VulnCheck
VulnCheck provides vulnerability and exploit intelligence to enterprise and government security teams, identifying actively exploited CVEs among 40,000+ annual disclosures using data from 500+ sources. Customers include the US Intelligence Community, Department of Defense, and NATO allies.
- Company typePrivate
- Founded2021
- HeadquartersLexington, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What VulnCheck does
VulnCheck, founded in 2021 by Anthony Bettini and headquartered in Lexington, Massachusetts, operates a vulnerability and exploit intelligence platform that aggregates data from more than 500 sources spanning 400M+ records to identify the roughly 1% of the 40,000+ annual CVEs that are actively exploited. The platform is organized around four core intelligence modules — Exploit & Vulnerability Intelligence, Initial Access Intelligence, Canary Intelligence (live exploitation telemetry from a global canary sensor network), and Target Intelligence (per-CVE enumeration of confirmed vulnerable internet-facing hosts via exact-version fingerprinting) — plus an IP Intelligence module and a dedicated government variant. The company also functions as a CVE Numbering Authority, ranked 17th globally by issuance volume, providing early visibility into disclosures.
The business model rests on quote-based enterprise and government subscriptions delivered via API, BigQuery, or file transfer, with a free VulnCheck Community tier (KEV, NVD++, XDB) functioning as a top-of-funnel acquisition channel. Distribution combines direct enterprise sales, a channel program with MSSPs/VARs (Optiv, GuidePoint Security, World Wide Technology) and government integrators (Carahsoft, ClearShark, Parsons, ManTech), marketplace listings (AWS Marketplace, ServiceNow Store), and integrations into major threat intelligence platforms (Anomali, ThreatConnect, OpenCTI/Filigran, Cyware, ThreatQuotient, Polarity, Vertex). Named customers span the US Intelligence Community, Department of Defense, federal civilian agencies, national CERTs, international intelligence agencies, and NATO allies, alongside commercial enterprises in financial services, healthcare, and technology; the company served approximately 7,000 organizations and 13,000+ users as of early 2026.
As of February 2026 VulnCheck has raised $45M across three rounds — a $3.2M seed (2023), a $12M Series A (March 2025), and a $25M Series B (February 2026) — with Sorenson Capital, Ten Eleven Ventures, In-Q-Tel, and National Grid Partners as institutional backers. Reported growth metrics in the year preceding the Series B include 557% YoY enterprise ARR growth, 306% YoY government ARR growth, and 319% YoY EMEA ARR growth, with a stated 100% customer retention rate. Recognition includes Forbes Cloud 100 Rising Stars (2024), CRN Security 100 (2026), CRN 10 Cybersecurity Startups to Watch (2026), and RSAC Innovation Sandbox finalist (2026).
VulnCheck firmographics
Firmographics- Name
- VulnCheck
- Legal name
- VulnCheck Inc.
- Website
- https://vulncheck.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- VulnCheck provides vulnerability and exploit intelligence to enterprise and government security teams, identifying actively exploited CVEs among 40,000+ annual disclosures using data from 500+ sources. Customers include the US Intelligence Community, Department of Defense, and NATO allies.
- Ownership category
- akta.pro rank
VulnCheck industry classification
Industry- Product category
- Vulnerability Intelligence and Exploit Monitoring
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Processing & Data Preparation (7374), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Threat Intelligence Services (BPAEADAC), Vulnerability Assessment & Scanning (HDADAHAA), Security Analytics & Detection Engineering (HDADAGAE), Deception Technology & Threat Hunting (HDADAGAI)
Keywords
Where VulnCheck is headquartered
LocationHeadquarters
- HQ city
- Lexington
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
VulnCheck business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Exploit & Vulnerability Intelligence Platform (Subscription): Subscription-based access to VulnCheck's multi-product exploit intelligence platform including Exploit & Vulnerability Intelligence, Initial Access Intelligence, Canary Intelligence, Target Intelligence, and IP Intelligence. Offered as API, BigQuery, or file-based delivery. Pricing is quote-based with enterprise and government tiers.
- Government-specific Exploit Intelligence: Specialized intelligence offerings for government agencies including dedicated SLA commitments (e.g., at least 200 new vulnerabilities per year with proprietary exploit code and detection artifacts), IP Intelligence with implant reporting, and integration with government procurement channels via partners like Carahsoft and AWS Marketplace.
- VulnCheck Community (Free Tier): Free community tier providing access to VulnCheck KEV, NVD++, and XDB data. Used as a top-of-funnel acquisition channel to convert users to paid platform subscriptions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Community (Free) |
Go-to-market motion5 records
Distribution channels8 records
Marketing channels9 records
VulnCheck product offering
Product offeringCore offering
VulnCheck provides a multi-product exploit intelligence platform that aggregates vulnerability and exploit data from 500+ sources covering 400+ million records, delivering real-time intelligence on actively exploited vulnerabilities. The platform's core offerings include Exploit & Vulnerability Intelligence (early access to CVE data ahead of NVD), Initial Access Intelligence (proprietary exploit PoCs and detection artifacts), Canary Intelligence (real-world exploitation telemetry from globally deployed sensors), Target Intelligence (confirmed vulnerable host identification), and IP Intelligence (attacker infrastructure tracking). Data is delivered via API, BigQuery, and file-based feeds to enterprise security teams, MSSPs, and government agencies.
Product overview
VulnCheck is an exploit intelligence company offering a modular platform built around four core products — Exploit & Vulnerability Intelligence, Initial Access Intelligence, Canary Intelligence, and Target Intelligence — plus a government-specific variant. The platform aggregates data from 500+ sources to provide early, machine-consumable intelligence on vulnerability exploitation, enabling security teams to prioritize and remediate vulnerabilities that are actively exploited in the wild rather than theoretically exploitable ones. Supplemental offerings include the freely accessible VulnCheck KEV catalog (tracking 4,200+ exploited CVEs), NVD++ enriched vulnerability data, the VulnCheck Exploit Database (XDB), IP Intelligence for attacker infrastructure tracking, and KEV Alerts for real-time notification via Slack and email.
Differentiator
Problem solved
Functional benefit
Brands
- VulnCheck KEV: VulnCheck Known Exploited Vulnerabilities Catalog - tracking exploited in-the-wild vulnerabilities.
- NVD++
- VulnCheck Exploit Database (XDB)
- Exploit & Vulnerability Intelligence
- Initial Access Intelligence
- Canary Intelligence
- Target Intelligence
- IP Intelligence
- THREATCON1
Products and services
- Exploit & Vulnerability Intelligence The core intelligence platform module providing early access to vulnerability information ahead of NIST NVD (average 14 days faster), with the industry's largest collection of exploit proof-of-concept code and evidence of exploitation in the wild. Covers over 400 million records from nearly 500 sources with complete exploitation timelines from disclosure through remediation.
- Initial Access Intelligence A module providing in-house developed exploit proof-of-concept code, packet captures (PCAPs), and detection artifacts (Suricata rules, Snort rules, YARA rules, Sigma rules, and nmap scripts) to defend against initial access vulnerabilities. Covers vulnerabilities that result in remote, unauthenticated, no-click data breaches, with early detection artifacts delivered before public disclosure.
- Canary Intelligence A product that captures real-world exploitation using a global network of intentionally vulnerable systems (canaries) deployed across the internet. Records live attacker activity including payloads, source IP addresses, geolocation data, and exploited CVEs, providing ground-truth visibility into active exploitation within minutes of occurrence.
- Target Intelligence A product that takes a CVE identifier and returns every confirmed vulnerable internet-facing host with IP address, geography, ASN, port, protocol, and exact software version details. Identifies vulnerable systems by querying product-specific endpoints to extract exact version information (not server banner reads). Delivered via API, BigQuery direct access, and offline backup file delivery.
- VulnCheck for Government A dedicated variant of the platform designed for government agencies, featuring specialized functionality and data available exclusively to government partners. Includes IP Intelligence capabilities for reporting on how implants were detected, SLA commitments for at least 200 new vulnerabilities per year with proprietary exploit code and detection artifacts, and integrations with government channel partners including Carahsoft, AWS Marketplace, and In-Q-Tel.
- IP Intelligence A module providing data on potentially vulnerable systems, attacker command-and-control (C2) infrastructure, honeypots, proxies, and implanted devices, with 3-day, 10-day, 30-day, and 90-day retention windows. For government partners, reports not just that implants were detected but how they were detected.
- VulnCheck KEV (Known Exploited Vulnerabilities) A community-accessible catalog of exploited in-the-wild vulnerabilities, freely available and tracking over 4,200 CVEs — 192% more than the CISA KEV catalog — with notifications delivered on average 27 days earlier than CISA KEV publication.
- VulnCheck NVD++ A reliable service providing enriched access to NIST NVD data combined with Mitre CVElist, with VulnCheck CPE enrichment added for improved vulnerability prioritization.
- VulnCheck Exploit Database (XDB) An exploit database of proof-of-concept code stored in Git repositories, compiled with human analysis validation and automated block lists to ensure code maturity and validity assessment.
- VulnCheck KEV Alerts A real-time notification service alerting security teams via Slack and email when vulnerabilities with confirmed exploitation evidence are added to the VulnCheck KEV catalog. Supports scalable API access and automation into security workflows.
Quantifiable outcome
- 557% year-over-year enterprise ARR growth in the year leading up to the February 2026 Series B
- +7 more outcomes
Companies that use VulnCheck
Customer profileNamed customers6 records
Segments4 records
Ideal customer profiles4 records
VulnCheck technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability6 records
Feature8 records
VulnCheck partnerships and signals
Strategic signalPartnerships
15 partnerships are on record, tiered core and minor.
- NetRisecoreNetRise and VulnCheck partnered to combine NetRise's software supply chain security products with VulnCheck's threat intelligence, enabling joint customers to access third-party risk reporting, device assessments, threat hunting, and vulnerability management. VulnCheck backed NetRise's Discovery Partner Program launch as a founding technology alliance partner, participating in joint executive conversations and co-marketing.
- Operational Technology Cybersecurity CoalitionminorVulnCheck joined the Operational Technology Cybersecurity Coalition to enhance real-time exploit intelligence for OT environments, aiming to strengthen cybersecurity measures in operational technology settings alongside other industry participants.
- AWScoreAWS Marketplace listing enabling AWS customers to discover and purchase VulnCheck exploit intelligence. AWS is listed as a distribution partner alongside Carahsoft, Andeco, ManTech, and others on VulnCheck's partner page.
- CarahsoftcoreCarahsoft serves as a key government channel partner and reseller, listed prominently on VulnCheck's government partner page alongside AWS Marketplace, EnSign InfoSecurity, Optiv, Optiv+ClearShark, Parsons, PCS Security, Rilian Technologies, and ThunderCat.
- AnomalicoreAnomali is a threat intelligence platform integration partner. VulnCheck's exploit and vulnerability intelligence is available within the Anomali platform, enabling joint customers to enrich threat intelligence with exploit data.
- ThreatConnectcoreThreatConnect integration partnership enabling VulnCheck exploit intelligence to be consumed within ThreatConnect's threat intelligence and security operations platform. Joint solution brief available.
- OpenCTIcoreOpenCTI integration enabling VulnCheck exploit intelligence to be accessed within the open-source threat intelligence platform operated by Filigran.
- FiligrancoreFiligran, the company behind OpenCTI and the Extended Threat Intelligence (XTI) platform, partnered with VulnCheck on joint go-to-market initiatives and a co-developed solution brief.
- ThreatQuotient/SecuronixcoreThreatQuotient integration enables VulnCheck exploit data within the ThreatQuotient security operations platform and Securonix SIEM. Listed as a Threat Intelligence Platform Integration partner.
- OptivcoreOptiv is listed as a distribution partner on VulnCheck's partner page, reselling VulnCheck exploit intelligence as part of its security consulting and MSSP offerings.
- Optiv + ClearSharkminorClearShark (now part of Optiv) is listed as a government channel partner on VulnCheck's government partner page, specializing in federal market distribution.
- ParsonsminorParsons is a government-focused channel and strategic consulting partner listed on VulnCheck's government partner page, providing government integration and delivery services.
- SevvominorSevvo (formerly partnered for real-time threat visibility and comprehensive asset intelligence) partnership to provide customers a combination of VulnCheck's exploit intelligence and Sevvo's asset intelligence data.
- CytoraminorCytora partnered with VulnCheck and Infinite Insight to incorporate exploit intelligence into its digital risk platform for insurers, enabling underwriters to access detailed vulnerability and threat activity data for improved cyber risk assessment and underwriting decisions.
- ServiceNowcoreVulnCheck's threat intelligence is available through the ServiceNow Store for integration with ServiceNow Security Operations and vulnerability management workflows.
Scale indicators14 records
Recent moves8 records
Expansion highlights6 records
VulnCheck competitors and assessment
Company assessmentBroad incumbents
- Recorded Future: Threat intelligence platform (now part of Mastercard) that aggregates and analyzes threat data including vulnerability and exploit context. Closest broad incumbent in commercial threat/exploit intelligence, with much larger scale and broader product portfolio.
- Mandiant (Google Cloud): Google-owned threat intelligence and incident response firm that publishes and consumes vulnerability and exploit intelligence, including through its own Advantage product. Comparable in government/intelligence community penetration and exploit context, but operates as part of a much larger security portfolio.
- CrowdStrike: Public endpoint and cloud security leader with Falcon Intelligence and Spotlight vulnerability management modules. Adjacent in exploit-driven vulnerability prioritization, but bundled into a much broader platform with overlapping exploit telemetry.
Direct peers
- Tenable: Public vulnerability management leader (Nessus/Tenable.sc) that has expanded into vulnerability prioritization and threat intelligence. Directly overlaps VulnCheck's vulnerability intelligence and prioritization use cases for enterprise and government buyers.
- Rapid7: Public security analytics and vulnerability management company offering InsightVM and threat intelligence capabilities. Comparable in targeting enterprise vulnerability prioritization and offering overlapping exploit intelligence features.
- Qualys: Public cloud security and vulnerability management platform with VMDR and TruRisk prioritization. Overlaps with VulnCheck's vulnerability intelligence and prioritization workflows for enterprise security teams.
- Flashpoint: Commercial threat intelligence vendor offering finished intelligence on exploited vulnerabilities, illicit communities, and adversary infrastructure. Competes head-to-head with VulnCheck in enterprise and government exploit intelligence.
- Cybersixgill: Threat intelligence company specializing in deep and dark web monitoring with an emphasis on early access to exploits, vulnerability discussions, and leaked data. Closely comparable to VulnCheck's exploit intelligence and early-warning positioning.
Emerging players
- GreyNoise: Emerging player in internet noise and mass-exploitation telemetry, offering a community tier plus paid intelligence on opportunistic scanning and exploitation. Comparable to VulnCheck Canary and IP Intelligence in approach (sensor-based, internet-scale exploitation visibility).
- Nucleus Security: Emerging vulnerability management and prioritization platform that aggregates exploit intelligence sources to drive remediation. Compares to VulnCheck's prioritization focus, though lacks the breadth of in-house exploit and canary data.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
VulnCheck social profiles
Digital presenceVulnCheck financial estimates
Financial estimateRevenue estimate
Valuation estimate
VulnCheck leadership team
Management profileNumber of profiles
Profiles11 records
VulnCheck funding detail
Funding detailFunding overview
Funding rounds4 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
VulnCheck M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about VulnCheck
What does VulnCheck do?
VulnCheck provides a multi-product exploit intelligence platform that aggregates vulnerability and exploit data from 500+ sources covering 400+ million records, delivering real-time intelligence on actively exploited vulnerabilities. The platform's core offerings include Exploit & Vulnerability Intelligence (early access to CVE data ahead of NVD), Initial Access Intelligence (proprietary exploit PoCs and detection artifacts), Canary Intelligence (real-world exploitation telemetry from globally deployed sensors), Target Intelligence (confirmed vulnerable host identification), and IP Intelligence (attacker infrastructure tracking). Data is delivered via API, BigQuery, and file-based feeds to enterprise security teams, MSSPs, and government agencies.
Is VulnCheck a public or private company?
VulnCheck is a private company. It is classified as venture growth investor backed and is currently operating.
When was VulnCheck founded?
VulnCheck was founded in 2021. It employs 51 to 100 people.
Where is VulnCheck based?
VulnCheck is headquartered in Lexington, United States, in the North America region.
How does VulnCheck make money?
Three revenue lines are on record. Exploit & Vulnerability Intelligence Platform (Subscription) is the primary driver. The others are government-specific Exploit Intelligence and vulnCheck Community (Free Tier).
Who are VulnCheck's main competitors?
Broad incumbents on record are Recorded Future, Mandiant (Google Cloud) and CrowdStrike. Direct peers are Tenable, Rapid7, Qualys, Flashpoint and Cybersixgill. Emerging players are GreyNoise and Nucleus Security.
Does VulnCheck have an API?
Yes. VulnCheck exposes a public API for querying its vulnerability and exploit intelligence datasets. The API provides endpoints for retrieving exploit data, initial access intelligence, canary telemetry, target intelligence, and IP intelligence by CVE ID or other identifiers. Customers can query indices including /v3/index/exploits, /v3/index/initial-access, /v3/index/vulncheck-canaries, and /v3/index/ipintel-3d. The API supports machine-level consumption for integration into security workflows, automation, and SOAR platforms. Developer documentation is at docs.vulncheck.com.
What industry is VulnCheck in?
VulnCheck's product category is Vulnerability Intelligence and Exploit Monitoring. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5415 and its SIC code is 7374.