

We believe in making people a priority
Kodem means “first” or “early” in Hebrew. A priority. We believe in helping appsec teams make security a priority by spotlighting risks that truly matter. We believe in helping developers improve code quality by shifting left and catching issues early. And we believe in making people a priority: our customers, our team, and our partners.
2021
founded
51
employees
$40M+
raised to date
45,291
songs on office playlist
9
languages spoken
3,542
cups of coffee weekly

Aviv, Pavel, and Idan built Kodem because they were tired of watching AppSec teams struggle with endless streams of false positives from traditional software composition analysis tools.
Meet the team

Aviv Mussinger

Aviv is co-founder and CEO of Kodem. He believes application security went wrong by optimizing for how much it could find rather than how much of it was true, and that the way back is unglamorous: work out what actually executes in production, and let that decide what matters.
He spends most of his writing on definitions, because he thinks the category argues about tools while leaving its terms undefined. Runtime intelligence, reachability, exploit probability and agentic risk all mean something specific, and being precise about them is what makes the rest of the conversation possible.

Pavel Furman

Pavel is co-founder and CTO of Kodem. He is interested in the layer most security tools skip, which is what a process is genuinely doing rather than what its manifest claims, and he thinks a platform is only as honest as the evidence underneath it.
That conviction shapes what he builds and what he writes: reading loaded libraries and executing functions from kernel and memory signals, and working out the data model that would let anyone reason clearly about applications now that agents are part of them.

Mahesh Babu

Mahesh is Field CISO at Kodem. He works with security leaders on the part nobody puts in a diagram: who actually fixes the thing, on what evidence, and how the program survives an auditor asking why.
His writing follows that bias. Proving compliance with runtime evidence rather than screenshots, securing AI-assisted development as it arrives rather than after, and the specific realities of healthcare, insurance and financial services. He judges a security idea by whether someone can act on it on Monday.












Supporting the open source community
We believe in the ability of cloud technologies to accelerate creativity, and we are proud to participate in the advancement of the open source community.














