Australia|Sydney Digital Edition
Thursday 10 September 2026
The Metropolitan Journal
The Sydney Times

Sydney startup Vunit raises AUD 40 million for AI-powered code review platform

Sydney startup Vunit has raised AUD 40 million in Series B funding for its AI-powered code review platform, which uses fine-tuned language models to catch security vulnerabilities and performance issues before code reaches production.

Sydney startup Vunit raises AUD 40 million for AI-powered code review platform
Sydney startup Vunit raises AUD 40 million for AI-powered code review platform
The Sydney Times
T&
By Tech & Ideas Desk

Tech & Ideas Desk is a contributing writer covering tech and public affairs for The Sydney Times.

9 September 20266 min read

Sydney startup Vunit has raised AUD 40 million in Series B funding for its AI-powered code review platform, which uses fine-tuned language models to catch security vulnerabilities and performance issues before code reaches production. The round was led by Blackbird Ventures and Square Peg, with participation from Atlassian Ventures, and it values the company at approximately AUD 180 million. The funding will be used to expand the engineering team, accelerate enterprise sales in Australia and the United States, and develop specialised models for regulated industries including financial services and healthcare.

Vunit's platform integrates with GitHub, GitLab, and Bitbucket to analyse pull requests before they are merged, flagging security vulnerabilities, performance anti-patterns, and style inconsistencies that manual code review often misses. The platform uses fine-tuned language models that have been trained on millions of real-world pull requests and security advisories, giving it domain-specific knowledge that generic frontier models lack. The fine-tuning is the key differentiator, because generic models can identify some security issues but they lack the contextual knowledge of enterprise codebases, internal libraries, and organisation-specific coding standards that Vunit's models incorporate.

Code review automation and developer workflow integration

The Vunit platform is designed to augment rather than replace human code review, and it positions itself as a tool that catches the low-hanging fruit so that human reviewers can focus on architectural and design issues. The platform flags roughly 80 percent of common security vulnerabilities including SQL injection, cross-site scripting, and authentication bypass patterns, with a false positive rate below 5 percent on well-defined vulnerability categories. The false positives that do occur are presented with explanatory context that helps developers understand why a pattern is flagged, which reduces the friction of correcting issues that the model identifies correctly.

The workflow integration is seamless for teams that use standard Git-based development processes. Vunit adds a check to the pull request pipeline that runs automatically when a developer opens a request for review, and it posts comments directly on the code lines that it flags. The comments include suggested fixes where the model is confident in its recommendation, and they include references to security documentation where the issue requires human judgment. The integration does not require changes to existing development workflows, which reduces the adoption friction that has slowed other AI-powered developer tools.

Enterprise adoption in Australian financial services

Commonwealth Bank and Westpac are both using Vunit in their software development pipelines, with the banks reporting that the platform catches security vulnerabilities earlier in the development cycle than traditional static analysis tools. The earlier detection reduces the cost of remediation, because fixing a security vulnerability in code review is significantly cheaper than fixing the same vulnerability in production. The banks declined to share specific cost figures, but they confirmed that Vunit has become a standard part of their secure software development lifecycle.

The financial services adoption is driven by regulatory expectations for secure software development and the high cost of security breaches in the sector. The Australian Prudential Regulation Authority expects regulated institutions to maintain secure software development practices, and the regulator has increased its scrutiny of application security in recent years. Vunit's audit logging and compliance reporting features help firms demonstrate that they have appropriate security controls in place, which is a factor in regulatory examinations and customer security assessments.

Competitive landscape and product roadmap

Vunit competes with GitHub Copilot, Snyk, and SonarQube in the AI-powered code review market. GitHub Copilot offers AI-assisted code completion and some security scanning capabilities, but it is primarily a developer productivity tool rather than a security platform. Snyk specialises in dependency vulnerability scanning and software composition analysis, with some AI-assisted features but not the deep code understanding that Vunit provides. SonarQube is a static analysis platform that has added AI features but remains primarily rule-based rather than model-driven. Vunit's differentiation is its fine-tuned models trained specifically on security vulnerabilities and enterprise code patterns, which gives it an accuracy advantage over competitors that use generic models or rule-based analysis.

The Series B funding will support Vunit's expansion into the United States, where the code review market is larger and the willingness to pay for security tooling is higher. The company has already established a presence in San Francisco with a small sales and engineering team, and it plans to double that team within 18 months. The US expansion is the primary driver of the valuation increase, because Australian investors are pricing the company based on its potential to capture share in a market that is ten times larger than the domestic market. The execution risk is significant, but the product quality and early customer traction give Vunit a credible path to becoming a global player in the AI code review market. Explore more Australian tech analysis at the Tech & Ideas hub

For Vunit's product documentation, see Vunit. Blackbird Ventures' investment portfolio is at Blackbird Ventures. Square Peg's investment focus is published at Square Peg.

Filed Under
VunitAI code reviewSydney startupenterprise software
The Sydney Times Newsroom

Direct inquiries, corrections, or documentation concerning this dispatch to our editorial newsroom desk.

Further Reporting in tech

Explore tech Desk →