arXiv empirical study analyzing 22,000+ AI review comments across 178 repositories found human review comments get addressed roughly 60% of the time, versus 0.9%-19.2% for AI-generated comments depending on the tool. Design factors that help: hunk-level (line-anchored) comments over file/PR-level, manual triggers over automatic, code-rich suggestions, shorter comments. This is an adjacent category (PR-review bots, not vulnerability scanners), but the underlying mechanism — low-context, high-volume, low-precision AI output developers learn to ignore — is the same failure mode as the false-positive complaints, and it's the strongest documented argument that the deep version of "review every PR" is unsolved by anyone, including the frontier labs, which still require human review of every patch or remain in private beta with no disclosed false-positive rate AI code security companies.
Tool sprawl is not directly quantified via a live source but is strongly implied structurally: the sheer count of narrowly-scoped tools this category contains (14+ named vendors), each with its own dashboard and alert format, is the explicit stated rationale behind every "unified AI layer across SAST+SCA+secrets+IaC" pitch every AI-native vendor now makes.
#Willingness to pay for fixing vs. finding
No vendor checked prices purely on outcomes — no "$X per vulnerability actually fixed." Every vendor's core pricing unit is still developer/contributor/committer count, with autofix bundled in as a feature of a tier. But several vendors already meter the AI-fix capability itself as a separate consumption unit layered on top of seats — the clearest available evidence of nascent outcome-based pricing:
- Corgea: fix quota tiered by plan — 10 auto-fixes/mo (Free), 50/mo (Growth), 200/mo (Scale). Fix-throughput, not just seats, is the upsell lever.
- Semgrep: "AI credits" scale by tier (60 free, 20/dev/mo Teams, 50 Enterprise) for "AI-powered detection, triage, and remediation."
- Aikido: "AI AutoFixes" capped at 10/mo free, unlimited from Basic ($300/mo) — a deliberate gate on fix volume.
The market is already pricing fix-capacity as a distinct, metered dimension from find-capacity — meaning vendors believe (or have already learned) that buyers value fixing enough to pay for it as an incremental unit. But no vendor has gone all the way to pure per-outcome pricing (e.g., "$50 per critical vuln closed" with scanning given away free). The likely reason: pure outcome pricing requires attributing a fix definitively to the tool rather than an independent human action after being alerted — a harder billing and trust problem than metering "fixes the AI applied." This is a genuine, currently unclaimed white-space opportunity for differentiation, not a validated GTM pattern — see Where the gaps actually are and What could actually be defensible.
#What this means for us
- Price per developer/contributor from day one, not per enterprise seat license — it aligns cost with the buyer who actually decides whether the tool stays installed, and it's the only pricing unit every credible competitor in this category already uses.
- Design the first sale for an engineering leader at a 50-500 person company, not a CISO — self-serve or lightly-assisted at $25-60/dev/mo is the entry point that doesn't require a sales team, directly relevant to the Go to market sequencing question.
- Build BYOK and self-hosted deployment into the roadmap before targeting anything above $250K ACV or any EU-regulated buyer — this is now a hard product requirement, not a differentiator, and it plays directly to the sovereignty argument in EU regulation as a demand engine and Germany: §202c and the Berlin question.
- The false-positive problem is the real, durable pain point across every incumbent, AI-native or not — precision engineering (not "detecting more stuff") is where actual product differentiation and defensibility live; see The three ideas, judged and What could actually be defensible.
- Meter AI-fix volume as a separate consumption unit from seats immediately — it's already the norm, and it's the natural on-ramp to outcome-based pricing nobody has claimed yet.
- Don't build a business case on Gartner's "$5B securing AI" market number — that's a different market than AI-powered AppSec tooling. Use the $12.6B AppSec figure, and treat it as the honest TAM.