ProjectDiscovery
ProjectDiscovery is a cybersecurity company that monetizes a 100,000+ practitioner open-source community through Neo, an AI-powered autonomous penetration testing platform, and the ProjectDiscovery Cloud Platform, built on its Nuclei vulnerability scanner and 20+ open-source security tools.
- Company typePrivate
- Founded2020
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What ProjectDiscovery does
ProjectDiscovery is a San Francisco-based, venture-backed cybersecurity company that operates a hybrid open-source and commercial model. Its foundation is a portfolio of 20+ open-source security tools — most prominently Nuclei (a community-driven vulnerability scanner with 12,000+ templates and 900+ contributors) alongside Subfinder, Httpx, Naabu, Katana, Interactsh, and Proxify — collectively amassing 117,000+ GitHub stars and used by 100,000+ security practitioners. The company is incorporated as ProjectDiscovery, Inc. (Delaware), has 11-50 employees, and has raised approximately $26.7M across a 2021 seed/angel round ($1.7M, SignalFire-led) and a 2023 Series A ($25M, CRV-led with Point72, SignalFire, Rain Capital, Mango Capital, Accel, and Lightspeed). The company is SOC 2 Type II certified.
The commercial product layer rests on two offerings. The ProjectDiscovery Cloud Platform, launched in August 2023, provides a SaaS-hosted commercial version of the open-source toolchain with enterprise features (SSO, SAML, dedicated VPC, BYOK, volume credit discounts). Neo, introduced in December 2025 and commercially launched at RSAC 2026, is an AI-powered autonomous penetration testing platform combining frontier AI models (including Anthropic Opus 4.6) with a multi-agent Plan-Execute-Verify architecture, 30+ agent-native tools, OAST callback infrastructure, and isolated Firecracker microVM sandboxes. Neo performs continuous pentesting, PR security review on every pull request, continuous threat modeling, vulnerability triage from bug bounty platforms, and automated retesting of fixes — across web apps, APIs, cloud infrastructure, and source code. The platform reports benchmark results of 66 verified vulnerabilities (including 24 not detected by competing tools), 80% fewer false positives than code-only AI review, and 22 autonomously-disclosed CVEs in open-source projects.
Monetization combines a credit-based Neo tier ($250 per seat with 50 credits, $5 per additional credit) and annual Enterprise contracts (volume discounts, unlimited seats, dedicated VPC, BYOK, SSO/SAML, internal network auditing). Go-to-market is hybrid: a product-led funnel driven by the 100K+ open-source community funnels practitioners into self-serve Neo, while a sales-assisted motion targets enterprise accounts through demo requests and major conference presence (RSAC Innovation Sandbox 2025 winner, Black Hat 2025, Notable Capital Rising in Cyber 2026). Named enterprise customers include Elastic, a Fortune 500 restaurant chain, a top-10 global crypto exchange, and a publicly traded digital asset financial services company.
ProjectDiscovery firmographics
Firmographics- Name
- ProjectDiscovery
- Legal name
- ProjectDiscovery, Inc.
- Website
- https://projectdiscovery.io
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ProjectDiscovery is a cybersecurity company that monetizes a 100,000+ practitioner open-source community through Neo, an AI-powered autonomous penetration testing platform, and the ProjectDiscovery Cloud Platform, built on its Nuclei vulnerability scanner and 20+ open-source security tools.
- Ownership category
- akta.pro rank
ProjectDiscovery industry classification
Industry- Product category
- Application Security Testing Platform
- NAICS
- Software Publishers (5132), Computer Systems Design and Related Services (54151), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Application Security & DevSecOps Services (BPAKAHAJ), Penetration Testing & Red Teaming (BPAKAHAF), Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where ProjectDiscovery is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
ProjectDiscovery business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- ProjectDiscovery Cloud Platform (SaaS): Paid cloud platform offering enhanced versions of open-source security tools (Nuclei, Subfinder, Httpx) with additional features, automation, collaboration, and enterprise-scale capabilities for organizations.
- Neo AI Security Platform: Subscription-based AI-powered autonomous pentesting platform with credit-based consumption model. Pay-as-you-go plan starts at $250 per seat with 50 credits, topped up at $5 per credit. Enterprise tier includes volume discounts, unlimited seats, and dedicated VPC deployment.
- Open Source Community: Free open-source tools (Nuclei, Subfinder, Httpx, Naabu, Katana, and 20+ others) serve as community acquisition funnel, converting practitioners to paid cloud platform subscriptions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Hybrid | Pay-as-you-go | Pay as you go — Advanced security testing accessible to all teams |
| Subscription | Annual | Enterprise — For teams scaling security testing across the organization |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels9 records
ProjectDiscovery product offering
Product offeringCore offering
ProjectDiscovery develops and sells Neo, an AI-powered autonomous security testing platform that performs end-to-end penetration testing, PR security review, threat modeling, vulnerability triage, and remediation across web applications, APIs, cloud infrastructure, and source code. The company also operates the ProjectDiscovery Cloud Platform, a SaaS layer that hosts commercial versions of its widely adopted open-source security tools, including the Nuclei vulnerability scanner and a suite of 20+ reconnaissance tools used by over 100,000 security practitioners.
Product overview
ProjectDiscovery is a cybersecurity company that has evolved from an open-source vulnerability scanning community into a commercial platform-plus-modules portfolio. The core commercial product is Neo, an advanced autonomous AI-powered security testing platform (available via Pay As You Go starting at $250 and Enterprise tiers) that performs continuous pentesting, PR security review, threat modeling, vulnerability triage, and remediation across web applications, APIs, cloud infrastructure, source code, and networks. Neo is built on top of and interoperates with the company's flagship open-source tools — most notably Nuclei (the vulnerability scanner engine) and its community-curated Nuclei Templates library (12K+ templates, 900+ contributors) — as well as a suite of 20+ specialized open-source tools (Subfinder, Httpx, Naabu, Katana, Interactsh, Proxify, and others) collectively amassing 126.9K+ GitHub stars and used by 100K+ practitioners. The ProjectDiscovery Cloud Platform provides the SaaS-hosted commercial layer for these open-source tools with enterprise features (SSO, SAML, dedicated VPC, BYOK). A dedicated Triage module automates vulnerability report validation from bug bounty platforms (HackerOne, BugCrowd, Intigriti) and AI coding assistants (Claude Code), while the PR Security Review module delivers continuous pentesting on every pull request. The portfolio also includes published research (AI Code Deluge report), whitepapers (State of AppSec 2026, Attack Surface Management 2026), and webinars.
Differentiator
Problem solved
Functional benefit
Brands
- Neo: An autonomous AI-powered pentesting platform that performs continuous security testing, vulnerability validation, and delivers verified proof of exploitability for web applications, APIs, and code.
- Nuclei
- Subfinder
- HTTPx
- Katana
- Naabu
- Interactsh
Products and services
- Neo Neo is an autonomous AI-powered security testing platform that performs continuous penetration testing, PR security review, threat modeling, vulnerability triage, and remediation across web applications, APIs, cloud infrastructure, and source code. It combines runtime validation with AI reasoning to deliver verified exploitability evidence and is sold via Pay As You Go (starting at $250 for 50 credits) and Enterprise tiers.
- ProjectDiscovery Cloud Platform A SaaS platform that hosts commercial versions of Nuclei and related tools, providing cloud-based vulnerability detection, remediation workflows, asset inventory, AI-powered search, and enterprise features such as SSO, SAML provisioning, dedicated VPC deployment, and volume credit discounts.
- Nuclei Nuclei is a fast, customizable open-source vulnerability scanner supporting HTTP, TCP, DNS, File, Headless, and JavaScript protocols. Used by over 100,000 security practitioners with 30K+ GitHub stars and 50M+ scans per month.
- Triage Triage is an automated vulnerability report validation module that reproduces, validates, and resolves complex vulnerability reports from bug bounty platforms and internal scanners before they reach security teams, running each report in an isolated Firecracker microVM sandbox.
- PR Security Review PR Security Review is a continuous pentesting module that triggers a full pentest cycle (recon, analysis, exploit, report) on every pull request before it merges, with target SLAs of ~15 minutes per review.
- Subfinder Subfinder is a fast passive subdomain enumeration tool that discovers subdomains using multiple passive sources, with 13,900+ GitHub stars.
- Httpx Httpx is a fast and multi-purpose HTTP toolkit for running multiple probes with automated credential scavenging and multiple DNS providers, with 10,072+ GitHub stars.
- Naabu Naabu is a fast port scanner written in Go designed for rapid port enumeration across target infrastructure, with 6,013+ GitHub stars.
- Katana Katana is a next-generation crawling and spidering framework for web application reconnaissance and content discovery, with 17,077+ GitHub stars.
- Interactsh Interactsh is an OOB interaction gathering server and client library used for detecting blind vulnerabilities such as blind SSRF, blind XSS, and DNS-based exfiltration, with 4,391+ GitHub stars.
Quantifiable outcome
- 3x more critical findings detected compared to traditional tools
- +9 more outcomes
Companies that use ProjectDiscovery
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles2 records
ProjectDiscovery technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration14 records
AI capability9 records
Feature10 records
ProjectDiscovery partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core_integration.
- HackerOnecore_integrationNative integration with HackerOne enables vulnerability reports from bug bounty programs to flow directly into Neo's triage pipeline, preserving severity, metadata, and researcher context for automated validation and prioritization.
- BugCrowdcore_integrationNative integration with BugCrowd bug bounty platform enables automated vulnerability report triage and validation within Neo's platform.
- Intigriticore_integrationNative integration with Intigriti enables automated vulnerability report triage and validation within Neo's platform.
- GitHubcore_integrationNeo integrates natively with GitHub for PR security review workflows, enabling automated pentesting of pull requests and findings posted directly as PR comments with verified exploit proof.
- GitLabcore_integrationNeo integrates with GitLab for automated security review of merge requests, enabling continuous pentesting within GitLab workflows.
- Claude Code (Anthropic)core_integrationIntegration with Claude Code enables Neo to validate every finding discovered by Claude Code in real time, filtering noise and false positives before results reach security teams.
- AWS, GCP, Azure, Cloudflare, Vercelcore_integrationNeo offers native integrations with major cloud providers (AWS, GCP, Azure), CDN/edge providers (Cloudflare), and deployment platforms (Vercel) for automated security scanning and exposure analysis across cloud infrastructure.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
ProjectDiscovery competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first security platform offering SAST, SCA, container, and IaC scanning with a similar PLG/open-source heritage and strong enterprise tier. Snyk is the most direct competitor in AppSec targeting developers and security engineers.
- Semgrep: Code analysis platform providing SAST, secrets detection, and supply chain security, with an open-source engine (the Semgrep rules engine) that parallels ProjectDiscovery's open-source Nuclei community model.
- Invicti (Netsparker): DAST/penetration testing platform that has added AI capabilities and proof-based scanning — competing directly with Neo's autonomous pentesting and verified findings positioning.
- Pentera: Automated security validation platform that performs continuous, agent-based penetration testing against enterprise environments. Closest direct competitor to Neo's autonomous runtime validation model.
- Aikido Security: All-in-one application security platform offering SAST, DAST, SCA, and runtime scanning with a focus on reducing alert fatigue. Targets the same developer and AppSec buyer as ProjectDiscovery.
Broad incumbents
- Veracode: Established AppSec testing platform covering SAST, DAST, and software composition analysis with broad enterprise penetration. Represents the legacy incumbent that Neo's AI-driven approach is disrupting.
- GitHub Advanced Security: GitHub's bundled code security offering (CodeQL, secret scanning, Dependabot) integrated directly into the GitHub platform. The most dangerous platform incumbent due to bundling into the dominant VCS — and a key integration partner for Neo.
Others
- HackerOne: Bug bounty platform and a core integration partner for Neo's Triage module. Adjacent rather than competitive — HackerOne routes vulnerability reports, and Neo validates/triages them, creating a complementary ecosystem relationship.
Emerging players
- Apiiro: Code risk platform that uses deep code analysis and context to prioritize vulnerabilities and detect risks across the SDLC. Competes for the same AppSec budget with a different architectural approach (code-graph vs. runtime validation).
- Endor Labs: Software supply chain security platform focused on dependency selection, SCA, and reachability analysis. Competes for developer security mindshare with a narrower focus than ProjectDiscovery's broad AppSec/ASM scope.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
ProjectDiscovery social profiles
Digital presenceProjectDiscovery compliance and trust
Trust signalCompliance1 record
ProjectDiscovery financial estimates
Financial estimateRevenue estimate
Valuation estimate
ProjectDiscovery leadership team
Management profileNumber of profiles
Profiles6 records
ProjectDiscovery funding detail
Funding detailFunding overview
Funding rounds2 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ProjectDiscovery M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ProjectDiscovery
What does ProjectDiscovery do?
ProjectDiscovery develops and sells Neo, an AI-powered autonomous security testing platform that performs end-to-end penetration testing, PR security review, threat modeling, vulnerability triage, and remediation across web applications, APIs, cloud infrastructure, and source code. The company also operates the ProjectDiscovery Cloud Platform, a SaaS layer that hosts commercial versions of its widely adopted open-source security tools, including the Nuclei vulnerability scanner and a suite of 20+ reconnaissance tools used by over 100,000 security practitioners.
Is ProjectDiscovery a public or private company?
ProjectDiscovery is a private company. It is classified as venture growth investor backed and is currently operating.
When was ProjectDiscovery founded?
ProjectDiscovery was founded in 2020. It employs 11 to 50 people.
Where is ProjectDiscovery based?
ProjectDiscovery is headquartered in San Francisco, United States, in the North America region.
How does ProjectDiscovery make money?
Three revenue lines are on record. ProjectDiscovery Cloud Platform (SaaS) is the primary driver. The others are neo AI Security Platform and open Source Community.
Who are ProjectDiscovery's main competitors?
Direct peers on record are Snyk, Semgrep, Invicti (Netsparker), Pentera and Aikido Security. Broad incumbents are Veracode and GitHub Advanced Security. HackerOne is listed as an others. Emerging players are Apiiro and Endor Labs.
Does ProjectDiscovery have an API?
Yes. ProjectDiscovery offers API access as an Enterprise-tier feature. The API enables developers to programmatically access platform capabilities, export scan results in various formats (PDF, email, interface, or API-based exports), integrate vulnerability findings into external workflows, and manage assets and subscriptions programmatically. The Documentation is available at docs.projectdiscovery.io. Developer documentation is at docs.projectdiscovery.io.
What industry is ProjectDiscovery in?
ProjectDiscovery's product category is Application Security Testing Platform. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAJ, Application Security & DevSecOps Services. Its NAICS code is 5132 and its SIC code is 7370.