Breaking
RSAC 2026: Sprocket Security wins Best Solution in Offensive Security New CTO: Eric Sheridan joins to lead engineering & product Series A: $8M led by Blueprint Equity closes March 2024 Metric: success measured by findings remediated, not found Free forever: Attack Surface Management as the front door HQ: Madison, Wisconsin - team across three continents
Company Profile · Offensive Security

The Pentest That Never Clocks Out

A solo hacker in Madison got tired of writing the same annual report twice. So he built software to run the test all year - and turned continuous penetration testing into a business.

Every security professional knows the quiet embarrassment of the annual penetration test. A firm arrives, spends two weeks trying to break into your network, hands over a PDF, and leaves. By the time engineering reads the report, the code has shipped three times, two new cloud services are live, and a fresh domain is pointing somewhere nobody remembers. The document describes a company that no longer exists.

Casey Cammilleri spent about fifteen years on the delivering end of that ritual - as a network security engineer at Trustwave, a researcher at 403 Labs, a consultant at SynerComm - and eventually decided the whole model was backwards. Attackers do not test you once a year. They test you constantly. So the defense, he reasoned, should be constant too. That idea became Sprocket Security, a Madison, Wisconsin company that sells penetration testing not as a project with a start and end date, but as something that simply keeps running.

2017
Founded in Madison, WI
$8M
Series A, March 2024
~46
Team, three continents
Retests, no extra charge

01 / WHAT IT DOESTurning the report into a subscription

Sprocket's core product is Continuous Penetration Testing. Instead of a two-week engagement, the platform watches a customer's attack surface year-round and probes it the way a real intruder would - external network, internal network, web applications, and social engineering such as phishing and vishing. When it finds something exploitable, it does not bury it in an appendix. It writes an attack narrative: the step-by-step story of how a hole could be walked through, in language an engineer can act on.

The part customers seem to notice most is the retesting. In the traditional world, you fix a finding and then wait until next year - or pay for another engagement - to learn whether the fix actually worked. Sprocket includes unlimited retesting in the subscription. Close a vulnerability, and a tester checks your work at no additional cost. It is a small policy with a large consequence: it reframes the relationship from "here are your problems" to "let's get these actually closed."

Sprocket Security platform findings dashboard
The receipts. The platform's findings view, where exploitable risk shows up ranked by severity and status - not as a year-end PDF, but as a live queue engineers can burn down.
The annual pentest
  • One snapshot, once or twice a year
  • Retest costs another engagement
  • Report is stale the day it ships
  • Findings, not fixes, are the deliverable
Sprocket's model
  • Testing runs continuously, all year
  • Unlimited retesting included
  • New exposures caught as they appear
  • Measured by findings remediated

02 / THE FRONT DOORFree attack surface management

Before a company ever pays, Sprocket will show it something slightly unsettling: what it looks like from the outside. The company's Attack Surface Management product continuously maps domains, applications, APIs, and cloud assets - the sprawling, half-forgotten external footprint that most organizations cannot fully list from memory. Sprocket offers it free and permanently.

That is not generosity for its own sake. Show a security team its own exposed footprint through an attacker's eyes, and the case for continuous testing tends to make itself. Attack surface management is the on-ramp; continuous penetration testing is the road.

Sprocket Security attack surface management summary view
Know thyself, uncomfortably. The attack surface management summary - the free view that maps a company's external footprint before a single invoice is sent.
Automated solutions alone can't keep up with change and lack critical business context. Casey Cammilleri, Founder & CEO

03 / HUMANS + MACHINESThe AI question, answered plainly

Ask most security startups about AI and you will get a fog of superlatives. Sprocket's position is refreshingly blunt: machines are only as good as the humans directing them. Automation handles the scale and speed - crawling the surface, running the noisy first passes - and expert testers validate what actually matters. No model signs your breach report. The pitch is that a scanner finds noise, and a human finds the breach; Sprocket runs both, but keeps the person in the loop.

This is also the answer to an old objection about automated tools: they generate mountains of low-value alerts and miss the creative, chained attacks that experienced testers spot. By treating automation as an accelerator rather than a replacement, Sprocket tries to keep the speed of software and the judgment of a practitioner in the same product.

Sprocket Security team in the office
The humans in the loop. Part of the Sprocket team, which spans North America, Europe, and South America. The company measures itself by fixes closed, not alerts generated.

04 / WHO PAYSThe customers and the model

Sprocket sells to mid-market and enterprise organizations in finance and insurance, healthcare, manufacturing, retail, and software - the sort of companies that carry real regulatory weight and cannot afford a year-long blind spot. Published case studies name customers such as Farmers Alliance Mutual Insurance and Roundhouse Marketing. The platform is also listed on the AWS Marketplace, which lets buyers procure it through budgets they already have.

The business model is a subscription rather than a series of engagements. Pricing scales with the size and complexity of the attack surface - how many assets, which environments (external, internal, application), and how broad the scope. Unlimited retesting is baked in. It is a SaaS-plus-services hybrid: software does the watching, people do the breaking, and the customer pays once a year for both.

The metric worth stealing

Sprocket judges itself not by vulnerabilities found but by vulnerabilities remediated. Finding holes is easy and slightly self-serving. Getting a customer to close them is the harder, more honest measure - and it quietly aligns the vendor with the outcome the customer actually wants.

05 / THE OPEN TOOLBOXWhy a paid company gives tools away

On GitHub, Sprocket maintains a set of free, open-source offensive tools that working red-teamers actually use: gigaproxy, fireproxng, cvetrends, and proxycannon-ng - the last of which was born at a 2018 security conference hackathon. They have collected thousands of combined stars and forks. Giving away sharp tools builds credibility with the exact practitioners a security company needs to hire and be trusted by, and it keeps Sprocket's name in the terminals of the people who break into things for a living.

06 / THE MARKETWhere it fits, and against whom

Sprocket plays in the crowded "penetration testing as a service" category alongside names like Cobalt.io, NetSPI, Pentera, CyCognito, BreachLock, Bugcrowd, HackerOne, and Synack. Its wedge is a semantic one it takes very seriously: much of what the industry calls PTaaS, Sprocket argues, is still a point-in-time test with a dashboard bolted on. The company's contention - that it has been doing genuinely continuous testing since 2015, before the acronym existed - is both a marketing claim and a real product distinction. Whether the difference is a category or a nuance is a fair debate; the retesting policy and the always-on posture are the evidence it points to.

Funding to date
Pre-2024bootstrapped
Series A$8.0M

Led by Blueprint Equity, with Capital Midwest Fund. Announced March 28, 2024.

The March 2024 Series A - $8 million led by Blueprint Equity, with the Wisconsin-based Capital Midwest Fund participating - is the company's only disclosed institutional round; before it, Sprocket was effectively bootstrapped. Blueprint's John Bonhard joined the board. The money is aimed at the usual places for a company at this stage: platform development, customer success, and expanding sales and marketing.

Within cybersecurity's ever-changing landscape, constant vigilance through penetration testing is critical. John Bonhard, Blueprint Equity

07 / THE FOUNDER'S BETA hacker who cloned himself into software

The origin story is unusually literal. Cammilleri was a one-person penetration testing operation. Faced with more demand than a single tester could serve, he had two options: hire twenty more of himself, or write software that does what he does and scale that instead. He chose the software. Sprocket is, in a sense, an attempt to bottle one practitioner's expertise and pour it across many companies at once - with a team of human testers on top to handle the judgment calls a program cannot.

He built it in Madison, Wisconsin - not San Francisco, not Austin - and hired across three continents. It is a quiet argument that a security company can be credible without a coastal zip code, and that the talent for breaking into networks is distributed a lot more evenly than venture capital is.

Sprocket Security booth at Black Hat USA 2024
Show floor, not showroom. Sprocket's booth and crew at Black Hat USA 2024, where the offensive-security world gathers to compare notes on how everything breaks.

08 / RECENT FORMAwards, a new CTO, and momentum

The last two years have been busy. In September 2025, G2 named Sprocket best for support and easiest to do business with in penetration testing - the kind of relationship-index recognition that comes from customers, not analysts. In January 2026 the company appointed Eric Sheridan, a longtime security and software engineering leader with a stack of patents, as Chief Technology Officer to run engineering and product. And at RSAC 2026 it collected the Global InfoSec Awards for Best Solution in Offensive Security and Trailblazing Penetration Testing, alongside a Fortress Cybersecurity Award for continuous exposure management.

2015
The continuous idea
Cammilleri begins pioneering continuous testing as a solo practitioner, before PTaaS existed.
2017
Sprocket Security founded
The company is established in Madison to turn continuous testing into a product.
2018
Platform and open-source tools
The software takes shape; proxycannon-ng emerges from a conference hackathon.
2024
$8M Series A
Blueprint Equity leads the round to expand platform and go-to-market.
2025
G2 recognition
Named best for support and easiest to do business with in penetration testing.
2026
New CTO and industry awards
Eric Sheridan joins as CTO; RSAC and Fortress awards follow.

09 / THE HONEST LIMITSWhere the model strains

Continuous testing is not a fit for everyone. A company with a tiny, static attack surface and a strict compliance checklist may find a cheap annual audit is all it truly needs. Subscription pricing that scales with complexity can climb for organizations with sprawling estates. And the whole promise depends on the customer's willingness to act - unlimited retesting only matters if someone is actually fixing things between the tests. Sprocket's own chosen metric, remediation, is a tacit admission of that: the vendor can find the hole, but it still takes an engineering team to close it.

Still, the direction of travel is clear. Attack surfaces are getting larger and changing faster, and a snapshot from last spring is a weaker and weaker defense against that. Sprocket's bet is that the test has to move at the speed of the thing it is testing. From a gear-logo startup in Wisconsin, that bet is starting to look less contrarian and more like where the category is headed.