Case studies / Snyk Code · 2020 – 2025

From the DeepCode acquisition to a $100M+ ARR product.

I joined Snyk through the DeepCode acquisition in 2020 and led design for Snyk Code, Snyk's static analysis (SAST) product, from beta through scale. I worked across the web app, the IDE, the CLI and pull requests, with one belief throughout: developers fix what shows up inside their own workflow.

Role
Lead, then Staff Product Designer
Timeline
2020 – 2025
Surfaces
Web app, VS Code, CLI, SCM pull requests
Outcome
$100M+ ARR in 2024
Snyk Code analysis in the Snyk web app: a project's issues filtered by severity and status on the left, and a Path Traversal issue with its vulnerable code and data flow on the right.
01 · Launch

Two cultures, one product, in under five months.

DeepCode was a small, research-led startup. Snyk was an established scale-up with its own platform, patterns and customers. Merging the two was hard at times, and it paid off. We had to turn DeepCode’s engine into a product that felt native to Snyk, and we had one release window to do it.

We ran it as a series of Google Design Sprints: map the problem, sketch, prototype, and test with customers within the week. We went through many iterations and took in a lot of feedback. Less than five months later we released a beta that did well and became the foundation of Snyk Code as it is today.

The original DeepCode dashboard: a list of findings beside the analysed source file.
BeforeDeepCode's standalone dashboard.
A Path Traversal issue in Snyk Code, showing the step-by-step data flow next to the highlighted source code.
AfterSnyk Code, native to the Snyk platform.
Design sprintsUser researchPrototypingUsability testing
02 · Customization

Let customers teach the engine about their own code.

SAST is hard. Whatever the approach, no engine covers 100% of what customers need. The gap shows up most with custom code: an in-house sanitizer that the engine doesn’t recognise produces false positives, and false positives cost developers’ trust.

Rules extensions let teams tell Snyk Code how to interpret specific code, starting with marking a function as a sanitizer directly from an issue. PM and I worked on it closely, with a lot of support from the engineering team, and tested it with customers who had the problem.

A data-flow step in a Snyk Code issue with an inline prompt asking whether the function is a sanitizer.
Marking a sanitizer directly on the data flow.
Rule management view listing Snyk Code rules and custom extensions, with a detail panel showing the rule's change history.
Managing rules and extensions across the organization.
Customer researchUI designPrototypingUsability testing
03 · AI Fix

I designed and built AI Fix for VS Code.

Snyk AI Fix (Autofix) fixes supported vulnerabilities right where developers find them. In 2024, with most of the team committed to foundational work for the year, I took responsibility for bringing it to VS Code.

I designed the experience, wrote the UI myself and coordinated the developers working on the backend. The work paid off: AI Fix was shown on stage at Google Next 2024.

User researchUI designPrototypingUsability testingUI implementation
04 · Workflow

Meet developers in the pull request.

Most developers don’t like security. It’s one more thing on an already long list. Asking them to open another dashboard makes that worse.

So we brought Snyk into code review. New issues appear as inline PR comments with the data flow, a risk score and a CWE link. Developers act on them by replying: @snyk /fix suggests a fix, /apply commits it, /explain explains the issue, and /ignore dismisses it with a reason.

I checked technical feasibility with engineering before we committed to the design, and wrote parts of the UI myself.

A pull request thread where Snyk flags an insecure MD5 hash, the developer replies '@snyk /fix', Snyk suggests a SHA-512 change as a diff, and the developer replies '@snyk /apply'.
Flag, fix and apply, all without leaving the PR.
User researchTechnical feasibilityPrototypingUsability testingUI implementation
05 · Vision

Envisioning Snyk 2.0: from fixing one issue to a fix plan.

Fixing one issue at a time wasn’t enough. Codebases keep growing, and while the worst issues get blocked before deploy, most known risk stays in the code.

The AI Fix Plan starts from what security leaders (CISOs, AppSec teams, security champions) care about most, turns that into a prioritized plan, and guides developers through fixing it one step at a time. I prototyped it, got stakeholders aligned on the direction, and built a proof of concept.

AI Fix Plan summary in a dark IDE panel: a prioritized list of issues grouped by package and policy, with notes on why each group matters.
A plan built from the organization's policies.
An AI Fix Plan step open next to a Path Traversal issue, with the suggested code change and an AI explanation.
Each step walks the developer through the fix.
User researchPrototypingStakeholder alignmentPOC implementation
06 · Outcome

A beta that grew into one of Snyk's core products.

From acquisition to beta
<5mo
Snyk Code ARR · 2024
$100M+
AI Fix on stage
Next'24
Surfaces designed
4
Next case study

Color Forklift

Perceptual palettes with contrast checks, token export and an MCP server.

Building something for developers?

I'm always happy to talk about agentic UX, developer tools or design systems.

Say hi on LinkedIn