Six months ago, in our 2025 year-in-review, we shared that StepSecurity had grown ARR more than 5x for the second consecutive year, repeating the milestone we first announced in our 2024 year-in-review. We also committed to an ambitious 2026 roadmap: secure the developer machine, extend Harden-Runner beyond Linux, and expand protection across package ecosystems.
Halfway through the year, everything on that list has shipped, and the business is growing faster than at any point in our history. After more than 5x ARR growth in each of the last two years, 2026 is on track to be our biggest year yet.
A Step Change in Growth
- Revenue growth accelerated in H1 2026, following 5x growth in 2024 and 5x in 2025
- We closed roughly 7x more new customers than in H1 2025
Growth came from two directions: new customers, and existing customers expanding coverage. Many expansions happened before the first renewal: teams onboarded, saw value within weeks, and added more products ahead of schedule.
The Customers Have Changed
Early in our journey, StepSecurity customers were startups and small to mid-sized technology companies. That profile has fundamentally shifted. The customers we closed in H1 2026 include several publicly listed enterprises, multiple unicorns, large-scale AI companies, and market leaders in heavily regulated industries: global financial data and analytics, capital markets and asset management, mortgage and fintech, media and entertainment, online gaming, defense technology, healthcare, and enterprise software.
One signal we are especially proud of: several of the industry's best-known cybersecurity companies, including unicorn-scale security vendors used by thousands of enterprises, chose StepSecurity in H1 to protect their own development pipelines. When mature security companies whose business is protecting others select your platform, there is no stronger endorsement.
Why Now: AI Changed Both Sides of the Equation
Because of the acceleration in AI technologies, everyone is a software engineer now. The volume of code being produced and shipped through software development pipelines has exploded, and every one of those pipelines is an attack surface.
Attackers have adopted AI just as fast. Supply chain attacks that once required state-level resources and a team of security experts can now be executed by a single person with an AI coding agent. This is not speculation. Our security research team has seen the evidence directly while analyzing recent attacks: self-spreading worms that specifically target AI coding agents, malware with unmistakable signs of AI-assisted development, and attack timelines compressed from months to days.
Attackers are also shifting left. Rather than attacking hardened production environments, they target the development and delivery pipeline itself: developer machines, code repositories, package registries, and CI/CD. That is exactly the pattern we saw across H1 2026, and it makes this urgent for every company that ships software.
Protecting the Entire Pipeline, and Proving You Are Not Impacted
Security leaders now ask us two questions. The first is proactive: how do I protect my entire agentic software development and delivery pipeline? The second comes the moment an attack lands: how do I make sure I am not impacted? Protection requires controls at every stage an attacker can reach. Proving you are clean requires knowing whether a compromised package ran in CI/CD, is installed on a developer machine, or sits in a pull request or a default branch. Here is how that plays out when a popular package is compromised:
No point solution can answer either question. Tools that focus on a single stage, whether the code repository, the registry, or the build, protect one slice of the pipeline and see one slice of the exposure. Legacy application security and runtime security products were designed for a different threat model entirely. And one control is never enough: comprehensive protection requires independent layers, so prevention, detection, and mitigation never rest on one control.
This is what StepSecurity was built for, and it works in both directions. Proactively, teams deploy preventive controls at every stage before an attack ever lands: package cooldown and Secure Registry keep freshly published versions out of builds and off developer machines, Device Policy locks down what runs on engineering laptops, workflow policies and egress block mode stop malicious code from executing or exfiltrating in CI/CD. And when an incident does break somewhere in the ecosystem, the same platform proves you are protected in minutes: fleet-wide search across developer machines, package search across pull requests and default branches, and automatic cancellation of workflow runs that reference compromised components.
On the Front Lines, First, Again
In H1 2026, StepSecurity discovered, or was among the first to publicly report, many of the most consequential supply chain attacks of the year: the Axios npm compromise, the Shai-Hulud attack on TanStack, the Nx Console VS Code extension compromise that led to the breach of roughly 3,800 GitHub internal repositories (per GitHub's disclosure, documented by CISA), Microsoft's durabletask PyPI compromise, and the Red Hat cloud services npm compromises. That research feeds straight into the platform: discovery becomes automated protection across every customer environment.
The outside world noticed. Our H1 research generated more than a hundred stories across Bloomberg, TechCrunch, The Hacker News, and dozens of other publications, official CISA citations, and public credits from the maintainers of compromised projects.
Product Velocity: A Small but Mighty Team
We are a small team that gives 100%, and it shows in how fast the product moves. Our product has been evolving in direct response to real-world supply chain attacks, and in the last six months we shipped runtime security for every operating system your pipelines and developers run on, protection for every package download, and the threat intelligence to tie it all together, alongside 500+ StepSecurity Maintained Actions as secure drop-in replacements.
Every release is public: see the changelog entries for each item above and the Harden-Runner release history.
What's Next
Software supply chain security has moved from an emerging concern to a board-level requirement, and H1 2026 made the reason plain: AI has multiplied both the software being shipped and the attackers targeting it. Our job in H2 is the same as it was on day one: stay ahead of the threat, and make sure our customers do too.
Thank you to our customers for trusting us, to the community for reading and sharing our research, and to the StepSecurity team for showing up every single day. Here's to an even bigger H2.
See the platform. Request a demo or start free. Harden-Runner and Dev Machine Guard remain free for open source.
We are hiring. Growth like this needs more hands. Open roles: Account Executive, Solutions Engineer, Founding Customer Success Engineers (US and India), and Software Engineers (US and India). If you want real ownership on problems that matter, apply here.



