Bearer is a developer-first SAST tool for sensitive data and security risks in code, now part of Cycode. See 2026 status, features, and pricing.
Bearer is a developer-first static application security testing (SAST) tool designed to discover, filter, and prioritize security and privacy risks in source code, with a particular focus on tracing how sensitive data such as personal or health information flows through an application.
The Bearer product and company were founded in 2018 by Guillaume Montard and Cedric Fabianski, headquartered near Paris in Clichy, France, and the company raised approximately 8 million dollars in seed funding from investors including Alven, Kima Ventures, Partech, and Point Nine.
In 2024, application security company Cycode acquired Bearer, announcing the deal in March 2024 and closing it on April 30, 2024. Bearer no longer operates as an independent company; its scanning technology and team are now part of Cycode's Application Security Posture Management (ASPM) platform, and bearer.sh now redirects to bearer.com under Cycode's branding.
At its core, Bearer's engine scans source code to identify data types being handled (including PII and PHI), maps how that data flows through the application, and flags risky patterns such as data being logged, sent to third parties, or stored insecurely.
The Bearer CLI supports scanning for languages including Ruby, JavaScript, TypeScript, Java, and PHP, and integrates into developer workflows via GitHub, GitLab, and Bitbucket, making it usable directly in CI/CD pipelines to catch issues before code reaches production.
Under Cycode, an expanded 'Bearer Pro' capability adds cross-file and interprocedural analysis (tracing data flows across multiple files and function calls) along with support for additional languages including C#, Kotlin, and Elixir, as part of Cycode's broader ASPM platform.
The Bearer CLI remains free and open source, released under the Elastic License v2 (ELv2), and can be downloaded and run directly from its GitHub repository without a paid plan.
More advanced capabilities, sold as part of Cycode's ASPM platform rather than as a standalone Bearer product, are not available with published self-service pricing; interested organizations need to contact Cycode directly for a quote or demo.
Because Bearer is no longer sold as an independent product, there is no separate 'Bearer subscription' available outside of the Cycode platform as of the most recent available information.
No. Bearer was acquired by Cycode, with the deal announced in March 2024 and closed on April 30, 2024; its technology and team are now part of Cycode.
Yes. The Bearer CLI remains free and open source under the Elastic License v2 (ELv2) and is available on GitHub.
The original bearer.sh website redirects to bearer.com, which presents Bearer as a product within Cycode rather than a standalone company.
Bearer was founded in 2018 by Guillaume Montard (CEO) and Cedric Fabianski, and was headquartered in Clichy, near Paris, France.
Bearer performs static application security testing (SAST) with a particular focus on mapping how sensitive data, such as PII and PHI, flows through an application's source code, alongside general security risk detection.
The free CLI supports Ruby, JavaScript, TypeScript, Java, and PHP; the paid Bearer Pro capability through Cycode adds support for additional languages including C#, Kotlin, and Elixir.
Cycode does not publish self-service list pricing for Bearer Pro or the broader ASPM platform; organizations need to contact Cycode directly for pricing.
Cycode described the acquisition as accelerating its move into AI-enhanced security remediation, folding Bearer's scanning engine and privacy-analysis capabilities into its Application Security Posture Management (ASPM) platform.