# Snyk

> Checks your own source code, embedded open-source libraries, container images and infrastructure configuration for known vulnerabilities and licence risks, right in the development environment, the repository and the build. For each finding it proposes a fix, for dependencies usually as a ready-made pull request.

- Vendor: Snyk Limited, London
- Canonical URL: https://www.convios.com/en/toolbox/snyk
- Language version: https://www.convios.com/de/werkzeugkasten/snyk
- Area: Governance & security · Cluster: vulnerabilities in your own code
- Role: Off-the-shelf product · Origin: Established, AI retrofitted
- As of: 2026-09-29 · Reviewed: 2026-09-29 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: Anyone shipping software has to show which libraries are inside it and which known vulnerabilities are open. Large customers' security questionnaires ask for this, as does every technical due diligence, and so does the EU Cyber Resilience Act, whose reporting duties for actively exploited vulnerabilities have applied since 11.09.2026 and whose remaining duties for products with digital elements apply from 11.12.2027. With AI-written code, the volume of changes someone has to check grows faster than any team. Automated checks in the build keep you level with the market, and every competitor can buy them as well.

## Suitability by company size

- Solo: suitable with caveats — The free plan checks five projects and allows 100 code tests a month. It runs in the US region only, and signing in through your own company identity provider only comes with the Enterprise plan.
- Mid-market: suitable with caveats — The Team plan from 25 US dollars a month is designed for at most ten developers and also runs in the US region only. Anyone larger, or anyone who wants to keep data in the EU, ends up on the Enterprise plan with credit billing, whose entry point is negotiated through sales.
- Enterprise: suitable — The Enterprise plan brings the Frankfurt region, sign-in through SAML or OpenID Connect, a change log via the API and SOC 2 reports through the account team. A contractual deletion deadline after the agreement ends remains open and should be agreed in writing before signing.

## Vendor staying power

Established: In the market since 2015; the parent company is Snyk Limited in London, and the US company is based in Boston. According to the last published group accounts, revenue grew 26 percent in 2024 to 278.4 million US dollars, the operating loss was 188.4 million US dollars, and cash and investments stood at 412.4 million US dollars. The 2025 accounts were filed with the UK register on 28.09.2026 and are not yet available. Leadership changed in 2026: the long-standing chief executive handed over to an interim chief executive in April and left the board in May, and the co-founder has been a director again since March.

- Company registration: Snyk Limited, Companies House no. 09677925, incorporated on 09.07.2015, registered in London (source: https://find-and-update.company-information.service.gov.uk/company/09677925, as of 2026-09-29)
- Last published annual figures: Fiscal 2024: revenue 278.4 million US dollars (up 26 percent), operating loss 188.4 million US dollars, net loss 166.5 million US dollars, cash and investments 412.4 million US dollars, 4,478 customers, 1,162 employees, audited by PricewaterhouseCoopers (source: https://find-and-update.company-information.service.gov.uk/company/09677925/filing-history, as of 2026-09-29)
- Leadership change: Former chief executive Peter McKay left the board on 15.05.2026, after handing over in April to chief financial officer Ken MacAskill as interim chief executive; co-founder Guy Podjarny a director again since 27.03.2026 (source: https://find-and-update.company-information.service.gov.uk/company/09677925/officers, as of 2026-09-29)
- Job cuts: Around 90 jobs cut, reported on 24.06.2026, according to the report the fourth round since 2022 (source: https://en.globes.co.il/en/article-snyk-to-lay-off-90-employees-1001546903, as of 2026-09-29)
- Documented vulnerability: CVE-2025-6624, credentials in local debug logs of the Snyk command-line tool before version 1.1297.3, published on 26.06.2025, rated 2.4 (low) under CVSS 4.0 and 7.2 (high) under CVSS 3.1 (source: https://www.cve.org/CVERecord?id=CVE-2025-6624, as of 2026-09-29)
- Incident at a service provider: Incident at vendor Klue in June 2026: unauthorised parties accessed contact, contract and support data from Snyk's CRM, the platform was not affected according to Snyk; investigation closed on 08.07.2026 (source: https://trust.snyk.io/, as of 2026-09-29)

## Cost of leaving

Moderate: The findings themselves can be regenerated with any other scanner by running it again over the same repositories. What is missing after the switch is what grew in operation: justified exceptions for accepted risks, licence rules, check thresholds in the build pipeline, links to Jira and the history that shows auditors since when a finding was known. Then there is the contract: on the Enterprise plan, credits are bought in advance and expire unused at the end of the term.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | publicly available, version of 27.01.2026, part of the terms of service and the master services agreement — The agreement applies without a separate signature, and the Irish authority is the supervisory authority for the standard contractual clauses. Snyk may amend it unilaterally on changes in law, restructuring or new features with seven days' notice; continued use counts as consent. | evidenced | 2026-09-29 |
| Storage location | Frankfurt region (SNYK-EU-01) on the Enterprise plan only; the default, and the only region for Free and Team, is the United States; sign-in data, support and product analytics are stored globally — Vulnerability data, source code, audit logs and integration data stay in the chosen region. According to the documentation, billing, customer relationship data, operational logs, product analytics, support tickets and user authentication data are excluded. | partially evidenced | 2026-09-29 |
| Subprocessors | public list with purpose and location for each subprocessor, last changed on 03.02.2026 — For the AI functions, the list names OpenAI and Google Vertex located in the United States and AWS Bedrock located at the customer's choice. New subprocessors are announced 30 days in advance, and a reasoned objection is possible within that period. | evidenced | 2026-09-29 |
| Third-country transfer | worldwide transfers permitted, based on standard contractual clauses module 2, the UK addendum and Swiss clauses — The clauses govern transfers from the customer to Snyk. For onward transfers to subprocessors, the agreement only commits to taking the necessary measures, without naming a basis per recipient. Snyk is not on the participant list of the EU-US Data Privacy Framework (checked 29.09.2026). | partially evidenced | 2026-09-29 |
| Training on customer data | contractually excluded for inputs to AI models, extending to affiliates and subprocessors — The terms of service of 18.09.2026 rule out using inputs to train or improve AI models, except for customisations that run for that customer only. Snyk may analyse usage data excluding inputs to improve the services. According to the documentation, the fix model for Snyk Code learns only from public repositories with permissive licences. | evidenced | 2026-09-29 |
| Retention and deletion | no deletion deadline after the agreement ends; the customer is to delete the organisation and projects themselves or ask support to do so; Snyk Code source code cached for roughly 24 to 48 hours depending on region, under the cloud provider's storage rules — The data processing agreement refers to the contract for deletion, and both the terms of service and the master services agreement put deletion in the customer's hands, with no deadline for deletion on the vendor's side and nothing on backups. According to the documentation, Snyk keeps issue locations and vulnerability metadata without a stated time limit. | partially evidenced | 2026-09-29 |
| Certifications | ISO 27001:2022 and ISO 27017:2015 for all services except Snyk API & Web, SOC 2 Type II, audited externally every year; certificate and report through the Trust Center once access is granted — Version and scope are stated in the security addendum of 28.01.2026 and in the Trust Center. Snyk releases the certificate and the SOC 2 report only on request through the Trust Center or the account team, and no certificate number is published. In the master services agreement, Snyk commits to maintaining both for the term of the contract. | partially evidenced | 2026-09-29 |
| EU AI Act, Article 50 | AI Act not named; the terms of service classify the AI functions as decision support with human review and commit to model documentation on request — Section 5.4 of the terms of service of 18.09.2026 describes an AI compliance programme covering transparency, risk management and human oversight, without naming the AI Act or Article 50. The documentation lists purpose, model and processed data for each AI function. The functions address in-house developers, so labelling towards end customers hardly arises. | partially evidenced | 2026-09-29 |
| Audit logging | audit log on the Enterprise plan only, retrievable through the API for the last 90 days; sign-ins and sign-outs are not included — The log captures changes to groups, organisations and settings, invitations and role changes, licence rules and service accounts. For analysis in your own systems, Google Security Operations and Panther offer ready-made connectors that pull the log through the API. | partially evidenced | 2026-09-29 |

## Cost

- Entry: Free costs nothing, Team starts at 25 US dollars a month for up to ten developers. On the Enterprise plan you buy credits in advance, one credit equalling one US dollar: code and dependency checks cost one credit each per active contributor per day, so together about 730 US dollars per person per year at list rates. (as of 2026-09-29)
- Where it gets expensive: Every identity that has committed to a monitored private repository in the last 90 days counts as active, including bots, service accounts and commits under a personal email address, and it is charged for every calendar day. Containers, infrastructure, secrets and the Evo functions each add their own rate, and an AI penetration test costs 4,000 credits. Unused credits expire at the end of the contract, and overuse is invoiced in arrears.

## Three routes compared

### GitHub Code Security and Secret Protection

Anyone keeping code on GitHub anyway gets Dependabot's dependency alerts at no extra cost and, since April 2025, can add code and secret scanning separately for 30 and 19 US dollars per active committer per month. That saves a second contract and a second interface. Snyk, in turn, checks across GitHub, GitLab, Bitbucket and Azure Repos, which tips the balance for mixed code hosting after acquisitions.

### Claude Security from Anthropic, alongside Aikido

Anthropic introduced Claude Code Security as a limited preview on 20.02.2026 and released it as a public beta for Enterprise customers under the name Claude Security on 30.04.2026. The model reads the code, traces data flows across components and proposes fixes that a developer approves; findings can be exported as CSV or Markdown. Prices are not published. None of Anthropic's publications describes checks of open-source dependencies or licences (as of 29.09.2026). Aikido bundles similar checks with AI pre-triage at flat prices, with paid plans from 300 US dollars a month including ten users and a free entry tier for two users, and closed a 60 million US dollar funding round in January 2026.

### Open-source scanners in your own build pipeline

The building blocks are freely available: OSV-Scanner for dependencies against the open OSV database, Semgrep Community Edition for code, Trivy for containers and infrastructure, Gitleaks for secrets. In GitHub or GitLab they run as a step on every pull request; Claude Code can write custom rules and fix suggestions, LiteLLM and Langfuse can steer and log an AI pre-triage of findings, and credentials sit in Infisical. It gets hard in two places. Someone has to sort false alarms, maintain rules and justify exceptions, every week. And for an audit there are no reports, no licence overview and no party that answers for how current the vulnerability data is.

Recommendation by size:

- Solo: Use the code host's built-in tools first, such as Dependabot. Take Snyk's free plan only with the US region in mind.
- Mid-market: Up to ten developers, Team is enough if the US region is acceptable. Beyond that, compare GitHub Code Security and Aikido against Snyk's credit bill.
- Enterprise: Buy if several code hosts need checking. Settle a deletion deadline after contract end, the Frankfurt region and how expiring credits are handled in writing before signing.

## Context

- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The Cyber Resilience Act requires every manufacturer alike to handle known vulnerabilities, and the test classifies a bought scanner as meeting that duty without creating an edge.
- Implements method: [DORA Delivery Diagnostic](https://www.convios.com/en/methods/dora-delivery-diagnose) — A check in the build lengthens the lead time of every change, and the diagnosis shows whether that actually raises stability or only adds waiting time.
- Implements method: [DORA AI Capabilities Model (Seven AI Capabilities)](https://www.convios.com/en/methods/dora-ai-capabilities) — Anyone letting AI write code at scale needs automated checking as a guardrail, and the model asks whether that guardrail is part of your own platform or missing.
- Alternative: [GitHub](https://www.convios.com/en/toolbox/github)
- Alternative: [GitLab](https://www.convios.com/en/toolbox/gitlab)
- Alternative: [CodeRabbit](https://www.convios.com/en/toolbox/coderabbit)
- Displaces: Spreadsheets of libraries in use and their versions, Reading security advisories for dependencies by hand, Separate check scripts per repository without a shared report, Open-source licence checks just before a sale

## Evidence

- Free and Team plans, Team for up to ten developers from 25 US dollars, credit rate card on the Enterprise plan, one credit equals one US dollar — https://snyk.io/plans/ (as of 2026-09-29)
- Billing per active contributor per calendar day, 90-day window, expiry of unused credits, overuse invoiced in arrears, as of 4 August 2026 — https://snyk.io/policies/credit-based-billing/ (as of 2026-09-29)
- Data processing agreement of 27 January 2026: standard contractual clauses module 2, Irish supervisory authority, 30-day subprocessor notice, unilateral amendment with seven days' notice — https://snyk.io/policies/dpa/ (as of 2026-09-29)
- Terms of service of 18 September 2026: no training on inputs, deletion by the customer, security incident notice within 72 hours — https://snyk.io/policies/terms-of-service/ (as of 2026-09-29)
- Subprocessors with purpose and location, as of 3 February 2026, including OpenAI, Google Vertex and AWS Bedrock — https://snyk.io/policies/subprocessors/ (as of 2026-09-29)
- Regions and data residency exceptions, Frankfurt region on the Enterprise plan only — https://docs.snyk.io/snyk-data-and-governance/regional-hosting-and-data-residency (as of 2026-09-29)
- Handling of customer data per product, source code cache, no training on customer code — https://docs.snyk.io/snyk-data-and-governance/how-snyk-handles-your-data (as of 2026-09-29)
- Audit log on the Enterprise plan only, 90 days, without sign-ins and sign-outs — https://docs.snyk.io/platform-administration/user-management/user-management-with-the-api/retrieve-audit-logs-of-user-initiated-activity-by-api-for-an-org-or-group (as of 2026-09-29)
- Single sign-on on the Enterprise plan only — https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk (as of 2026-09-29)
- ISO 27001:2022 and ISO 27017:2015 for all services except Snyk API & Web, SOC 2 Type II, security addendum of 28 January 2026 — https://snyk.io/policies/snyk-security-addendum/ (as of 2026-09-29)
- Terms of service section 5.4 AI Compliance, without naming the AI Act — https://snyk.io/policies/terms-of-service/ (as of 2026-09-29)
- Company registration of Snyk Limited, incorporated 9 July 2015 — https://find-and-update.company-information.service.gov.uk/company/09677925 (as of 2026-09-29)
- Group accounts for 2024 and filing of the 2025 accounts on 28 September 2026 — https://find-and-update.company-information.service.gov.uk/company/09677925/filing-history (as of 2026-09-29)
- Peter McKay left on 15 May 2026, Guy Podjarny a director again since 27 March 2026 — https://find-and-update.company-information.service.gov.uk/company/09677925/officers (as of 2026-09-29)
- Around 90 jobs cut, reported on 24 June 2026 — https://en.globes.co.il/en/article-snyk-to-lay-off-90-employees-1001546903 (as of 2026-09-29)
- CVE-2025-6624, Snyk command-line tool before version 1.1297.3, CVSS 4.0 score 2.4 and CVSS 3.1 score 7.2 — https://www.cve.org/CVERecord?id=CVE-2025-6624 (as of 2026-09-29)
- GitHub Secret Protection at 19 and Code Security at 30 US dollars per active committer per month, since April 2025 — https://github.blog/changelog/2025-03-04-introducing-github-secret-protection-and-github-code-security/ (as of 2026-09-29)
- Claude Code Security introduced as a limited preview on 20 February 2026 — https://www.anthropic.com/news/claude-code-security (as of 2026-09-29)
- Aikido plans with flat prices — https://www.aikido.dev/pricing (as of 2026-09-29)
- Aikido funding round of 60 million US dollars on 14 January 2026 — https://www.aikido.dev/blog/aikido-funding-series-b (as of 2026-09-29)
- Claude Security as a public beta for Enterprise customers since 30 April 2026, findings exportable as CSV or Markdown — https://claude.com/blog/claude-security-public-beta (as of 2026-09-29)
- Handover to chief financial officer Ken MacAskill as interim chief executive in April 2026 — https://www.bostonglobe.com/2026/07/14/business/rapid7-layoffs-snyk-cybersecurity-jobs/ (as of 2026-09-29)
- Cyber Resilience Act (EU) 2024/2847: reporting duties from 11 September 2026, remaining duties from 11 December 2027 — https://eur-lex.europa.eu/eli/reg/2024/2847/oj (as of 2026-09-29)
- Dependabot alerts based on the GitHub Advisory Database — https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts (as of 2026-09-29)
- Incident at vendor Klue in June 2026, investigation closed on 8 July 2026 — https://trust.snyk.io/ (as of 2026-09-29)
- Snyk not on the EU-US Data Privacy Framework participant list — https://www.dataprivacyframework.gov/list (as of 2026-09-29)
