Onapsis
Onapsis is a Boston-based cybersecurity platform that protects business-critical SAP and Oracle ERP applications for roughly 200 large enterprise and government customers. Founded in 2009, it provides vulnerability management, threat detection, code security, and compliance automation via an agentless, SAP-endorsed platform.
- Company typePrivate
- Founded2009
- HeadquartersBoston, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Onapsis does
Onapsis is a Boston-based, privately-held cybersecurity and compliance company founded in 2009 by CEO Mariano Nunez that protects business-critical SAP and Oracle ERP applications for approximately 200 large enterprise and government customers. Its platform spans four primary modules — Assess (vulnerability management), Defend (real-time threat detection and response with 2,500+ detection rules and 600+ exploit rules), Control (code security and SAP transport analysis), and Comply (continuous control monitoring for SOX, GDPR, NIST, PCI-DSS, ISO, NERC CIP) — plus an AI-powered Security Advisor introduced in 2025. The technology uses an agentless, external architecture that imposes zero performance impact on production SAP environments and provides tamper-proof evidence collection; the platform is the only cybersecurity offering officially designated as a Premium Certified SAP Endorsed App. Onapsis Research Labs, the company's dedicated threat-research function, has discovered 1,000+ zero-day ERP vulnerabilities and produced 6 US DHS critical alerts, and feeds proprietary threat intelligence and pre-patch zero-day protection rules into the platform.
The product surface has been extended with specialized solutions for SAP BTP (Assess, Control, and Defend for BTP), SAP SuccessFactors, a Secure RISE Accelerator for SAP S/4HANA migrations, and Premium Add-Ons (Threat Intel Center, Network Detection Rule Pack). Onapsis monetizes through annual subscription licenses for the core platform and add-ons, supplemented by SAP-endorsed Incident Response professional services and managed/advisory services around RISE migrations. Pricing is quote-based and sold sales-led to enterprise buyers, supported by a free interactive SAP risk assessment as a top-of-funnel lead magnet, a SI/consulting partner channel anchored by Deloitte, and out-of-the-box SIEM/SOAR integrations (Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, CrowdStrike Falcon, ServiceNow). Reported ARR grew from $23.5M in 2021 to $93.5M in 2025, supported by $115.6M of cumulative venture funding across five rounds, the most recent being a $55M growth round in October 2020 led by La Caisse and NightDragon.
Onapsis firmographics
Firmographics- Name
- Onapsis
- Legal name
- Onapsis
- Website
- https://onapsis.com
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Onapsis is a Boston-based cybersecurity platform that protects business-critical SAP and Oracle ERP applications for roughly 200 large enterprise and government customers. Founded in 2009, it provides vulnerability management, threat detection, code security, and compliance automation via an agentless, SAP-endorsed platform.
- Ownership category
- akta.pro rank
Onapsis industry classification
Industry- Product category
- SAP Application Security and Compliance
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming Services (7371), Services-Prepackaged Software (7372)
- akta.pro primary industry
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
Keywords
Where Onapsis is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Onapsis business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- SaaS platform subscriptions (Assess, Defend, Control, Comply): Recurring SaaS revenue from the Onapsis Platform (vulnerability management, threat detection, code security, compliance automation). Reported $93.5M ARR in 2025, up from $23.5M in 2021.
- Premium Add-On subscriptions (Threat Intel Center, Network Detection Rule Pack): Annual subscription premium add-ons that extend platform capabilities with curated threat intelligence and network-layer detection rules.
- SAP Incident Response professional services: On-demand, retainer-style professional services offering SAP-endorsed incident response and recovery; deployed with proprietary forensic extraction tools, often remote, with deliverable of a full Incident Report.
- Secure RISE Accelerator advisory and tooling: Framework-driven advisory plus platform technology sold to enterprises undergoing RISE with SAP migrations; combines dedicated security advisors, templates, and automation.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based enterprise platform (Assess, Defend, Control, Comply) |
| Subscription | Annual | Premium Add-Ons (Threat Intel Center, Network Detection Rule Pack) |
| Other | — | Onapsis Comply Packs (SOX, GDPR, NIST, PCI-DSS, ISO, NERC CIP) |
| Other | — | SAP Incident Response engagement |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels10 records
Onapsis product offering
Product offeringCore offering
Onapsis provides a cybersecurity and compliance platform purpose-built for SAP and Oracle business-critical applications, including ERP, CRM, PLM, HCM, SCM, and BI. The platform bundles four core modules (Assess for vulnerability management, Defend for real-time threat detection, Control for code/transport security, and Security Advisor for AI-driven guidance) with premium add-ons, compliance packs, and an incident response service. It is the only Premium Certified SAP Endorsed App in the cybersecurity category and is sold on a subscription basis to large enterprises running SAP.
Differentiator
Problem solved
Functional benefit
Products and services
- Onapsis Assess SAP vulnerability management and compliance platform that continuously discovers, prioritizes, and validates SAP system vulnerabilities, missing patches, and configuration issues. For security and SAP Basis teams in large enterprises running SAP landscapes.
- Onapsis Defend Real-time SAP threat detection and response platform with 2,500+ detection rules and 600+ exclusive exploit rules; provides pre-patch zero-day protection, agentless architecture, and SIEM integrations. For SOC teams and security operations protecting SAP environments.
- Onapsis Control Automated SAP application security testing and code analysis embedded in CI/CD pipelines, Git repositories, IDEs, and SAP Transport Management. Provides 600+ security test cases with automated remediation for ABAP, Java, SAPUI5, and SAP BTP development. For SAP development and DevSecOps teams.
- Onapsis Security Advisor AI-powered SAP security advisor delivering 360° view of SAP security posture, leveraging 14+ years of accumulated SAP and cybersecurity data and best practices from Onapsis customers for benchmarking and tailored recommendations. For CISOs and security leadership managing SAP environments.
- Onapsis for SAP BTP (Assess, Control, Defend for SAP BTP) Specialized security solutions for SAP Business Technology Platform that enforce security best practices for users, privileges, configurations, code, and runtime activity on SAP BTP. For enterprises running RISE with SAP and SAP BTP workloads.
- Onapsis Assess for SAP SuccessFactors Dedicated integration that automatically evaluates SAP SuccessFactors user, system, and integration settings against security best practices. For organizations running SAP SuccessFactors HR cloud applications.
- Onapsis Comply Compliance automation add-on to Onapsis Assess that provides continuous control monitoring and pre-built policy mapping for frameworks including SOX, GDPR, NIST, PCI-DSS, ISO, and NERC CIP. For compliance, audit, and GRC teams running SAP.
- Onapsis Premium Add-Ons (Threat Intel Center and Network Detection Rule Pack) Annual subscription premium add-ons that extend platform capabilities with curated threat intelligence (Threat Intel Center) and vendor-agnostic, open-source network layer detection rules (Network Detection Rule Pack). For enterprises seeking enhanced SAP threat detection beyond the base platform.
- Onapsis Secure RISE Accelerator Framework-driven advisory and tooling program for enterprises undergoing RISE with SAP migrations, combining dedicated RISE Security Advisors, templates, and automation to embed security into every phase of the SAP Activate methodology. For enterprises migrating to RISE with SAP.
- Onapsis SAP Incident Response On-demand, retainer-style professional services offering SAP-endorsed incident response and recovery, deployed with proprietary forensic extraction tools and delivering a full Incident Report. For enterprises experiencing or preparing for SAP security breaches.
Quantifiable outcome
- 83% reduction in time remediating SAP vulnerabilities
- +8 more outcomes
Companies that use Onapsis
Customer profileNamed customers19 records
Segments9 records
Ideal customer profiles3 records
Onapsis technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration24 records
AI capability3 records
Feature8 records
Onapsis partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered flagship and core.
- SAPflagshipSAP Endorsed App relationship: Onapsis is the only cybersecurity and compliance platform officially a Premium Certified SAP Endorsed App, premium certified to work seamlessly with SAP S/4HANA and RISE with SAP. Co-marketing includes joint webinars (e.g., 'Maximizing Security in RISE with SAP' with Roland Costea, CISO of SAP Enterprise Cloud Services) and joint customer engagements. SAP directly collaborates with Onapsis Research Labs on vulnerability disclosure.
- Microsoft (Microsoft Sentinel)coreOut-of-the-box integration with Microsoft Sentinel (and Splunk, IBM QRadar, ArcSight, CrowdStrike Falcon, SAP Enterprise Threat Detection) to bring curated SAP events into the SOC. Dedicated solution brief 'Empowering Security Operations with Unified SAP Threat Detection and Response' for Onapsis Defend and Microsoft Sentinel.
- SplunkcoreOut-of-the-box SIEM integration that imports real-time Onapsis alerts, issues, and incidents into Splunk for SOC visibility and incident response.
- IBM (QRadar)coreOut-of-the-box integration with IBM QRadar; cited in Fortune 250 Biotech case study ('Integrating with our existing IBM QRadar solution has further accelerated our response times and given our SOC teams much-needed visibility').
- CrowdStrike (Falcon Next-Gen SIEM)coreOnapsis Defend Data Connector is published on the CrowdStrike Marketplace, enabling SAP-specific alerts to flow into CrowdStrike Falcon.
- SAP Enterprise Threat Detection (ETD)coreIntegration with SAP Enterprise Threat Detection listed as part of Onapsis Defend's SIEM integration suite, allowing bidirectional SAP event visibility.
- ServiceNowcoreIntegration with ServiceNow enables automatic assignment of remediation tickets to the appropriate teams and progress tracking, per customer testimonials on the homepage.
- SAP (ChaRM, TMS, BTP, Business Application Studio)coreOnapsis Control integrates with SAP ChaRM, SAP Transport Management System (TMS), SAP Cloud Transport Management (cTMS), SAP Business Application Studio, and the ABAP Workbench to embed security testing and change management into SAP-native development workflows.
- GitHub / GitLab / Azure Repos / BitbucketcoreOnapsis Control scans custom code at rest across GitHub, GitLab, Azure Repos, and Bitbucket, supporting gCTS, abapGit, and SAPUI5; integrates with Azure Pipelines, SAP Project Piper, and SAP CI/CD.
- DeloittecoreCo-marketing webinar 'Maximizing Application Security in RISE with SAP: A Collaborative Approach with SAP, Onapsis and Deloitte' positions Deloitte as a system integrator partner for Onapsis-led RISE with SAP transformations.
Scale indicators12 records
Recent moves6 records
Expansion highlights8 records
Onapsis competitors and assessment
Company assessmentDirect peers
- SecurityBridge: SecurityBridge is a direct competitor specializing in SAP cybersecurity, offering vulnerability management, code scanning, and threat detection for SAP landscapes. It targets the same SAP customer base with a similar feature set, making it the closest one-to-one competitor to Onapsis.
- Pathlock: Pathlock provides application access governance, continuous controls monitoring, and security for ERP systems including SAP, Oracle, and Workday. It competes with Onapsis in SAP access governance and compliance (SOX/SOD) and increasingly in vulnerability management, addressing the same enterprise buyer.
- Appsian: Appsian delivers ERP data security, identity and access management, and threat detection specifically for SAP and Oracle EBS environments. It overlaps directly with Onapsis's identity, data security, and threat detection capabilities for the same SAP/Oracle customer base.
Emerging players
- Layer Seven Security: Layer Seven Security is an SAP-specialized cybersecurity services and technology provider focused on vulnerability management, code scanning, and secure configuration for SAP. It is a niche, SAP-only competitor that overlaps with Onapsis's Assess and Control products but at a smaller scale.
Broad incumbents
- SAP Enterprise Threat Detection: SAP Enterprise Threat Detection is a native SAP security offering for real-time threat monitoring on SAP applications. It is the platform-vendor alternative to Onapsis Defend and represents the single largest competitive threat to Onapsis's threat detection business.
- Palo Alto Networks (Prisma Cloud): Palo Alto Networks acquired ERPScan and now includes SAP/Oracle ERP security testing capabilities within its Prisma Cloud application security portfolio. It competes with Onapsis through broader cloud security bundles aimed at the same Fortune 500 buyers.
- CrowdStrike: CrowdStrike Falcon Next-Gen SIEM integrates with Onapsis Defend as a marketplace data connector but also competes as a broader endpoint and SOC platform. CrowdStrike represents a competitor/partner hybrid: a channel for Onapsis today but a potential consolidator of SAP-aware detection going forward.
- Microsoft (Sentinel / Defender): Microsoft Sentinel and Defender for Cloud integrate with Onapsis for SAP threat telemetry but compete as broader enterprise security platforms with much larger R&D budgets and existing SAP customer relationships via Azure and Microsoft enterprise agreements.
- Splunk: Splunk integrates Onapsis Defend alerts into its SIEM and serves many of the same SOC buyers. As a broader observability and security platform owned by Cisco, Splunk represents a channel partner today but a competitive threat if it expands native SAP-aware content.
- IBM Security (QRadar): IBM QRadar integrates with Onapsis Defend and serves overlapping enterprise security buyers across regulated industries. IBM's broader security and consulting portfolio makes it a partner/competitor hybrid for Onapsis in Fortune 500 SIEM buying decisions.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat7 records
Key risks6 records
Key highlights7 records
Customer concentration
Onapsis social profiles
Digital presenceOnapsis financial estimates
Financial estimateRevenue estimate
Valuation estimate
Onapsis leadership team
Management profileNumber of profiles
Profiles21 records
Onapsis funding detail
Funding detailFunding overview
Funding rounds5 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Onapsis M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Onapsis
What does Onapsis do?
Onapsis provides a cybersecurity and compliance platform purpose-built for SAP and Oracle business-critical applications, including ERP, CRM, PLM, HCM, SCM, and BI. The platform bundles four core modules (Assess for vulnerability management, Defend for real-time threat detection, Control for code/transport security, and Security Advisor for AI-driven guidance) with premium add-ons, compliance packs, and an incident response service. It is the only Premium Certified SAP Endorsed App in the cybersecurity category and is sold on a subscription basis to large enterprises running SAP.
Is Onapsis a public or private company?
Onapsis is a private company. It is classified as venture growth investor backed and is currently operating.
When was Onapsis founded?
Onapsis was founded in 2009. It employs 251 to 500 people.
Where is Onapsis based?
Onapsis is headquartered in Boston, United States, in the North America region.
How does Onapsis make money?
Four revenue lines are on record. SaaS platform subscriptions (Assess, Defend, Control, Comply) is the primary driver. The others are premium Add-On subscriptions (Threat Intel Center, Network Detection Rule Pack), SAP Incident Response professional services and secure RISE Accelerator advisory and tooling.
Who are Onapsis's main competitors?
Direct peers on record are SecurityBridge, Pathlock and Appsian. Layer Seven Security is listed as an emerging player. Broad incumbents are SAP Enterprise Threat Detection, Palo Alto Networks (Prisma Cloud), CrowdStrike, Microsoft (Sentinel / Defender), Splunk and IBM Security (QRadar).
Does Onapsis have an API?
No public API is recorded for Onapsis.
What industry is Onapsis in?
Onapsis's product category is SAP Application Security and Compliance. Its primary akta.pro industry code is BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services. Its NAICS code is 54151 and its SIC code is 7371.