TAC Security
TAC Security is an AI-native vulnerability management and application security platform serving 10,000+ enterprises and government agencies across 100+ countries via its ESOF suite, with FY26 revenue of ₹57.26 Crore.
- Company typePublic
- Founded2013
- HeadquartersSan Francisco, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What TAC Security does
TAC Security, operating under TAC InfoSec Limited (NSE: TAC) and headquartered in San Francisco with operations across the US, India, and UAE, is an AI-native vulnerability management and application security vendor serving 10,000+ enterprises and government entities in 100+ countries. Its core platform, ESOF (Enterprise Security in One Framework), consolidates risk-based vulnerability management (ESOF VMP), web/mobile application security (ESOF AppSec), PCI DSS scanning (ESOF PCI ASV), agent-based vulnerability and configuration assessment (ESOF VACA), and AI-powered cyber risk quantification (ESOF CRQ) into a single console that produces a unified cyber risk score and 5-year vulnerability history. Supporting offerings include Socify.ai for SOC 2 compliance automation, CyberScope for Web3 smart contract auditing, ioXt IoT certification, and CyberSandia for US government cybersecurity services.
TAC Security firmographics
Firmographics- Name
- TAC Security
- Legal name
- TAC InfoSec Limited
- Website
- https://tacsecurity.com
- Company type
- Public
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- TAC Security is an AI-native vulnerability management and application security platform serving 10,000+ enterprises and government agencies across 100+ countries via its ESOF suite, with FY26 revenue of ₹57.26 Crore.
- Ownership category
- akta.pro rank
TAC Security industry classification
Industry- Product category
- Vulnerability Management & Application Security
- NAICS
- Computer Systems Design Services (541512), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
- akta.pro secondary industries
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
Keywords
Where TAC Security is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices6 records
Markets served
TAC Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Vulnerability Management Subscriptions: Annual subscription revenue from ESOF VMP platform with tiered pricing (Advanced, Premium, Enterprise). Recurring revenue model with multi-year contract potential.
- Application Security Testing: Per-application pricing for ESOF AppSec ranging from $900 (Advanced) to $1800 (Premium) annually, with Enterprise custom pricing. Additional revenue from manual penetration testing services.
- Compliance Automation (Socify.ai): SOC 2 compliance automation platform generating subscription revenue from AI-driven compliance workflows and evidence automation.
- CyberScope Web3 Security: Smart contract audits and blockchain security assessments adding approximately USD 1.2 million in revenue from the CyberScope acquisition.
- PCI Compliance Services: ESOF PCI ASV Approved Scanning Vendor services for payment card industry compliance with SLA-backed report delivery.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | ESOF AppSec Advanced - Annual application security testing |
| Subscription | Annual | ESOF AppSec Premium - Biannual comprehensive AppSec |
| Subscription | Multi-year contract | ESOF AppSec Enterprise - Unlimited enterprise-grade security |
| Unit Pricing | Pay-as-you-go | AASA (Automated Application Security Assessment) - Self-serve for developers and startups |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels6 records
TAC Security product offering
Product offeringCore offering
TAC Security operates the ESOF (Enterprise Security in One Framework) AI-native platform that consolidates vulnerability management, application security testing, PCI compliance scanning, agent-based configuration assessment, and cyber risk quantification into a single automated solution. It additionally offers Socify.ai for SOC 2 compliance automation, CyberScope for Web3 smart contract security, CyberSandia for U.S. government cybersecurity services, ioXt IoT certification, and the AASA self-serve application security assessment. The platform is used by more than 10,000 enterprises, financial institutions, and government agencies across 100+ countries.
Product overview
TAC Security offers an AI-native, integrated cybersecurity platform combining vulnerability management, application security, compliance automation, and Web3 security across 10 distinct products and services. The core ESOF (Enterprise Security in One Framework) platform unifies ESOF VMP for risk-based vulnerability management, ESOF AppSec for web/mobile application security, ESOF PCI ASV for PCI compliance scanning, ESOF VACA for agent-based vulnerability assessment, and ESOF CRQ for cyber risk quantification. Supporting products include Socify.ai (SOC 2 compliance automation), CyberScope (Web3/smart contract security), ioXt (IoT certification), CyberSandia (U.S. government cybersecurity services), and AASA (automated application security assessment). The platform serves 10,000+ enterprises across 100+ countries, positioning TAC Security as the world's 5th largest vulnerability management company.
Differentiator
Problem solved
Functional benefit
Brands
- ESOF: Enterprise Security in One Framework - AI-Native Vulnerability Management + AppSec platform with Certified Reports, Fast Turnaround, and Global Compliance
- Socify.ai
- CyberScope
- CyberSandia
- ioXt
- AASA
Products and services
- ESOF VMP (Vulnerability Management Platform) AI- and ML-powered risk-based vulnerability management platform that discovers, prioritizes, and remediates vulnerabilities across enterprise IT infrastructure, delivering a unified cyber risk score, 5-year vulnerability history, and integrations with existing security tools.
- ESOF AppSec Comprehensive web and mobile application security platform providing black box and grey box testing with OWASP Top 10 and SANS 25 vulnerability coverage, AI-powered cyber risk scoring, zero false positive detection, and SDLC-embedded DevSecOps security testing.
- ESOF PCI ASV PCI DSS Approved Scanning Vendor solution providing pre-configured scan templates, automated scheduled scans, a comprehensive PCI dashboard, and SLA-backed attested report delivery within 24 hours for payment card industry compliance.
- ESOF VACA (Vulnerability Assessment and Configuration Assessment) Agent-based vulnerability and configuration scanner for Linux and Windows systems that continuously scans, detects threats, and deploys automated patch management, with Threat Intel integration and zero-day vulnerability detection.
- ESOF CRQ (Cyber Risk Quantification) AI-powered cyber risk quantification platform that translates vulnerabilities into financial dollar impacts using a risk = breach likelihood x Impact + Application tier formula, enabling executives and boards to assess potential breach costs.
- Socify.ai AI-powered SOC 2 compliance automation platform that simplifies compliance through automated evidence collection, continuous monitoring, and rapid security assessments for AI, SaaS, fintech, and cybersecurity companies.
- CyberScope Web3 and blockchain security platform providing end-to-end smart contract auditing, token launch security, and blockchain dApp scanning for DeFi protocols, TON-based projects, and USDC stablecoin infrastructure.
- CyberSandia Statewide government cybersecurity platform delivering VAPT, endpoint protection, and incident response services to U.S. government infrastructure and agencies, including the State of New Mexico under a statewide contract.
- ioXt IoT Security Assessment & Certification IoT security assessment and certification service. TAC Security is one of only eight global labs authorized for ioXt Certification, providing security testing for smart devices, wearables, and connected platforms.
- AASA (Automated Application Security Assessment) Self-serve application security audits platform with instant reports and SOC 2 compliance automation, designed for developers and startups at a starting price of $540.
Quantifiable outcome
- 60% reduction in security gaps across applications
- +5 more outcomes
Companies that use TAC Security
Customer profileNamed customers20 records
Segments5 records
Ideal customer profiles4 records
TAC Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability8 records
Feature7 records
TAC Security partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered minor and core.
- Lunar StrategyminorStrategic partnership to integrate security validation with growth-focused services for Web3 projects ahead of token launches and ecosystem expansion.
- TON (The Open Network)coreCyberscope joined TON ecosystem as listed auditor providing smart contract audits, protocol risk assessments, and security support to TON-based developers and projects building on Telegram's blockchain network.
- Circle (USDC Issuer)coreCyberScope approved into USDC's Issuer Circle Partner Allowance Program following multi-stage compliance and governance review, positioning CyberScope as recognized security provider for organizations building with USDC.
- App Defense AlliancecoreTAC Security became Partner of App Defense Alliance, Linux Foundation for cloud application security.
- NSDL e-GovcoreProtean InfoSec, a NSDL e-Gov and TAC Security alliance for government cybersecurity services.
- Bombay Stock ExchangecoreTAC Security signed as Cyber Security Partner for Vulnerability Management for India's premier stock exchange.
- Tech MahindracoreEnterprise security solutions partnership to scale UK, Europe, and SAARC markets through Tech Mahindra's global distribution network.
- DeloittecoreStrategic alliance to deliver enterprise security solutions through Deloitte's consulting practice and client relationships.
- Ingram MicrocoreDistribution partnership through Ingram Micro's channel network for broader market reach.
- IBMcorePartnership to scale security solutions through IBM's enterprise sales channel to UK, Europe, and SAARC markets.
- GooglecoreGoogle partnered with TAC Security to perform risk assessment for their Global Partners. TAC Security also appointed as Google's MASA Security Assessor and Recommended/Preferred Security Partner for CASA (Cloud Application Security Assessment).
Scale indicators13 records
Recent moves8 records
TAC Security competitors and assessment
Company assessmentDirect peers
- Tenable: Tenable is the publicly-listed leader in vulnerability management (Nessus, Tenable One). Most direct competitor to TAC's ESOF VMP, serving the same Fortune 500 / enterprise customer base with a similar risk-based prioritization narrative, though at materially greater scale.
- Qualys: Qualys is a long-standing cloud-native vulnerability management and compliance platform. Closely comparable to TAC's ESOF VMP + ESOF PCI ASV offerings, especially in PCI DSS compliance scanning where both are Approved Scanning Vendors.
- Rapid7: Rapid7 offers InsightVM for vulnerability management alongside application security (InsightAppSec) and SIEM — a portfolio structure that closely mirrors TAC's ESOF VMP + AppSec stack, targeting the same mid-market and enterprise segments.
- SecurityScorecard: SecurityScorecard provides cyber risk quantification and ratings, overlapping with TAC's ESOF CRQ module and CRQ-style dollar-value risk translation for executive decision-making.
- Bitsight: Bitsight delivers external cyber risk ratings and quantification similar to TAC's CRQ. Both compete for the same board-level risk reporting use case at large enterprises.
- Snyk: Snyk is a developer-first application security platform (SAST, SCA, container security) — directly comparable to TAC's ESOF AppSec module, especially for the AI/SaaS/startup segment TAC targets via AASA and Socify.ai.
- Veracode: Veracode provides application security testing (SAST, DAST, manual pen testing) — directly comparable to ESOF AppSec, including the CREST PT-accredited manual penetration testing service.
- Checkmarx: Checkmarx offers an enterprise application security platform (SAST, SCA, IaC security). Overlaps with TAC's ESOF AppSec at the enterprise DAST/SAST/SDLC integration level.
Emerging players
- Wiz: Wiz is a fast-growing cloud security platform (CSPM, vulnerability management, CIEM). Competes with TAC's vulnerability and cloud security posture features, especially for cloud-native enterprises, and represents the type of well-capitalized emerging player that could compress TAC's growth.
Regional players
- Indusface: India-based application security and vulnerability management SaaS provider (Indusface WAS, Total Application Security). Directly comparable to TAC's ESOF AppSec + ESOF VMP, particularly for Indian enterprise and SMB customers where both are headquartered.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
TAC Security social profiles
Digital presenceTAC Security compliance and trust
Trust signalCompliance8 records
TAC Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
TAC Security leadership team
Management profileNumber of profiles
Profiles10 records
TAC Security subsidiaries and ownership
Company hierarchySubsidiaries4 records
TAC Security funding detail
Funding detailFunding overview
Funding rounds3 records
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TAC Security M&A and investment
M&A and investmentM&A3 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TAC Security
What does TAC Security do?
TAC Security operates the ESOF (Enterprise Security in One Framework) AI-native platform that consolidates vulnerability management, application security testing, PCI compliance scanning, agent-based configuration assessment, and cyber risk quantification into a single automated solution. It additionally offers Socify.ai for SOC 2 compliance automation, CyberScope for Web3 smart contract security, CyberSandia for U.S. government cybersecurity services, ioXt IoT certification, and the AASA self-serve application security assessment. The platform is used by more than 10,000 enterprises, financial institutions, and government agencies across 100+ countries.
Is TAC Security a public or private company?
TAC Security is a public company. It is classified as public and is currently operating.
When was TAC Security founded?
TAC Security was founded in 2013. It employs 251 to 500 people.
Where is TAC Security based?
TAC Security is headquartered in San Francisco, United States, in the North America region.
How does TAC Security make money?
Five revenue lines are on record. Vulnerability Management Subscriptions are the primary driver. The others are application Security Testing, compliance Automation (Socify.ai), cyberScope Web3 Security and PCI Compliance Services.
Who are TAC Security's main competitors?
Direct peers on record are Tenable, Qualys, Rapid7, SecurityScorecard, Bitsight, Snyk, Veracode and Checkmarx. Wiz is listed as an emerging player. Indusface is listed as a regional player.
Does TAC Security have an API?
No public API is recorded for TAC Security.
What industry is TAC Security in?
TAC Security's product category is Vulnerability Management & Application Security. Its primary akta.pro industry code is HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms, with a secondary code of HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies). Its NAICS code is 541512 and its SIC code is 7370.