penetration-testing

(20)
Company
GRC Solutions wrote the rulebook. Now it does the work.
Enterprise · Saas · Education

GRC Solutions wrote the rulebook. Now it does the work.

A business that began with security books now sells the people, software and testing behind compliance. Its next bet puts round-the-clock cyber response on the same shopping list.

grc · cyber-securityRead →
Company
The Security Company That Taught a Million Hackers - Then Gave Burp a Brain
Saas · Enterprise · Education

The Security Company That Taught a Million Hackers - Then Gave Burp a Brain

Burp Suite grew from a hobby project with comic sound effects into the daily workbench of web-security professionals. PortSwigger’s real trick is the loop behind it: discover an attack, turn it into a tool, then teach the world how it works.

web-application-security · burp-suiteRead →
Company
HackerOne Made a Business Out of Inviting Strangers to Break In
Enterprise · Saas · Marketplace

HackerOne Made a Business Out of Inviting Strangers to Break In

The bet sounded reckless: give hackers permission, set a bounty, and listen. One Pentagon pilot and hundreds of thousands of validated vulnerabilities later, HackerOne is trying to turn that human network into a continuous, AI-assisted security system.

cybersecurity · bug-bountyRead →
Company
Rapid7 Built a Security Empire on Hacker Tools. Now It Has to Make the Whole Stack Feel Like One Product.
Enterprise · Saas · Developer Tools

Rapid7 Built a Security Empire on Hacker Tools. Now It Has to Make the Whole Stack Feel Like One Product.

Rapid7 spent 25 years learning how attackers think, then assembled scanners, SIEM, cloud security and managed response around that knowledge. The hard part now is subtraction: turning a crowded toolbox into one coherent operating system for security teams.

cybersecurity · security-operationsRead →
Company
Bugcrowd Built a Switchboard for Hackers - Now It Wants to Put AI on the Line
Enterprise · Saas · Marketplace

Bugcrowd Built a Switchboard for Hackers - Now It Wants to Put AI on the Line

Bugcrowd turned an awkward corporate question - how do you invite strangers to attack your software safely? - into a managed marketplace. Its next wager is that machines should cover the map while human hackers chase the strange paths through it.

bug-bounty · crowdsourced-securityRead →
Company
Synack Put 1,500 Hackers Behind One Locked Door - Now AI Is Knocking
Saas · Enterprise · Ai

Synack Put 1,500 Hackers Behind One Locked Door - Now AI Is Knocking

Annual pentests were too slow, scanners were too noisy, and inviting strangers to attack corporate systems sounded absurd. Synack turned that trust problem into a platform - then added an autonomous red agent without removing the humans who prove what matters.

penetration-testing · cybersecurityRead →
Company
Bishop Fox Built a $154 Million Business by Breaking Into Companies Before the Bad Guys Do
Enterprise · Saas · Developer Tools

Bishop Fox Built a $154 Million Business by Breaking Into Companies Before the Bad Guys Do

The 20-year-old security firm turned pentesting from a periodic fire drill into a managed, continuous service. Its wager is simple: machines can scan the internet, but humans still decide what is actually dangerous.

offensive-security · penetration-testingRead →
Company
The Company That Made Audit Season Boring
Saas · Ai · Enterprise

The Company That Made Audit Season Boring

Meiran Galis spent years at EY watching startups treat security audits like a fire drill. Scytale is his bet that compliance can run in the background instead of eating a quarter.

soc-2 · iso-27001Read →
Company
The Pentest That Never Clocks Out
Saas · Enterprise · Developer Tools

The Pentest That Never Clocks Out

A solo hacker in Madison got tired of writing the same annual report twice. So he built software to run the test all year - and turned continuous penetration testing into a business.

penetration-testing · continuous-penetration-testingRead →
Company
Appknox
Enterprise · Saas · Developer Tools

Appknox

Most security tools inspect the code developers write. Appknox follows the app that users actually touch - from compiled binary and real-device behavior to the moment a counterfeit copy appears in an app store.

mobile-app-security · application-securityRead →
Company
Casco
Ai · Saas · Enterprise

Casco

Casco is a San Francisco cybersecurity startup that runs autonomous, AI-driven penetration tests on web apps, APIs, cloud infrastructure, and AI systems. Founded in 2025 by ex-AWS engineers Rene Brandel and Ian Saultz, it pairs continuous machine-driven attack simulation with human security experts, delivering compliance-ready reports for standards like SOC 2, ISO 27001, and the EU AI Act. A Y Combinator (X25) company, Casco says it serves 300+ companies and secures AI systems used across a majority of the Fortune 500.

ai-security · penetration-testingRead →
Company
MindFort
Ai · Saas · Enterprise

MindFort

MindFort is a San Francisco AI security lab building autonomous agents that continuously find, validate, and patch vulnerabilities in web applications and APIs. Founded out of Y Combinator's X25 batch by offensive-security veterans, it runs like a 24/7 AI red team - proving exploits in isolated runtime environments before it reports them, then opening pull requests with the fix. The company raised a $3M+ seed led by Soma Capital in April 2026.

ai-security · penetration-testingRead →
Company
Nebula Security
Ai · Enterprise · Developer Tools

Nebula Security

Nebula Security is an AI-native cybersecurity company from Y Combinator's Summer 2026 batch. Founded by world-class hackers - members of the world's #1 CTF team r3kapig, DEF CON finalists, Black Hat speakers, and a cybersecurity PhD - it pairs an autonomous code-scanning agent called VEGA with human expertise to audit software for vulnerabilities, from code-level bugs to architectural weaknesses. The team has earned $400K+ in bug bounties exploiting the Linux kernel and Chrome, and reported over a thousand vulnerabilities. Its pitch: 'Attackers already have AI. Get VEGA now.'

cybersecurity · ai-securityRead →
Company
Praetorian
Enterprise · Saas · Ai

Praetorian

Praetorian is an Austin, Texas-based cybersecurity company that helps organizations prevent breaches by combining an adversarial, offensive-security mindset with automation and AI. Founded in 2010 by CEO Nathan Sportsman, the firm pairs elite red-team engineers with its flagship Chariot platform for Continuous Threat Exposure Management (CTEM) and attack surface management, plus services spanning penetration testing, cloud and product security, and adversarial emulation. Its clients include large technology, finance, healthcare, and automotive organizations, and it maintains open-source tools such as the Nosey Parker secrets scanner.

cybersecurity · offensive-securityRead →
Company
watchTowr
Enterprise · Saas · Ai

watchTowr

watchTowr is a Singapore-based cybersecurity company that builds a real-time attacker's view of an organization's external attack surface, then continuously discovers and validates exploitable vulnerabilities before adversaries can use them. Founded in 2021 by offensive-security specialist Benjamin Harris, its platform blends external attack surface management, continuous automated red teaming, AI-driven rapid reaction to emerging threats, and autonomous edge mitigation. watchTowr is also known for watchTowr Labs, a research team whose public disclosures on Citrix, Fortinet, Ivanti, SonicWall and other enterprise software regularly make headlines. The company serves Fortune 500 firms and critical-infrastructure operators and has raised roughly $29-30 million, including a $19M Series A led by Peak XV.

cybersecurity · attack-surface-managementRead →
Company
Hitachi Cyber
Enterprise · Ai · Saas

Hitachi Cyber

Hitachi Cyber is the global cybersecurity and performance analytics arm of the Hitachi Group, operating under Hitachi Systems Trusted Cyber Management Inc. With roots going back to 1999, it delivers 24/7 managed security services, threat intelligence, governance-risk-compliance advisory, and performance analytics to more than 350 private and government organizations across 50-plus countries. A network of Security Operations Centers spanning Canada, Switzerland, Japan, India and Poland - integrated with Google Security Operations, Microsoft Sentinel and Splunk - anchors its detection and response work across IT, OT and AI environments.

cybersecurity · managed-security-servicesRead →
Company
CyCognito
Saas · Enterprise · Ai

CyCognito

CyCognito is a cybersecurity company that builds an external exposure management platform. It maps an organization's internet-facing attack surface the way an attacker would - discovering unknown, unmanaged, and forgotten assets across cloud, web, and APIs, then testing and prioritizing the risks that actually matter. Founded in 2017 by former Israeli intelligence (Unit 8200) operators, CyCognito counts large enterprises like Tesco, Colgate-Palmolive, Panasonic and Hitachi among its customers, and raised a $100M Series C in 2021 at an $800M valuation.

attack-surface-management · external-exposure-managementRead →
Company
BEMO
Enterprise · Saas · Ai

BEMO

BEMO is a Redmond, Washington-based managed IT and security service provider built specifically for small and mid-sized businesses that run on Microsoft 365 and Azure. Founded in 2010 by ex-Microsoft veterans Bruno Lecoq and Joel Lachance, the fully remote company bundles cybersecurity, compliance (SOC 2, ISO 27001, CMMC, NIST 800-171), managed helpdesk, and AI/Copilot security into packaged tiers so 10-to-500-person organizations can meet audit requirements without hiring an in-house security team. BEMO is a repeat Microsoft US Partner of the Year and a four-time Inc. 5000 honoree.

managed-security · msspRead →
Company
Strike
Ai · Saas · Enterprise

Strike

Strike is a cybersecurity company that runs always-on, continuous penetration testing by combining AI-driven offensive emulations with validation from an elite network of human ethical hackers it calls Strikers. Its platform and proprietary engine, Strike360, continuously test web apps, APIs, mobile apps, cloud infrastructure and internal networks, then guide teams through remediation and compliance. Founded in 2021 by Santiago Rosenblatt - a hacker since age six - Strike protects 120+ enterprises across 20+ countries, including Santander, Mercado Libre and Okta.

cybersecurity · penetration-testingRead →
Company
Zone24x7
Ai · Enterprise · Hardware

Zone24x7

Zone24x7 is a US-headquartered, end-to-end technology innovation company that weaves hardware and software into intelligent products for enterprises - from Fortune 500 retailers to startups. Founded in 2003 by Llavan and Saw-Chin Fernando, it pairs a San Jose business front with a deep engineering talent hub in Colombo, Sri Lanka, delivering AI, data science, embedded systems, IoT, computer vision, RFID and DevOps work for 50+ enterprise customers across retail, manufacturing, logistics and healthcare.

ai · machine-learningRead →