Coana

Denmark · owned by Socket (United States) · www.coana.tech · 7 vendors

Coana is a software composition analysis (SCA) company that uses reachability analysis — built on leading academic research from Aarhus University — to identify open source vulnerabilities that are genuinely exploitable in a codebase, eliminating over 80% of false positives. Its static analysis engine builds a call graph of the analyzed program to determine which vulnerabilities are actually reachable at runtime, allowing development teams to focus remediation efforts only on real threats. Coana was acquired by Socket, a developer-first open-source supply chain security company, in April 2025.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-14 · revision 6

7 direct vendors, 170 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Coana exhibits moderate migration readiness, primarily driven by its modern and flexible technology stack. The internal tech stack, featuring tools like GitHub, GitHub Actions, GitLab, CircleCI, Azure DevOps, and a REST API, along with product features like a CLI for on-prem use and extensive workflow integrations, suggests a modular, API-driven, and likely cloud-native environment. This foundation significantly eases the adoption of new platforms or cloud providers. However, several factors reduce its overall readiness. The complex regulatory landscape, with 'Partially Compliant' GDPR status and 'Assessment Required' for the EU Cyber Resilience Act, NIS2, and EU Dual-Use Regulation, introduces significant compliance hurdles that must be meticulously addressed during any migration. Explicit data residency requirements for operations in Denmark (EU) and the US further complicate data transfer strategies, requiring reliance on mechanisms like Standard Contractual Clauses or the EU-U.S. Data Privacy Framework. Additionally, the company's fluctuating financial stability, including a significant loss in 2024, could pose challenges in funding the substantial investments often required for large-scale migrations. Vendor lock-in appears moderate, with a reasonable number of services (8) from vendors in diverse geographies (US, Denmark) using common SaaS tools, which are generally less restrictive than highly specialized proprietary systems.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

Coana is established in Denmark, an EU member state, making GDPR directly applicable to its processing of personal data, regardless of where the data subjects are located.

As a Danish company, non-compliance with GDPR could lead to significant fines. The risk is elevated due to the processing of customer data, including from the US, which necessitates robust data transfer mechanisms.

ISO 27001 (source) — Assessment Required

Customers in the cybersecurity market often expect their vendors to adhere to internationally recognized security standards. ISO 27001 provides a framework for a comprehensive Information Security Management System (ISMS).

While not a legal requirement, ISO 27001 is a globally recognized standard for information security management. For a growing cybersecurity company, it can be a competitive advantage. The risk of not having it is primarily commercial.

US Export Administration Regulations — Assessment Required

The EAR has extraterritorial reach and applies to items of US origin and certain foreign-produced items. Coana's software, especially if it incorporates US-origin technology or is exported from the US, could be subject to these regulations.

As Coana has a US parent company (Socket) and serves US customers, it is exposed to US export control laws. Violations of EAR can result in substantial fines and restrictions on doing business in the US.

Evidence: https://www.google.com/search?q=time+in+United+States+of+America&ucbcb=1, https://www.google.com/search?q=time+in+Philadelphia,+PA,+US&ucbcb=1, https://industrialcyber.co/regulation-standards-and-compliance/eu-cyber-resilience-act-reporting-rules-take-effect-putting-vulnerability-disclosure-and-product-security-in-focus/, https://www.europarl.europa.eu/RegData/etudes/BRIE/2023/754439/EXPO_BRI(2023)754439_EN.pdf, https://www.mordorintelligence.com/industry-reports/software-composition-analysis-market, https://www.briefs.co/news/cybersecurity-startup-socket-just-hit-a-1-billion-valuation/

Financials

Three-year financials

Financial Resilience Score: 6/10

Coana ApS presents a mixed financial resilience profile. On a stand-alone basis, the Danish entity is technically insolvent with negative equity of DKK -11.6M at end-2025, having accumulated persistent operating losses of DKK 5-6M in each of the last two full years. Revenue is not disclosed under Danish micro/small entity rules, making the top-line scale opaque to outsiders. Average headcount is small (7 employees), concentrating key-person risk among the four founders. However, the risk profile is materially transformed by the April 2025 acquisition by Socket, a well-funded US software supply chain security company. As a wholly-owned subsidiary, the negative equity position is effectively backstopped by the parent. Additionally, Coana benefits from a tier-1 investor base (Sequoia Capital, Essence VC, Aarhus University), non-dilutive EU Horizon Europe EIC Transition grant funding, a differentiated technology moat in reachability-based static analysis, and blue-chip reference customers including Anthropic, OpenAI, Figma, and Vercel. Gross profit swung positively from DKK -2.01M to DKK +2.39M in FY2025, suggesting accelerating commercial traction. The overall score reflects the balance between stand-alone weakness and strong parent/investor backing.

Key strengths: Acquired by well-funded US parent Socket in April 2025, Tier-1 investor base including Sequoia Capital, Essence VC, Aarhus University, Non-dilutive EU Horizon Europe EIC Transition grant funding, Blue-chip customer roster: Anthropic, OpenAI, Figma, Vercel, Gross profit swung from DKK -2.01M to DKK +2.39M in FY2025, Differentiated reachability-based SCA technology moat

Risk factors: Negative equity of DKK -11.6M at end-2025 (technically insolvent stand-alone), Persistent operating losses of DKK 5-6M annually, Revenue not disclosed - top-line scale opaque, Small absolute scale with only ~7 average employees, Key-person risk concentrated in four founders, Post-acquisition integration risk; strategic direction now set by Socket

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report