JupiterOne
JupiterOne provides an AI-powered cyber asset attack surface management platform unifying visibility across cloud, code, identity, and SaaS environments. Founded in 2018 and headquartered in Morrisville, NC, it serves CISOs, security architects, SecOps, and compliance teams at large enterprises.
- Company typePrivate
- Founded2018
- HeadquartersDurham, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What JupiterOne does
JupiterOne is a private cybersecurity software company founded in 2018 as a subsidiary of LifeOmic and spun out as an independent company in May 2021. Headquartered in Morrisville, North Carolina, the company operates an AI-powered Cyber Asset Attack Surface Management (CAASM) platform built on a graph-native data model using Neo4j. The platform ingests and normalizes assets from more than 200 pre-built integrations spanning cloud infrastructure, identity and access management, SaaS applications, code repositories, endpoints, and HR systems. It maps the relationships between these assets, identities, and security findings into a unified graph queried using JupiterOne's proprietary J1QL query language, and exposes natural language querying through an AI capability branded 'Ask J1'.
The product portfolio centers on the JupiterOne AI Risk Management Platform and three add-on modules: AI Attack Surface Management (AI ASM), Unified Vulnerability Management (UVM), and Continuous Controls Monitoring (CCM). Together these capabilities support asset discovery, vulnerability deduplication and prioritization by exploit path, and continuous evaluation of controls against frameworks including SOC 2, ISO 27001, NIST 800-53, FedRAMP, HIPAA, and DORA. Notable named customers include Robinhood, Cisco, Indeed, Databricks, HSBC, Mercury Financial, Okta, Zephyr AI, Blend, Socotra, and Rippling, primarily enterprise and technology organizations.
JupiterOne operates a SaaS subscription revenue model with quote-based enterprise pricing. Go-to-market is led by a direct enterprise field sales motion targeting CISOs, security architects, SecOps teams, and compliance professionals, complemented by a channel partner program, technology alliances (AWS, Cisco, Splunk, Snyk, Orca Security, Jamf, Tines), and GSI/GSP relationships. The company achieved unicorn status in June 2022 with a $70 million Series C led by Tribe Capital, bringing total disclosed funding to over $119 million across Series A, B, and C rounds; strategic investors include Intel Capital, Sapphire Ventures, Bain Capital Ventures, Cisco Investments, and Splunk Ventures.
JupiterOne firmographics
Firmographics- Name
- JupiterOne
- Legal name
- JupiterOne
- Website
- https://jupiterone.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- JupiterOne provides an AI-powered cyber asset attack surface management platform unifying visibility across cloud, code, identity, and SaaS environments. Founded in 2018 and headquartered in Morrisville, NC, it serves CISOs, security architects, SecOps, and compliance teams at large enterprises.
- Ownership category
- akta.pro rank
JupiterOne industry classification
Industry- Product category
- Cybersecurity Asset Attack Surface Management (CAASM)
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Attack Surface Management (EASM/CAASM) (HDADAHAC)
Keywords
Where JupiterOne is headquartered
LocationHeadquarters
- HQ city
- Durham
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
JupiterOne business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription: JupiterOne operates as a SaaS platform providing subscription-based access to its cyber asset attack surface management platform. Customers pay for platform access with pricing based on organizational size and asset volume.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels4 records
JupiterOne product offering
Product offeringCore offering
JupiterOne provides a graph-native Cyber Asset Attack Surface Management (CAASM) SaaS platform that unifies assets, security findings, identities, and compliance evidence across cloud, SaaS, code, identity, and AI environments through 200+ pre-built integrations. Its core offering is the AI Risk Management Platform, sold alongside three specialized modules — AI Attack Surface Management (AI ASM), Unified Vulnerability Management (UVM), and Continuous Controls Monitoring (CCM) — all built on a shared asset graph queried via the proprietary J1QL language and an AI-powered natural language interface called "Ask J1". The platform is sold to enterprise security and compliance teams via subscription on a quote-based pricing model.
Product overview
JupiterOne is an AI-powered Cyber Asset Attack Surface Management (CAASM) platform built on a graph-native data model. The core platform unifies assets, security, and compliance across cloud, code, identity, and AI environments through over 200 integrations. The product portfolio consists of the central AI Risk Management Platform plus three specialized add-on modules: AI Attack Surface Management (AI ASM) for discovering and managing AI tools and their data access; Unified Vulnerability Management (UVM) for deduplicating and prioritizing vulnerabilities by business risk; and Continuous Controls Monitoring (CCM) for real-time compliance evidence against frameworks like SOC 2, ISO, NIST, and HIPAA. All products share the unified asset graph and J1QL query language, enabling natural language queries across the full environment.
Differentiator
Problem solved
Functional benefit
Brands
- AI ASM (AI Attack Surface Management): Product for discovering and managing AI risks in enterprise environments including copilots, agents, and LLM APIs.
- UVM (Unified Vulnerability Management)
- CCM (Continuous Controls Monitoring)
- Ask J1
- J1QL
Products and services
- JupiterOne AI Risk Management Platform The central SaaS platform that collects and normalizes assets from 200+ integrations, maps asset relationships in a graph-native data model, and enables natural language querying and automated compliance and audit evidence collection across cloud, AI, code, identity, and SaaS environments. Sold to enterprise security and compliance teams as the foundational subscription.
- AI Attack Surface Management (AI ASM) Attack surface management product built for the cloud, SaaS, and AI era that provides continuous discovery of every cloud, SaaS tool, and AI integration (approved, shadow, or in between) and AI-aware discovery maps showing what AI agents can read, write, and touch across the environment. Sold to CISOs, Security Architects, and SecOps teams.
- Unified Vulnerability Management (UVM) Vulnerability management product built on the graph that deduplicates vulnerabilities across cloud, code, identity, and endpoints, prioritizes by exploit paths reaching the assets that matter most, and routes findings to the owner who can fix them. Sold to SecOps, Vulnerability Management Leads, and CISOs.
- Continuous Controls Monitoring (CCM) Compliance product that evaluates controls against live technical data continuously rather than at point-in-time audits. Uses a graph data model linking assets, identities, and configuration relationships across 200+ integrations to prove controls are working, with support for SOC 2, DORA, ISO, NIST, FedRAMP and HIPAA frameworks. Sold to CISOs, Compliance Leads, and Security Architects.
Quantifiable outcome
- 90% reduction in data pipeline costs after Neo4j migration
- +3 more outcomes
Companies that use JupiterOne
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles3 records
JupiterOne technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration30 records
AI capability5 records
Feature7 records
JupiterOne partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship and core.
- AWSflagshipOfficial technology alliance partner and cloud provider integration. JupiterOne provides comprehensive AWS environment security monitoring and asset visibility.
- CiscocoreTechnology alliance partner with integration capabilities for Cisco security ecosystem.
- SplunkcoreTechnology alliance partner with product integration for security data correlation.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
JupiterOne competitors and assessment
Company assessmentDirect peers
- Axonius: Closest direct competitor in the CAASM/asset-graph category, serving CISOs and security teams with a platform for unifying cyber asset inventory across cloud, SaaS, identity, and devices.
- Noetic Cyber: CAASM-focused startup offering a continuous asset inventory and security posture platform with a graph-based approach, directly comparable to JupiterOne's core offering.
Emerging players
- Orca Security: Agentless cloud security platform with its own asset graph and prioritization model, overlapping with JupiterOne's cloud and AI attack surface management offerings.
- Vulcan Cyber: Vulnerability remediation and prioritization platform that ingests asset context to drive owner-aware routing, comparable to JupiterOne's UVM module.
Broad incumbents
- Wiz: Cloud security leader whose agentless platform now extends into ASM and exposure management, competing head-to-head with JupiterOne in cloud and AI asset visibility.
- Rapid7: Security analytics and vulnerability management vendor offering InsightCloudSec and exposure solutions that overlap with JupiterOne's cloud and vulnerability posture capabilities.
- Tenable: Vulnerability and exposure management vendor whose Tenable One platform aggregates asset and vulnerability context, competing with JupiterOne's UVM and asset-graph modules.
- ServiceNow (Security & CMDB): Enterprise IT platform whose CMDB and Security Operations modules provide asset and configuration visibility, often competing against CAASM vendors in large accounts.
- Microsoft Security Exposure Management: Hyperscaler-native exposure and asset graph offering inside the Defender and Sentinel ecosystem, increasingly competing with standalone CAASM platforms.
- Palo Alto Networks (Cortex): Broad cybersecurity platform with Cortex XSIAM and ASM capabilities that overlap JupiterOne's asset graph and vulnerability prioritization use cases.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
JupiterOne social profiles
Digital presenceJupiterOne compliance and trust
Trust signalCompliance6 records
JupiterOne financial estimates
Financial estimateRevenue estimate
Valuation estimate
JupiterOne leadership team
Management profileNumber of profiles
Profiles5 records
JupiterOne funding detail
Funding detailFunding overview
Funding rounds3 records
Investors11 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
JupiterOne M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about JupiterOne
What does JupiterOne do?
JupiterOne provides a graph-native Cyber Asset Attack Surface Management (CAASM) SaaS platform that unifies assets, security findings, identities, and compliance evidence across cloud, SaaS, code, identity, and AI environments through 200+ pre-built integrations. Its core offering is the AI Risk Management Platform, sold alongside three specialized modules — AI Attack Surface Management (AI ASM), Unified Vulnerability Management (UVM), and Continuous Controls Monitoring (CCM) — all built on a shared asset graph queried via the proprietary J1QL language and an AI-powered natural language interface called "Ask J1". The platform is sold to enterprise security and compliance teams via subscription on a quote-based pricing model.
Is JupiterOne a public or private company?
JupiterOne is a private company. It is classified as venture growth investor backed and is currently operating.
When was JupiterOne founded?
JupiterOne was founded in 2018. It employs 51 to 100 people.
Where is JupiterOne based?
JupiterOne is headquartered in Durham, United States, in the North America region.
How does JupiterOne make money?
One revenue line is on record: saaS Subscription.
Who are JupiterOne's main competitors?
Direct peers on record are Axonius and Noetic Cyber. Emerging players are Orca Security and Vulcan Cyber. Broad incumbents are Wiz, Rapid7, Tenable, ServiceNow (Security & CMDB), Microsoft Security Exposure Management and Palo Alto Networks (Cortex).
Does JupiterOne have an API?
Yes. JupiterOne provides an API and the JupiterOne MCP Server (Model Context Protocol) for developer integration. The MCP Server is described as enabling large, highly regulated enterprises to validate security controls across complex hybrid cloud environments in real time, utilizing a cyber asset graph and AI-assisted automation. The MCP Server is in general availability (November 2025). Documentation is available at docs.jupiterone.io. Developer documentation is at docs.jupiterone.io.
What industry is JupiterOne in?
JupiterOne's product category is Cybersecurity Asset Attack Surface Management (CAASM). Its primary akta.pro industry code is HDADAHAC, Attack Surface Management (EASM/CAASM). Its NAICS code is 5415 and its SIC code is 7371.