Cybersecurity · sub-niche
OSS vulnerability graphs.
The dependency graph for open source vulnerabilities, indexed for AI agents and humans.
Reading the two labels: one-quarter build build cost means expect a quarter of sustained build time, usually two or three people, before first external users. Trickle, one deal per quarter deal velocity means few rounds land in this category in a given year, buyers are rare.
Quick take: OSS vulnerability graphs is a one-quarter build-cost, trickle, one deal per quarter-velocity opportunity inside Cybersecurity, with 3 public reference points. Open data is the wedge; commercialization is the platform on top. Fund only with prior security infra background.
Why now
Agents need machine-readable security context. The graph layer is unbuilt or buried inside paid products.
What the signal looks like
Repos with CVE / OSV ingestion, dependency-graph build pipelines, and MCP / API surfaces.
Public examples
We name publicprojects + categories only, never founders we track inside the paid product. The buyer’s edge stays inside the product.
- GUAC / OSV graph projects
- Snyk Knowledge Base
- OWASP-style open repos
What this displaces
A CVE database + npm audit + grep.
How to validate it in an afternoon
Before committing build time or a thesis memo to oss vulnerability graphs, run three cheap checks against public engineering activity. Each takes minutes and none require access to private data.
- Count active builders. Search GitHub for repositories matching this category, then check how many accepted commits in the last 14 days. More than a handful of active teams means the category has energy, not just mentions.
- Look for the trickle, one deal per quarter pattern in funding. If funded companies keep appearing here, few rounds land in this category in a given year, buyers are rare. Cross-check the cybersecurity leaderboard to see whether any of the accelerators sit adjacent to this niche.
- Test the one-quarter build cost assumption honestly: expect a quarter of sustained build time, usually two or three people, before first external users. If your calendar cannot absorb that, the opportunity is real but not yours yet.
The weekly signal feed tracks 10 Cybersecurity sub-niches including this one, so the cohort side of this check can run continuously instead of manually.
Our build-vs-invest call
Open data is the wedge; commercialization is the platform on top. Fund only with prior security infra background.
Common questions about this niche
- Who pays?
- Security platforms paying for higher-fidelity data.
- Moat?
- Data freshness + graph completeness + API ergonomics.
- Build or fund?
- Build only with prior security data background; fund teams with named security backgrounds.
Five breakout startups, every Sunday, before the round gets crowded
The free Acceleration Watch: five venture-backed teams accelerating on the engineering signal, translated into plain English, 21 to 47 days before the deck circulates. No code-reading, no card.
More inside Cybersecurity
- LLM firewall tooling WAF for AI agents, prompt injection blocking, output sanitization, policy enforcement at the API boundary.
- Supply chain attack detectors Catch malicious npm / PyPI packages before they land in production.
- Secret rotation automation Secrets that rotate themselves, across HashiCorp Vault, AWS Secrets Manager, GitHub, and your CI.
- Cloud config drift detection Continuous detection of AWS / GCP / Azure config drift, plus AI-suggested remediation.