SafeHill
SafeHill is a Chicago-based cybersecurity company that delivers an AI-human hybrid Threat Exposure Management platform (SecureIQ) with modules for SAST, DAST, cloud, and internal network security, serving security teams from SMBs to large enterprises across healthcare, finance, and government sectors.
- Company typePrivate
- Founded2023
- HeadquartersChicago, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What SafeHill does
SafeHill, legally operating as Tacticly, Inc. (d/b/a SafeHill and Tactic.ly), is a Chicago-based cybersecurity company founded in March 2023 that delivers an AI-human hybrid Threat Exposure Management (TEM) platform aligned with Gartner's Continuous Threat Exposure Management (CTEM) framework. The flagship SecureIQ platform unifies external attack surface monitoring, continuous penetration testing validation, AI-driven attack path prioritization, threat intelligence monitoring, compliance mapping, and remediation orchestration, supported by modules for internal network and Active Directory assessment (HygenIQ), multi-cloud configuration assessment across AWS, Azure, and GCP (HygenIQ Cloud), AI-powered SAST (Helix), continuous DAST for web applications and APIs (DynamIQ), and an autonomous exposure validation agent (Sentinel) that confirms the runtime exploitability of static findings.
The company serves security teams from small businesses to large enterprises across finance, healthcare, and government sectors, addressing alert fatigue, the limitations of point-in-time penetration testing, and the inability to prioritize actually exploitable vulnerabilities. Revenue is generated through tiered annual SaaS subscriptions (SecureIQ, SecureIQ Plus, SecureIQ Dev) sold via direct enterprise field sales and inside sales motions, supplemented by professional services for penetration testing, cyber risk and readiness assessments, and training. Named customers include Shiplify, First Medical, Caprock Solutions, Bandsintown, and APS Health. Distribution is supported by CISO advisors from Zscaler and Booking.com, a former FBI government-sector advisor, and the "Hacker & the Fed" podcast serving as the primary thought-leadership channel.
SafeHill emerged from stealth in October 2025 with a $2.6 million pre-seed round led by Mucker Capital and Chingona Ventures, and has since executed two material moves: the March 2026 acquisition of Phoenix-based Arcane Security (integrating autonomous AI penetration testing into SecureIQ and adding two directors), and the June 2026 announcement of a Tampa Bay research office to anchor AI-driven security R&D. AI is built in-house: a three-model Adversarial Intelligence Loop running on SafeHill-owned NVIDIA GPU infrastructure, including a 32B parameter FP8-quantized model fine-tuned via QLoRA on confirmed vulnerabilities, with no external AI provider calls.
SafeHill firmographics
Firmographics- Name
- SafeHill
- Legal name
- Tacticly, Inc.
- Website
- https://safehill.com
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SafeHill is a Chicago-based cybersecurity company that delivers an AI-human hybrid Threat Exposure Management platform (SecureIQ) with modules for SAST, DAST, cloud, and internal network security, serving security teams from SMBs to large enterprises across healthcare, finance, and government sectors.
- Ownership category
- akta.pro rank
SafeHill industry classification
Industry- Product category
- Threat Exposure Management / Cybersecurity Validation
- NAICS
- Computer Systems Design and Related Services (5415), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
Keywords
Where SafeHill is headquartered
LocationHeadquarters
- HQ city
- Chicago
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
SafeHill business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Platform Subscriptions: SaaS subscription model with tiered plans (SecureIQ, SecureIQ Plus, SecureIQ Dev) providing platform access. Recurring annual or monthly subscription fees for access to threat exposure management capabilities.
- Security Assessment Services: Professional services including human ethical hacker validation, penetration testing, and security assessments complement the AI platform. Service engagements may be bundled with subscriptions or sold separately.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | SecureIQ - Core Security Operations tier for organizations needing foundational threat exposure management |
| Subscription | Annual | SecureIQ Plus - Scaling Security Teams tier for growing security operations |
| Subscription | Annual | SecureIQ Dev - Vibe Coding tier for software development teams using AI coding assistants |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels7 records
SafeHill product offering
Product offeringCore offering
SafeHill sells the SecureIQ threat exposure management platform—an AI-human hybrid SaaS that continuously discovers external attack surfaces, validates which vulnerabilities are actually exploitable using the Sentinel autonomous agent, prioritizes attack paths in real time, maps findings to compliance frameworks, and orchestrates remediation through Jira, Slack, and Datadog. Offerings are delivered through three subscription tiers (SecureIQ, SecureIQ Plus, SecureIQ Dev) with additional modules (HygenIQ internal network, HygenIQ Cloud, Helix SAST, DynamIQ DAST) and complemented by SafeHill Cyber Services offensive security engagements for enterprise and mid-market customers.
Product overview
SafeHill offers a platform-plus-modules architecture built around its SecureIQ flagship threat exposure management platform. SecureIQ serves as the central operational hub linking the five CTEM pillars—scoping, discovery, validation, prioritization, and mobilization—in a continuous loop. The platform is offered in three subscription tiers: SecureIQ (core external threat exposure management with attack surface monitoring, AI-human hybrid pentesting, path prioritization, threat intelligence, compliance mapping, and remediation orchestration); SecureIQ Plus (adds HygenIQ for internal network security including Active Directory audits and internal network pentesting); and SecureIQ Dev (adds HygenIQ Cloud for multi-cloud configuration assessment, Helix for AI-powered SAST code scanning with Sentinel autonomous validation, and DynamIQ for continuous agentic AI web app and API pentesting). All tiers combine agentic AI automation with human ethical hacker validation, positioning SafeHill between fully automated scanner tools and traditional manual penetration testing services.
Differentiator
Problem solved
Functional benefit
Brands
- SecureIQ: Flagship AI-human hybrid threat exposure management platform for continuous discovery, validation, and prioritization of attack paths
- HygenIQ
- HygenIQ Cloud
- Helix
- DynamIQ
Products and services
- SecureIQ Flagship AI-human hybrid threat exposure management platform that continuously discovers external attack surfaces, validates what is actually exploitable, prioritizes attack paths in real time, maps findings to compliance frameworks, and orchestrates remediation through Jira, Slack, and Datadog. Sold as a tiered subscription (SecureIQ, SecureIQ Plus, SecureIQ Dev) for enterprise and mid-market security teams.
- HygenIQ Internal network security module for continuous internal attack surface monitoring, Active Directory audits, and continuous internal network testing to uncover weaknesses supporting lateral movement and privilege escalation.
- HygenIQ Cloud Multi-cloud security assessment module for AWS, Azure, and GCP environments, providing security misconfiguration detection, benchmark and compliance alignment (CIS, NIST, PCI-DSS), and automated cloud scanning.
- Helix AI-powered SAST and code security module combining intelligent static analysis (rule-based scanning, LLM-driven analysis, code property graph taint tracking, cross-function RAG), Sentinel autonomous exposure validation, and agentic AI pentesting for code review. Embedded as a GitHub PR reviewer for software development teams using AI coding assistants.
- DynamIQ Continuous agentic AI web application and API pentesting platform featuring automated DAST scanning, API dynamic security testing, AI-driven runtime validation, and Burp Suite integration to confirm exploitability against real application behavior.
- SafeHill Cyber Services Offensive security services including penetration testing (cloud, social engineering, physical, external/internal network, web/mobile/API, wireless), cyber risk and readiness assessments (CTEM program creation, crisis tabletop exercises, BAS, red team, SIEM gap analysis, AI integration impact assessment), and cybersecurity training. Sold to enterprise and mid-market customers as standalone engagements or bundled with SecureIQ subscriptions.
Quantifiable outcome
- Thousands of hours of engagement accumulated across customer environments
- +2 more outcomes
Companies that use SafeHill
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles4 records
SafeHill technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration8 records
AI capability11 records
Feature6 records
SafeHill partnerships and signals
Strategic signalScale indicators6 records
Recent moves6 records
Expansion highlights7 records
SafeHill competitors and assessment
Company assessmentDirect peers
- Tenable: Tenable is the leading vulnerability management platform with Nessus and Tenable One Exposure Management. SafeHill's SecureIQ directly competes on continuous vulnerability discovery, prioritization, and attack path analysis, but with an AI-human hybrid model rather than a scanner-first approach.
- Rapid7: Rapid7 InsightVM and the Exposure Command platform offer continuous vulnerability management, ASM, and threat prioritization. Rapid7 is one of the closest large competitors in the exposure management category SafeHill is targeting.
- Cymulate: Cymulate provides a breach and attack simulation (BAS) platform with continuous security validation aligned to CTEM. Both SafeHill and Cymulate compete on validating exploitability and prioritizing real attack paths over theoretical vulnerabilities.
- SafeBreach: SafeBreach is a BAS platform that runs continuous attack simulations to validate security controls. It is a direct competitor in the continuous threat exposure validation and prioritization space SafeHill targets.
- AttackIQ: AttackIQ offers an agentic BAS platform purpose-built for continuous security control validation and exposure management. It directly overlaps with SafeHill's continuous validation and attack path prioritization capabilities.
- Pentera: Pentera provides automated security validation that emulates attacker behavior across the full kill chain. It competes head-on with SafeHill's DynamIQ and broader continuous pentesting validation offering.
- XM Cyber: XM Cyber focuses on attack path management and continuous exposure validation, mapping how attackers would chain vulnerabilities across on-prem and cloud. It is closely comparable to SafeHill's attack path prioritization engine.
Broad incumbents
- CrowdStrike: CrowdStrike Falcon Surface and Falcon Exposure Management bundle ASM, vulnerability management, and prioritization into its broader endpoint and XDR platform. It is a broad incumbent whose expanding exposure management capabilities compete with SafeHill's SecureIQ.
- Palo Alto Networks: Palo Alto Networks Cortex Xpanse (ASM) and the broader Cortex platform offer attack surface management and exposure validation. It competes with SafeHill as a broad cybersecurity incumbent with overlapping exposure management capabilities.
Emerging players
- Bishop Fox: Bishop Fox is an offensive security services firm offering continuous penetration testing and attack surface management. It overlaps with SafeHill's hybrid AI-human penetration testing and continuous validation services offering, particularly for enterprises that want human-led validation.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
SafeHill social profiles
Digital presenceSafeHill compliance and trust
Trust signalCompliance13 records
SafeHill financial estimates
Financial estimateRevenue estimate
Valuation estimate
SafeHill leadership team
Management profileNumber of profiles
Profiles8 records
SafeHill subsidiaries and ownership
Company hierarchySubsidiaries1 record
SafeHill funding detail
Funding detailFunding overview
Funding rounds1 record
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SafeHill M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SafeHill
What does SafeHill do?
SafeHill sells the SecureIQ threat exposure management platform—an AI-human hybrid SaaS that continuously discovers external attack surfaces, validates which vulnerabilities are actually exploitable using the Sentinel autonomous agent, prioritizes attack paths in real time, maps findings to compliance frameworks, and orchestrates remediation through Jira, Slack, and Datadog. Offerings are delivered through three subscription tiers (SecureIQ, SecureIQ Plus, SecureIQ Dev) with additional modules (HygenIQ internal network, HygenIQ Cloud, Helix SAST, DynamIQ DAST) and complemented by SafeHill Cyber Services offensive security engagements for enterprise and mid-market customers.
Is SafeHill a public or private company?
SafeHill is a private company. It is classified as venture growth investor backed and is currently operating.
When was SafeHill founded?
SafeHill was founded in 2023. It employs 11 to 50 people.
Where is SafeHill based?
SafeHill is headquartered in Chicago, United States, in the North America region.
How does SafeHill make money?
Two revenue lines are on record. SaaS Platform Subscriptions are the primary driver. The others are security Assessment Services.
Who are SafeHill's main competitors?
Direct peers on record are Tenable, Rapid7, Cymulate, SafeBreach, AttackIQ, Pentera and XM Cyber. Broad incumbents are CrowdStrike and Palo Alto Networks. Bishop Fox is listed as an emerging player.
Does SafeHill have an API?
No public API is recorded for SafeHill.
What industry is SafeHill in?
SafeHill's product category is Threat Exposure Management / Cybersecurity Validation. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction. Its NAICS code is 5415 and its SIC code is 7371.