Prevents falling behindOff-the-shelf productEstablished, AI retrofitted

Snyk

Snyk Limited, London ·snyk.io· As of: 2026-09-29

Checks your own source code, embedded open-source libraries, container images and infrastructure configuration for known vulnerabilities and licence risks, right in the development environment, the repository and the build. For each finding it proposes a fix, for dependencies usually as a ready-made pull request.

Work through this tool with an AI

Our verdict

Anyone shipping software has to show which libraries are inside it and which known vulnerabilities are open. Large customers' security questionnaires ask for this, as does every technical due diligence, and so does the EU Cyber Resilience Act, whose reporting duties for actively exploited vulnerabilities have applied since 11.09.2026 and whose remaining duties for products with digital elements apply from 11.12.2027. With AI-written code, the volume of changes someone has to check grows faster than any team. Automated checks in the build keep you level with the market, and every competitor can buy them as well.

Evidence:As of 2026-09-29Free and Team plans, Team for up to ten developers from 25 US dollars, credit rate card on the Enterprise plan, one credit equals one US dollarOpen sourceAs of 2026-09-29Billing per active contributor per calendar day, 90-day window, expiry of unused credits, overuse invoiced in arrears, as of 4 August 2026Open sourceAs of 2026-09-29Data processing agreement of 27 January 2026: standard contractual clauses module 2, Irish supervisory authority, 30-day subprocessor notice, unilateral amendment with seven days' noticeOpen sourceAs of 2026-09-29Terms of service of 18 September 2026: no training on inputs, deletion by the customer, security incident notice within 72 hoursOpen sourceAs of 2026-09-29Subprocessors with purpose and location, as of 3 February 2026, including OpenAI, Google Vertex and AWS BedrockOpen sourceAs of 2026-09-29Regions and data residency exceptions, Frankfurt region on the Enterprise plan onlyOpen sourceAs of 2026-09-29Handling of customer data per product, source code cache, no training on customer codeOpen sourceAs of 2026-09-29Audit log on the Enterprise plan only, 90 days, without sign-ins and sign-outsOpen sourceAs of 2026-09-29Single sign-on on the Enterprise plan onlyOpen sourceAs of 2026-09-29ISO 27001:2022 and ISO 27017:2015 for all services except Snyk API & Web, SOC 2 Type II, security addendum of 28 January 2026Open sourceAs of 2026-09-29Terms of service section 5.4 AI Compliance, without naming the AI ActOpen sourceAs of 2026-09-29Company registration of Snyk Limited, incorporated 9 July 2015Open sourceAs of 2026-09-29Group accounts for 2024 and filing of the 2025 accounts on 28 September 2026Open sourceAs of 2026-09-29Peter McKay left on 15 May 2026, Guy Podjarny a director again since 27 March 2026Open sourceAs of 2026-09-29Around 90 jobs cut, reported on 24 June 2026Open sourceAs of 2026-09-29CVE-2025-6624, Snyk command-line tool before version 1.1297.3, CVSS 4.0 score 2.4 and CVSS 3.1 score 7.2Open sourceAs of 2026-09-29GitHub Secret Protection at 19 and Code Security at 30 US dollars per active committer per month, since April 2025Open sourceAs of 2026-09-29Claude Code Security introduced as a limited preview on 20 February 2026Open sourceAs of 2026-09-29Aikido plans with flat pricesOpen sourceAs of 2026-09-29Aikido funding round of 60 million US dollars on 14 January 2026Open sourceAs of 2026-09-29Claude Security as a public beta for Enterprise customers since 30 April 2026, findings exportable as CSV or MarkdownOpen sourceAs of 2026-09-29Handover to chief financial officer Ken MacAskill as interim chief executive in April 2026Open sourceAs of 2026-09-29Cyber Resilience Act (EU) 2024/2847: reporting duties from 11 September 2026, remaining duties from 11 December 2027Open sourceAs of 2026-09-29Dependabot alerts based on the GitHub Advisory DatabaseOpen sourceAs of 2026-09-29Incident at vendor Klue in June 2026, investigation closed on 8 July 2026Open sourceAs of 2026-09-29Snyk not on the EU-US Data Privacy Framework participant listOpen source

Who it fits

Solo

suitable with caveats

The free plan checks five projects and allows 100 code tests a month. It runs in the US region only, and signing in through your own company identity provider only comes with the Enterprise plan.

Mid-market

suitable with caveats

The Team plan from 25 US dollars a month is designed for at most ten developers and also runs in the US region only. Anyone larger, or anyone who wants to keep data in the EU, ends up on the Enterprise plan with credit billing, whose entry point is negotiated through sales.

Enterprise

suitable

The Enterprise plan brings the Frankfurt region, sign-in through SAML or OpenID Connect, a change log via the API and SOC 2 reports through the account team. A contractual deletion deadline after the agreement ends remains open and should be agreed in writing before signing.

Buy, switch or build

Off-the-shelf

GitHub Code Security and Secret Protection

Anyone keeping code on GitHub anyway gets Dependabot's dependency alerts at no extra cost and, since April 2025, can add code and secret scanning separately for 30 and 19 US dollars per active committer per month. That saves a second contract and a second interface. Snyk, in turn, checks across GitHub, GitLab, Bitbucket and Azure Repos, which tips the balance for mixed code hosting after acquisitions.

AI-native

Claude Security from Anthropic, alongside Aikido

Anthropic introduced Claude Code Security as a limited preview on 20.02.2026 and released it as a public beta for Enterprise customers under the name Claude Security on 30.04.2026. The model reads the code, traces data flows across components and proposes fixes that a developer approves; findings can be exported as CSV or Markdown. Prices are not published. None of Anthropic's publications describes checks of open-source dependencies or licences (as of 29.09.2026). Aikido bundles similar checks with AI pre-triage at flat prices, with paid plans from 300 US dollars a month including ten users and a free entry tier for two users, and closed a 60 million US dollar funding round in January 2026.

Build it yourself

Open-source scanners in your own build pipeline

The building blocks are freely available: OSV-Scanner for dependencies against the open OSV database, Semgrep Community Edition for code, Trivy for containers and infrastructure, Gitleaks for secrets. In GitHub or GitLab they run as a step on every pull request; Claude Code can write custom rules and fix suggestions, LiteLLM and Langfuse can steer and log an AI pre-triage of findings, and credentials sit in Infisical. It gets hard in two places. Someone has to sort false alarms, maintain rules and justify exceptions, every week. And for an audit there are no reports, no licence overview and no party that answers for how current the vulnerability data is.

Our advice

  • Solo: Use the code host's built-in tools first, such as Dependabot. Take Snyk's free plan only with the US region in mind.
  • Mid-market: Up to ten developers, Team is enough if the US region is acceptable. Beyond that, compare GitHub Code Security and Aikido against Snyk's credit bill.
  • Enterprise: Buy if several code hosts need checking. Settle a deletion deadline after contract end, the Frankfurt region and how expiring credits are handled in writing before signing.

Who is behind it

Staying power: Established

In the market since 2015; the parent company is Snyk Limited in London, and the US company is based in Boston. According to the last published group accounts, revenue grew 26 percent in 2024 to 278.4 million US dollars, the operating loss was 188.4 million US dollars, and cash and investments stood at 412.4 million US dollars. The 2025 accounts were filed with the UK register on 28.09.2026 and are not yet available. Leadership changed in 2026: the long-standing chief executive handed over to an interim chief executive in April and left the board in May, and the co-founder has been a director again since March.

  • Company registration: Snyk Limited, Companies House no. 09677925, incorporated on 09.07.2015, registered in LondonAs of 2026-09-29Company registration of Snyk Limited, incorporated 9 July 2015Open source · As of 2026-09-29
  • Last published annual figures: Fiscal 2024: revenue 278.4 million US dollars (up 26 percent), operating loss 188.4 million US dollars, net loss 166.5 million US dollars, cash and investments 412.4 million US dollars, 4,478 customers, 1,162 employees, audited by PricewaterhouseCoopersAs of 2026-09-29Group accounts for 2024 and filing of the 2025 accounts on 28 September 2026Open source · As of 2026-09-29
  • Leadership change: Former chief executive Peter McKay left the board on 15.05.2026, after handing over in April to chief financial officer Ken MacAskill as interim chief executive; co-founder Guy Podjarny a director again since 27.03.2026As of 2026-09-29Peter McKay left on 15 May 2026, Guy Podjarny a director again since 27 March 2026Open source · As of 2026-09-29
  • Job cuts: Around 90 jobs cut, reported on 24.06.2026, according to the report the fourth round since 2022As of 2026-09-29Around 90 jobs cut, reported on 24 June 2026Open source · As of 2026-09-29
  • Documented vulnerability: CVE-2025-6624, credentials in local debug logs of the Snyk command-line tool before version 1.1297.3, published on 26.06.2025, rated 2.4 (low) under CVSS 4.0 and 7.2 (high) under CVSS 3.1As of 2026-09-29CVE-2025-6624, Snyk command-line tool before version 1.1297.3, CVSS 4.0 score 2.4 and CVSS 3.1 score 7.2Open source · As of 2026-09-29
  • Incident at a service provider: Incident at vendor Klue in June 2026: unauthorised parties accessed contact, contract and support data from Snyk's CRM, the platform was not affected according to Snyk; investigation closed on 08.07.2026As of 2026-09-29Incident at vendor Klue in June 2026, investigation closed on 8 July 2026Open source · As of 2026-09-29

Cost of leaving: Moderate

The findings themselves can be regenerated with any other scanner by running it again over the same repositories. What is missing after the switch is what grew in operation: justified exceptions for accepted risks, licence rules, check thresholds in the build pipeline, links to Jira and the history that shows auditors since when a finding was known. Then there is the contract: on the Enterprise plan, credits are bought in advance and expire unused at the end of the term.

Regulation and data

How to read the traffic lightHow to read the traffic lightThe traffic light rates how well a point is evidenced, not how good the tool is. It draws only on the value, note and source held in the profile. Where a statement is missing, it rates the absence, not a guess. A well-reasoned "unclear" on a point that matters little for this tool is yellow. A missing source on a point that decides whether you can use it at all is red.documented, no condition attacheddocumented, tied to a conditiondocumented, but unfavourableopen on a point that decides usability
Data processing agreementScale for this point: Data processing agreementdocumented, no condition attached: Auftragsverarbeitungsvertrag öffentlich abrufbar und ohne weitere Bedingung Bestandteil des Vertrags; oder er entfällt nachvollziehbar begründet, weil kein Anbieter Kundendaten verarbeitet.documented, tied to a condition: Vertrag existiert, ist aber an einen Tarif gebunden, nur nach Anfrage einsehbar oder allein in den Nutzungsbedingungen geregelt statt als eigenes Dokument.documented, but unfavourable: Kein Auftragsverarbeitungsvertrag im üblichen Sinn: entweder weil der Anbieter für das Kerngeschäft eigenständig Verantwortlicher ist und stattdessen eine andere Konstruktion gilt, oder weil öffentlich offen bleibt, ob überhaupt einer angeboten wird.open on a point that decides usability: Weder ein Vertrag noch ein dokumentierter Weg zu einem Vertrag; der Einkauf hätte nichts, worauf er sich stützen kann.documented, no condition attachedpublicly available, version of 27.01.2026, part of the terms of service and the master services agreementAs of 2026-09-29Data processing agreement of 27 January 2026: standard contractual clauses module 2, Irish supervisory authority, 30-day subprocessor notice, unilateral amendment with seven days' noticeOpen sourceThe agreement applies without a separate signature, and the Irish authority is the supervisory authority for the standard contractual clauses. Snyk may amend it unilaterally on changes in law, restructuring or new features with seven days' notice; continued use counts as consent.As of 2026-09-29
Storage locationScale for this point: Storage locationdocumented, no condition attached: EU-Speicherort ohne Zusatzkosten und ohne Tarifbindung, oder der Ort ist vollständig selbst bestimmbar, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: EU-Speicherort möglich, aber an einen Tarif, einen gesondert zu aktivierenden Zusatz oder einen Umzug in eine getrennte Umgebung gebunden; oder die EU-Region ist nicht die Voreinstellung.documented, but unfavourable: Kein EU-Speicherort, der Ort ist aber eindeutig benannt, sodass die Folgen bewertbar sind.open on a point that decides usability: Der Speicherort ist öffentlich nicht benannt oder vom Kunden nicht steuerbar, sodass sich die Verarbeitung nicht verorten lässt.documented, tied to a conditionFrankfurt region (SNYK-EU-01) on the Enterprise plan only; the default, and the only region for Free and Team, is the United States; sign-in data, support and product analytics are stored globallyAs of 2026-09-29Regions and data residency exceptions, Frankfurt region on the Enterprise plan onlyOpen sourceVulnerability data, source code, audit logs and integration data stay in the chosen region. According to the documentation, billing, customer relationship data, operational logs, product analytics, support tickets and user authentication data are excluded.As of 2026-09-29
SubprocessorsScale for this point: Subprocessorsdocumented, no condition attached: Vollständige öffentliche Liste der Unterauftragnehmer mit Zweck und Land; oder es gibt keine, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Liste existiert und ist benannt, aber nur nach Anfrage oder nach Zugang zu einem Vertrauensportal einsehbar, oder sie nennt Zweck und Land nicht vollständig.documented, but unfavourable: Keine geführte Liste; namentlich stehen nur einzelne Dienste in der Datenschutzerklärung, überwiegend solche der eigenen Website.open on a point that decides usability: Weder eine Liste noch eine Nennung der Verarbeiter des Produkts, und kein dokumentierter Weg, sie zu erfahren.documented, no condition attachedpublic list with purpose and location for each subprocessor, last changed on 03.02.2026As of 2026-09-29Subprocessors with purpose and location, as of 3 February 2026, including OpenAI, Google Vertex and AWS BedrockOpen sourceFor the AI functions, the list names OpenAI and Google Vertex located in the United States and AWS Bedrock located at the customer's choice. New subprocessors are announced 30 days in advance, and a reasoned objection is possible within that period.As of 2026-09-29
Third-country transferScale for this point: Third-country transferdocumented, no condition attached: Keine Übermittlung in ein Drittland, oder die Übermittlung findet statt und die Grundlage ist benannt und im Vertrag verankert, etwa Standardvertragsklauseln, Angemessenheitsbeschluss oder EU-US-Datenschutzrahmen.documented, tied to a condition: Übermittlung findet statt, eine Grundlage ist genannt, aber ohne Zuordnung, welcher Empfänger auf welcher Grundlage arbeitet.documented, but unfavourable: Übermittlung findet statt und die eigenen Unterlagen widersprechen sich, oder die genannte Grundlage bezieht sich erkennbar nur auf einen Randbereich wie die Marketing-Website.open on a point that decides usability: Übermittlung findet erkennbar statt und eine Grundlage wird nirgends genannt.documented, tied to a conditionworldwide transfers permitted, based on standard contractual clauses module 2, the UK addendum and Swiss clausesAs of 2026-09-29Data processing agreement of 27 January 2026: standard contractual clauses module 2, Irish supervisory authority, 30-day subprocessor notice, unilateral amendment with seven days' noticeOpen sourceThe clauses govern transfers from the customer to Snyk. For onward transfers to subprocessors, the agreement only commits to taking the necessary measures, without naming a basis per recipient. Snyk is not on the participant list of the EU-US Data Privacy Framework (checked 29.09.2026).As of 2026-09-29
Training on customer dataScale for this point: Training on customer datadocumented, no condition attached: Vertraglich oder in der Datenschutzerklärung ausdrücklich ausgeschlossen, mit Erstreckung auf die eingesetzten Modellanbieter; oder es gibt keine Datenübertragung an einen Anbieter.documented, tied to a condition: Ausschluss ab einem bestimmten Tarif, oder die Zusage steht nur auf einer Dokumentationsseite statt im Vertrag, oder die Frage stellt sich für das Werkzeug sachlich kaum und der Anbieter schweigt dazu.documented, but unfavourable: Nutzung ist die Voreinstellung und nur ein Widerspruch beendet sie; oder der Anbieter trainiert eigene Modelle auf bereinigten Kundendaten.open on a point that decides usability: Keine Aussage, obwohl das Werkzeug KI-Funktionen auf Kundeninhalten betreibt.documented, no condition attachedcontractually excluded for inputs to AI models, extending to affiliates and subprocessorsAs of 2026-09-29Terms of service of 18 September 2026: no training on inputs, deletion by the customer, security incident notice within 72 hoursOpen sourceThe terms of service of 18.09.2026 rule out using inputs to train or improve AI models, except for customisations that run for that customer only. Snyk may analyse usage data excluding inputs to improve the services. According to the documentation, the fix model for Snyk Code learns only from public repositories with permissive licences.As of 2026-09-29
Retention and deletionScale for this point: Retention and deletiondocumented, no condition attached: Löschfristen nach Vertragsende beziffert und die Löschung oder Rückgabe zugesagt; oder die Fristen bestimmt der Betreiber selbst, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Löschung ist zugesagt, die Fristen sind aber nur teilweise beziffert, oder Sicherungskopien sind ausdrücklich ausgenommen.documented, but unfavourable: Nur der Grundsatz der Erforderlichkeit ohne jede Frist nach Vertragsende, oder Fristen sind allein für Randbereiche wie Website-Protokolle genannt.open on a point that decides usability: Keine Aussage zu Aufbewahrung und Löschung.documented, but unfavourableno deletion deadline after the agreement ends; the customer is to delete the organisation and projects themselves or ask support to do so; Snyk Code source code cached for roughly 24 to 48 hours depending on region, under the cloud provider's storage rulesAs of 2026-09-29Handling of customer data per product, source code cache, no training on customer codeOpen sourceThe data processing agreement refers to the contract for deletion, and both the terms of service and the master services agreement put deletion in the customer's hands, with no deadline for deletion on the vendor's side and nothing on backups. According to the documentation, Snyk keeps issue locations and vulnerability metadata without a stated time limit.As of 2026-09-29
CertificationsScale for this point: Certificationsdocumented, no condition attached: Mehrere anerkannte Nachweise, benannt mit Norm, Fassung und Geltungsbereich, und bezogen auf den Anbieter selbst.documented, tied to a condition: Ein anerkannter Nachweis für den Anbieter belegt, der Bericht aber nur auf Anfrage, oder der Nachweis hängt an einem Tarif, oder der Geltungsbereich bleibt teilweise offen.documented, but unfavourable: Nur pauschale Nennung ohne Norm-Fassung und Geltungsbereich, oder bloße Selbstauskunft, oder die Nachweise gehören dem Infrastrukturanbieter statt dem Anbieter, oder der Prüfzeitraum ist erkennbar veraltet, oder die eigenen Angaben widersprechen sich.open on a point that decides usability: Kein Nachweis genannt und keine Sicherheits- oder Vertrauensseite vorhanden.documented, tied to a conditionISO 27001:2022 and ISO 27017:2015 for all services except Snyk API & Web, SOC 2 Type II, audited externally every year; certificate and report through the Trust Center once access is grantedAs of 2026-09-29ISO 27001:2022 and ISO 27017:2015 for all services except Snyk API & Web, SOC 2 Type II, security addendum of 28 January 2026Open sourceVersion and scope are stated in the security addendum of 28.01.2026 and in the Trust Center. Snyk releases the certificate and the SOC 2 report only on request through the Trust Center or the account team, and no certificate number is published. In the master services agreement, Snyk commits to maintaining both for the term of the contract.As of 2026-09-29
EU AI Act, Article 50Scale for this point: EU AI Act, Article 50documented, no condition attached: Der Anbieter macht eine belegte Aussage, die die eigene Pflicht trägt, etwa Modelldokumentation und Zertifizierung nach ISO/IEC 42001; oder das Werkzeug enthält nachvollziehbar begründet kein KI-System im Sinne der Verordnung.documented, tied to a condition: Der Anbieter äußert sich zur Verordnung oder ordnet die eigene Funktion ein, eine benannte Zusage zu den Transparenzpflichten aus Artikel 50 fehlt aber; oder das Werkzeug enthält kein KI-System, das gegenüber Menschen auftritt, und der Anbieter schweigt.documented, but unfavourable: Das Produkt enthält KI-Funktionen, der Anbieter schweigt dazu oder trägt ein Selbstetikett ohne Nachweis; die Kennzeichnung ist vom Betreiber aber selbst setzbar.open on a point that decides usability: KI spricht im Produkt unmittelbar mit Endkunden und der Anbieter sagt zu Artikel 50 nichts; die Kennzeichnung lässt sich ohne Zusage des Anbieters nicht sicher setzen.documented, tied to a conditionAI Act not named; the terms of service classify the AI functions as decision support with human review and commit to model documentation on requestAs of 2026-09-29Terms of service of 18 September 2026: no training on inputs, deletion by the customer, security incident notice within 72 hoursOpen sourceSection 5.4 of the terms of service of 18.09.2026 describes an AI compliance programme covering transparency, risk management and human oversight, without naming the AI Act or Article 50. The documentation lists purpose, model and processed data for each AI function. The functions address in-house developers, so labelling towards end customers hardly arises.As of 2026-09-29
Audit loggingScale for this point: Audit loggingdocumented, no condition attached: Nachvollziehbares Protokoll über Zugriffe und Änderungen in allen Tarifen enthalten, mit benannter Frist und Ausleitung in eigene Systeme; oder die Nachvollziehbarkeit liegt vollständig in eigener Hand, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Protokoll vorhanden, aber an einen höheren Tarif oder einen kostenpflichtigen Zusatz gebunden, oder die Ausleitung fehlt in den unteren Stufen; Reichweite und Frist sind benannt.documented, but unfavourable: Protokolle sind nur anbieterseitig beschrieben, oder Reichweite und Frist bleiben offen, sodass sich Nachweispflichten nicht planen lassen.open on a point that decides usability: Öffentlich nicht belegt, ob der Kunde überhaupt ein auswertbares Protokoll erhält.documented, tied to a conditionaudit log on the Enterprise plan only, retrievable through the API for the last 90 days; sign-ins and sign-outs are not includedAs of 2026-09-29Audit log on the Enterprise plan only, 90 days, without sign-ins and sign-outsOpen sourceThe log captures changes to groups, organisations and settings, invitations and role changes, licence rules and service accounts. For analysis in your own systems, Google Security Operations and Panther offer ready-made connectors that pull the log through the API.As of 2026-09-29

What it really costs

Entry price

Free costs nothing, Team starts at 25 US dollars a month for up to ten developers. On the Enterprise plan you buy credits in advance, one credit equalling one US dollar: code and dependency checks cost one credit each per active contributor per day, so together about 730 US dollars per person per year at list rates.As of 2026-09-29Free and Team plans, Team for up to ten developers from 25 US dollars, credit rate card on the Enterprise plan, one credit equals one US dollarOpen source

As of 2026-09-29

What gets expensive

Every identity that has committed to a monitored private repository in the last 90 days counts as active, including bots, service accounts and commits under a personal email address, and it is charged for every calendar day. Containers, infrastructure, secrets and the Evo functions each add their own rate, and an AI penetration test costs 4,000 credits. Unused credits expire at the end of the contract, and overuse is invoiced in arrears.

What it displaces

  • Spreadsheets of libraries in use and their versions
  • Reading security advisories for dependencies by hand
  • Separate check scripts per repository without a shared report
  • Open-source licence checks just before a sale

Interfaces

  • Integration with GitHub, GitLab, Bitbucket and Azure Repos
  • Extensions for VS Code, JetBrains and other development environments
  • Command-line tool for build pipelines
  • Sign-in through SAML and OpenID Connect (Enterprise)
  • Audit log via the API (Enterprise)
  • Jira integration from Team upwards

Matching methods

  • Regulatory Density TestThe Cyber Resilience Act requires every manufacturer alike to handle known vulnerabilities, and the test classifies a bought scanner as meeting that duty without creating an edge.
  • DORA Delivery DiagnosticA check in the build lengthens the lead time of every change, and the diagnosis shows whether that actually raises stability or only adds waiting time.
  • DORA AI Capabilities Model (Seven AI Capabilities)Anyone letting AI write code at scale needs automated checking as a guardrail, and the model asks whether that guardrail is part of your own platform or missing.

Alternatives

Sources

  1. 1.Free and Team plans, Team for up to ten developers from 25 US dollars, credit rate card on the Enterprise plan, one credit equals one US dollar (opens in a new tab)snyk.io/plans · As of 2026-09-29
  2. 2.Billing per active contributor per calendar day, 90-day window, expiry of unused credits, overuse invoiced in arrears, as of 4 August 2026 (opens in a new tab)snyk.io/policies/credit-based-billing · As of 2026-09-29
  3. 3.Data processing agreement of 27 January 2026: standard contractual clauses module 2, Irish supervisory authority, 30-day subprocessor notice, unilateral amendment with seven days' notice (opens in a new tab)snyk.io/policies/dpa · As of 2026-09-29
  4. 4.Terms of service of 18 September 2026: no training on inputs, deletion by the customer, security incident notice within 72 hours (opens in a new tab)snyk.io/policies/terms-of-service · As of 2026-09-29
  5. 5.Subprocessors with purpose and location, as of 3 February 2026, including OpenAI, Google Vertex and AWS Bedrock (opens in a new tab)snyk.io/policies/subprocessors · As of 2026-09-29
  6. 6.Regions and data residency exceptions, Frankfurt region on the Enterprise plan only (opens in a new tab)docs.snyk.io/…/regional-hosting-and-data-residency · As of 2026-09-29
  7. 7.Handling of customer data per product, source code cache, no training on customer code (opens in a new tab)docs.snyk.io/snyk-data-and-governance/how-snyk-handles-your-data · As of 2026-09-29
  8. 8.Audit log on the Enterprise plan only, 90 days, without sign-ins and sign-outs (opens in a new tab)docs.snyk.io/… · As of 2026-09-29
  9. 9.Single sign-on on the Enterprise plan only (opens in a new tab)docs.snyk.io/…/single-sign-on-sso-for-authentication-to-snyk · As of 2026-09-29
  10. 10.ISO 27001:2022 and ISO 27017:2015 for all services except Snyk API & Web, SOC 2 Type II, security addendum of 28 January 2026 (opens in a new tab)snyk.io/policies/snyk-security-addendum · As of 2026-09-29
  11. 11.Company registration of Snyk Limited, incorporated 9 July 2015 (opens in a new tab)find-and-update.company-information.service.gov.uk/…/09677925 · As of 2026-09-29
  12. 12.Group accounts for 2024 and filing of the 2025 accounts on 28 September 2026 (opens in a new tab)find-and-update.company-information.service.gov.uk/… · As of 2026-09-29
  13. 13.Peter McKay left on 15 May 2026, Guy Podjarny a director again since 27 March 2026 (opens in a new tab)find-and-update.company-information.service.gov.uk/…/officers · As of 2026-09-29
  14. 14.Around 90 jobs cut, reported on 24 June 2026 (opens in a new tab)en.globes.co.il/… · As of 2026-09-29
  15. 15.CVE-2025-6624, Snyk command-line tool before version 1.1297.3, CVSS 4.0 score 2.4 and CVSS 3.1 score 7.2 (opens in a new tab)cve.org/CVERecord?id=CVE-2025-6624 · As of 2026-09-29
  16. 16.GitHub Secret Protection at 19 and Code Security at 30 US dollars per active committer per month, since April 2025 (opens in a new tab)github.blog/… · As of 2026-09-29
  17. 17.Claude Code Security introduced as a limited preview on 20 February 2026 (opens in a new tab)anthropic.com/news/claude-code-security · As of 2026-09-29
  18. 18.Aikido plans with flat prices (opens in a new tab)aikido.dev/pricing · As of 2026-09-29
  19. 19.Aikido funding round of 60 million US dollars on 14 January 2026 (opens in a new tab)aikido.dev/blog/aikido-funding-series-b · As of 2026-09-29
  20. 20.Claude Security as a public beta for Enterprise customers since 30 April 2026, findings exportable as CSV or Markdown (opens in a new tab)claude.com/blog/claude-security-public-beta · As of 2026-09-29
  21. 21.Handover to chief financial officer Ken MacAskill as interim chief executive in April 2026 (opens in a new tab)bostonglobe.com/…/rapid7-layoffs-snyk-cybersecurity-jobs · As of 2026-09-29
  22. 22.Cyber Resilience Act (EU) 2024/2847: reporting duties from 11 September 2026, remaining duties from 11 December 2027 (opens in a new tab)eur-lex.europa.eu/eli/reg/2024/2847/oj · As of 2026-09-29
  23. 23.Dependabot alerts based on the GitHub Advisory Database (opens in a new tab)docs.github.com/…/about-dependabot-alerts · As of 2026-09-29
  24. 24.Incident at vendor Klue in June 2026, investigation closed on 8 July 2026 (opens in a new tab)trust.snyk.io · As of 2026-09-29
  25. 25.Snyk not on the EU-US Data Privacy Framework participant list (opens in a new tab)dataprivacyframework.gov/list · As of 2026-09-29

Last reviewed: 2026-09-29 by Dr. Oliver Gausmann, Convios GmbH

Details out of date? Let us know.

From tool to decision

The offer that fits this tool

A tool profile tells you what the tool does and what it means for compliance. Whether it gets priority in your company is a management decision, and it takes one working day: the executive AI workshop ranks your initiatives by business value, risk, data readiness and ownership.