Torq’s Quiet Bet on Jit Signals a New Phase in Cybersecurity Consolidation

Torq's acquisition of Jit merges cybersecurity automation with application security orchestration, reflecting the industry's aggressive push toward consolidated platforms as AI-generated code and rising vulnerability volumes make automated, full-cycle security operations an enterprise imperative.
Torq’s Quiet Bet on Jit Signals a New Phase in Cybersecurity Consolidation
Written by Eric Hastings

Torq, the hyperautomation cybersecurity company backed by some of the biggest names in venture capital, has agreed to acquire Jit, an Israeli startup that built its reputation on developer-first application security. The deal, announced in late April 2025, isn’t just another tuck-in acquisition. It’s a deliberate move to fuse security operations with application security under one automated roof — and it tells us something important about where the cybersecurity industry is heading next.

The terms of the acquisition were not publicly disclosed, which is typical for deals involving privately held companies at Jit’s stage. But the strategic logic is clear enough. Torq, which has raised over $200 million and was most recently valued at roughly $1.25 billion after a $70 million Series C round in late 2024, wants to extend its AI-driven automation platform beyond the security operations center and into the software development pipeline itself, according to Business Insider.

Jit, founded in 2022, had carved out a niche by offering what it called a “unified AppSec platform” — a way for developers and security teams to orchestrate open-source and commercial security tools from a single interface. Think of it as a control plane for application security testing: static analysis, software composition analysis, secrets detection, infrastructure-as-code scanning, and more, all stitched together and embedded into CI/CD workflows. The company had raised approximately $47 million, including a $38.5 million Series A in 2023 led by boldstart ventures, with participation from Tiger Global and other investors.

So why does a company known for automating SOC workflows want an AppSec orchestration startup?

The answer lies in a shift that’s been building for years but is now accelerating. The traditional boundary between security operations and application security is dissolving. Vulnerabilities discovered in code don’t stay neatly in a developer’s backlog anymore — they show up as alerts in security dashboards, as incidents requiring triage, as risks that CISOs must quantify for boards. And incidents detected in production increasingly demand remediation that traces back to the application layer. The wall between “finding bugs” and “responding to threats” has become a fiction that most large organizations can no longer afford to maintain.

Torq’s CEO and co-founder, Ofer Smadari, has been vocal about this convergence. In statements surrounding the deal, he described the acquisition as a way to create a “full-cycle” security automation platform — one that covers everything from code commit to incident response. The idea is that when Jit identifies a vulnerability in a developer’s pull request, Torq’s automation engine can immediately trigger the appropriate workflow: notify the right people, create tickets, enforce policies, or even auto-remediate certain classes of issues without human intervention.

That’s ambitious. And it’s not without precedent in the broader industry.

The cybersecurity market has been consolidating at a furious pace. Palo Alto Networks spent much of 2023 and 2024 absorbing acquisitions to build what it calls a “platformization” strategy. CrowdStrike has expanded well beyond endpoint detection. Wiz, another Israeli security company, agreed to be acquired by Google for $32 billion — a deal that would rank among the largest cybersecurity acquisitions in history. The message from buyers and investors alike is unmistakable: point solutions are out, platforms are in.

But Torq’s approach is distinct. Rather than building a detection engine or a vulnerability scanner, Torq built an automation layer — a system that sits on top of existing security tools and orchestrates actions across them using AI agents. Its platform connects to hundreds of third-party products, from SIEMs and endpoint detection tools to identity providers and cloud infrastructure. The value proposition isn’t replacing what you already have. It’s making what you already have work together, faster, with less manual effort.

Adding Jit extends that same philosophy into application security. Jit was already an orchestration layer for AppSec tools; it didn’t build its own static analyzer or dependency scanner. Instead, it integrated best-of-breed open-source tools like Semgrep, Trivy, and Gitleaks into a unified experience with centralized policies, dashboards, and developer-friendly interfaces. The architectural compatibility between the two companies is striking.

There’s a financial dimension here too. The cybersecurity startup market in 2025 has grown considerably more difficult for smaller companies trying to go it alone. Funding rounds are harder to close. Customer acquisition costs have risen. And enterprise buyers, fatigued by vendor sprawl, are actively reducing the number of security tools they purchase. For Jit, which was still in relatively early revenue stages, joining Torq likely offered a faster path to market than continuing independently.

Not everyone is convinced that combining SOC automation with AppSec orchestration will work as smoothly in practice as it sounds in a press release. Security operations teams and application security teams often report to different parts of the organization, use different tools, and think about risk in fundamentally different ways. A SOC analyst responding to a phishing incident and a developer triaging a critical CVE in a dependency operate in different contexts with different urgency models. Merging the automation layers doesn’t automatically merge the cultures or workflows.

Still, the trend is undeniable. Gartner and other analyst firms have been pushing the concept of “converged security platforms” for several years now. The firm’s research consistently shows that organizations using fewer, more integrated security platforms achieve better outcomes — faster detection, faster response, lower total cost — than those running dozens of disconnected point tools. Torq is betting that automation is the connective tissue that makes convergence practical rather than theoretical.

The acquisition also reflects a broader pattern in Israeli tech. Israel has long been one of the world’s most prolific producers of cybersecurity startups, but the market there has shifted. Exits via IPO have become rare. Acquisitions by larger Israeli or American companies have become the primary liquidity path. And the talent pool, while deep, is increasingly concentrated in fewer, larger companies as consolidation picks up speed. Torq acquiring Jit is, in many ways, a natural expression of this dynamic — a well-funded growth-stage company absorbing a younger startup before the younger startup has to face the brutal economics of scaling independently in a crowded market.

For Torq’s existing customers, the near-term impact should be relatively straightforward. The company has indicated that Jit’s capabilities will be integrated into the Torq platform over the coming months, giving security teams visibility into application-layer vulnerabilities alongside their existing operational workflows. For Jit’s customers — many of them smaller development teams and startups attracted by Jit’s free tier and developer-friendly UX — the transition may be less certain. Enterprise platforms and developer tools serve different masters, and maintaining the simplicity that made Jit appealing while embedding it in a larger, more complex platform is a genuine product challenge.

Torq’s investors include Bessemer Venture Partners, Insight Partners, Greenoaks Capital, and Evolution Equity Partners, among others. The company’s $70 million Series C in late 2024, which valued it at $1.25 billion, gave it significant capital to pursue exactly this kind of inorganic growth. Acquiring Jit likely consumed a relatively modest portion of that war chest, given Jit’s stage, and positions Torq to tell a more compelling story to enterprise buyers who want fewer vendors solving more problems.

The timing matters. With AI-generated code proliferating — thanks to tools like GitHub Copilot, Cursor, and a growing roster of AI coding assistants — the volume of code being written and deployed is increasing dramatically. More code means more potential vulnerabilities. More vulnerabilities mean more alerts. More alerts mean more need for automation. Torq is positioning itself at the intersection of these trends, arguing that human security teams simply cannot keep up without AI-driven automation handling the routine work.

Whether this acquisition delivers on its promise will depend on execution. Integrating two engineering teams, two product visions, and two customer bases is never simple. But the strategic rationale is sound. The cybersecurity industry is moving toward fewer, broader platforms. Automation is becoming the expected default rather than a nice-to-have. And the line between writing secure code and operating secure infrastructure is getting thinner by the quarter.

Torq’s bet on Jit is a bet on that convergence. It won’t be the last deal like this. Not by a long shot.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us