Bishop Fox
Bishop Fox is a Tempe, Arizona-based offensive security firm delivering penetration testing, red teaming, and continuous threat exposure management to large enterprises, including 26% of the Fortune 100, via its Cosmos platform, Cosmos AI engine, and an open-source security tooling portfolio.
- Company typePrivate
- Founded2006
- HeadquartersTempe, United States
- Headcount251–500
- GTM typeB2B
- OfferingServices
What Bishop Fox does
Bishop Fox is a privately held, US-based offensive security firm founded in 2005/2006 and headquartered in Tempe, Arizona, that delivers adversary-driven cybersecurity services to large enterprises. The company is organized around three service pillars: Penetration Testing Services (Application, AI/LLM, Mobile, Cloud, Product, Network, and Partner Assessments such as CASA/MASA, Oracle, and ioXt); Continuous Threat Exposure Management (CTEM) covering Attack Surface Discovery, Attack Surface Testing, and Emerging Threats; and Red Team & Readiness (Red Teaming, Social Engineering, Ransomware Readiness, IR Tabletop Exercises). Its customer base spans 1,700+ organizations including 26% of the Fortune 100, 50% of the Fortune 10, 8 of the top 10 global technology companies, and named logos such as Google, Amazon, Zoom, Equifax, Coinbase, and Flock Safety, with primary vertical practices in Financial Industry (FS-ISAC Affiliate Partner), Healthcare, Media & Entertainment (TPN), Energy & Utilities, and Public Safety Technology.
The firm's core technology is the Cosmos continuous offensive security platform, augmented by the Cosmos AI Engine — a proprietary AI module that automates application penetration testing at scale with a "human-on-the-loop" validation model and built-in ServiceNow/Jira integrations. Bishop Fox also maintains a substantial open-source tooling portfolio (Sliver, Eyeballer, CloudFox/CloudFox GCP, Cloudfoxable, AIMap, Joro, Burp Variables) that drives category authority and talent pipeline. Revenue is generated through a mix of professional services (engagement-based penetration testing and red teaming), managed continuous CTEM services, and subscription-aligned Cosmos AI-powered application pen testing, all delivered under custom, multi-year enterprise contracts.
The company operates from legal entities in the United States (Stach & Liu, LLC, the founding entity), the United Kingdom (Bishop Fox Limited), Spain (Bishop Fox S.L.), and Mexico (Bishop Fox MX, S. de R.L. de C.V.), with international expansion explicitly funded by a $129M Series B (led by Carrick Capital Partners in July 2022 and extended by WestCap in November 2022). Bishop Fox is ISO/IEC 27001 Type 2 and SOC 2 Type 2 certified, holds a 70 NPS rating, and is ranked #3 in the 2026 Top 15 Cybersecurity Consultancies (9.1/10) and named a Leader and Fast Mover in the 2026 GigaOm Radar for Attack Surface Management.
Bishop Fox firmographics
Firmographics- Name
- Bishop Fox
- Legal name
- Stach & Liu, LLC
- Website
- https://bishopfox.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Bishop Fox is a Tempe, Arizona-based offensive security firm delivering penetration testing, red teaming, and continuous threat exposure management to large enterprises, including 26% of the Fortune 100, via its Cosmos platform, Cosmos AI engine, and an open-source security tooling portfolio.
- Ownership category
- akta.pro rank
Bishop Fox industry classification
Industry- Product category
- Offensive Security Services
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Testing Laboratories (8734), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Threat & Vulnerability Assessments (TVA) (BPAKADAD)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE), AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage) (HDAAAKAG)
Keywords
Where Bishop Fox is headquartered
LocationHeadquarters
- HQ city
- Tempe
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
Bishop Fox business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Professional Security Services: Engagement-based offensive security services delivered as scoped projects: penetration testing (application, mobile, network external/internal, cloud, product, AI/LLM), red teaming, social engineering, ransomware readiness, IR tabletop exercises, secure code review, and partner/vendor assessments (CASA, MASA, Oracle, ioXt). Revenue recognized per engagement.
- Managed Continuous Services (CTEM): Recurring managed service delivering attack surface discovery, attack surface testing, and emerging threat monitoring under a Continuous Threat Exposure Management (CTEM) framework — a subscription-like ongoing service for security posture management.
- Cosmos Platform / Cosmos AI (AI-Powered Application Pen Testing): Recurring managed service powered by Cosmos AI delivering portfolio-scale application penetration testing at faster turnaround (~5 days) with expert validation — combines technology-enabled subscription dynamics with hands-on service delivery.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom / Quote-based enterprise engagements |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels9 records
Bishop Fox product offering
Product offeringCore offering
Bishop Fox is an offensive security firm that delivers adversary-driven cybersecurity services — penetration testing, red teaming, and continuous threat exposure management — to large enterprises and regulated industries. Its proprietary Cosmos Platform and Cosmos AI Engine power AI-augmented application penetration testing that combines automated exploitation with mandatory human expert validation, delivered as a managed service with portal-based onboarding. The company also maintains a widely adopted portfolio of open-source security tools (Sliver, Eyeballer, CloudFox, AIMap, Joro) and aligns engagements to compliance frameworks including DORA, PCI DSS v4.0.1, FDA 524B, ISO 27001, SOC 2, CJIS, and TPN.
Product overview
Bishop Fox delivers a platform-plus-modules architecture for offensive security. The Cosmos Platform is the unifying core that houses the Cosmos AI Engine — an AI-driven module that powers AI-Powered Application Penetration Testing with built-in portal integrations to ServiceNow and Jira for remediation ticketing. Around the platform, Bishop Fox offers discrete managed services organized into three pillars: Penetration Testing Services (Application, AI/LLM, Mobile, Secure Code Review, Cloud, Product, Network, Partner Assessments); Continuous Threat Exposure Management (Attack Surface Discovery, Attack Surface Testing, Emerging Threats); and Red Team & Readiness (Red Teaming, Social Engineering, Ransomware Readiness, IR Tabletop Exercises). Complementing the commercial offerings, Bishop Fox maintains an open-source security tooling portfolio including Sliver, Eyeballer, Burp Variables, CloudFox, CloudFox GCP, CloudFoxable (AWS/Azure training labs), AIMap, and Joro — many of which are produced by the same engineers who staff the consulting engagements.
Differentiator
Problem solved
Functional benefit
Brands
- Cosmos: Bishop Fox's continuous offensive security platform (formerly branded as CAST/Cosmos Continuous Offensive Security Platform) powering continuous penetration testing and the Cosmos AI engine for AI-powered application penetration testing.
- Cosmos AI
Products and services
- Application Penetration Testing Manual application-layer penetration testing service covering web and thick-client applications, executed by Bishop Fox consultants for enterprise security teams.
- AI-Powered Application Penetration Testing Application penetration testing service built on the Cosmos Platform and Cosmos AI Engine, automating reconnaissance and vulnerability discovery while keeping human consultants for validation, with portal integrations to ServiceNow and Jira for remediation ticketing.
- AI/LLM Security Assessment Specialized assessment service for AI and large-language-model systems, including prompt injection, jailbreak testing, model misuse, and agentic pipeline evaluation.
- Mobile Application Assessment Penetration testing and security review service for iOS and Android mobile applications, including API and backend coverage.
- Secure Code Review Manual and tool-assisted source code review to identify security defects and insecure coding patterns in customer applications.
- Cloud Penetration Testing Penetration testing services for cloud-hosted environments, covering AWS, Azure, and Google Cloud Platform architectures.
- Product Security Review Holistic security review service for commercial products, combining threat modeling, code review, and penetration testing.
- Network Penetration Testing External and internal network penetration testing services targeting on-premises and cloud-connected infrastructure.
- Partner Assessments Vendor program assessments covering CASA (Cloud App Security Assessment), MASA, Oracle Security Assessment, and ioXt Alliance Certification requirements for partner ecosystems.
- Continuous Threat Exposure Management (CTEM) Continuous managed program combining Attack Surface Discovery, Attack Surface Testing, and Emerging Threats services to identify, prioritize, and resolve business-impacting exposures across an organization's external footprint under a CTEM framework.
- Red Teaming Adversary-emulation engagements that test detection, response, and overall security program resilience against realistic threat actors.
- Ransomware Readiness Assessments and adversary simulations that measure an organization's preparedness against ransomware intrusion, encryption, and extortion scenarios.
- IR Tabletop Exercises Facilitated incident-response tabletop scenarios that exercise executive and operational response procedures.
- Cosmos Platform Continuous offensive security platform that consolidates Bishop Fox's testing methodologies, client portals, and findings management, with built-in integrations to ticketing systems such as ServiceNow and Jira for remediation workflows; powers the Cosmos AI Engine and AI-Powered Application Penetration Testing service.
- Sliver Open-source cross-platform adversary-emulation framework used by red teams for implant development, command-and-control, and post-exploitation; functions as an open-source alternative to Cobalt Strike.
- Eyeballer Open-source AI-powered reconnaissance tool that uses computer vision on webpage screenshots to flag 'interesting' pages (login pages, misconfigured apps, interesting endpoints) during penetration testing.
- CloudFox Open-source command-line tool for identifying attack paths, identities, and privilege-escalation opportunities in AWS cloud environments.
- CloudFox GCP Open-source Google Cloud Platform extension of CloudFox that automates attack-path identification against GCP resources.
- AIMap Open-source security testing platform that discovers, fingerprints, scores, and tests exposed AI endpoints including Ollama servers, MCP endpoints, and inference proxies.
- Joro Open-source collaborative web exploitation framework built with AI integration for chained vulnerability exploitation across teams.
Companies that use Bishop Fox
Customer profileNamed customers14 records
Segments6 records
Ideal customer profiles3 records
Bishop Fox technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability11 records
Feature8 records
Bishop Fox partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered flagship, core and minor.
- Flock SafetyflagshipFlock Safety engaged Bishop Fox to conduct continuous adversarial security testing across its hardware, software, and cloud products — a multi-stage, multi-layer adversarial testing campaign reinforcing Flock's SOC 2 Type II, ISO 27001, and CJIS Security Policy compliance posture. Functions as a flagship enterprise customer engagement that also sets a benchmark for the public safety technology industry.
- FS-ISACcoreBishop Fox is an FS-ISAC Affiliate Partner helping financial sector members strengthen resilience with adversary-driven offensive security — from penetration testing to red teaming — designed to protect financial operations, support regulatory expectations, and defend customer trust. The affiliation unlocks channel access to FS-ISAC member institutions globally.
- AppOmniminorAppOmni (CEO Brendan O'Connor) is referenced as an advisory board relationship through Vinnie Liu and as a co-panelist in Bishop Fox's "Building Security at Scale: The AppExchange Story" interview and ongoing SaaS security research. Reinforces Bishop Fox's positioning in SaaS and cloud security assurance.
- MoveworksminorMoveworks (CISO Damián Hasse and Security & Privacy Engineer Emily Choi-Greene) co-hosted Bishop Fox's "Pragmatic AI and LLM Security Mitigations for Enterprises" webcast, with shared research collaboration on AI/LLM security. Joint content and thought-leadership partnership.
- CERT/CCminorIf a vendor is unresponsive, Bishop Fox will send notification to CERT/CC 15 days after the first attempt at contacting the vendor — a coordinated vulnerability disclosure workflow integration rather than a commercial partnership.
Scale indicators8 records
Recent moves7 records
Expansion highlights7 records
Bishop Fox competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Trustwave is a global cybersecurity consulting and managed security services provider (owned by Optus/Singtel) offering penetration testing, red teaming, and managed detection; a broad incumbent that competes for enterprise offensive security budgets.
- Secureworks: Secureworks is a broad-incumbent cybersecurity services and managed detection provider (now owned by Sophos), offering penetration testing and red-team services as part of a wider portfolio; competes with Bishop Fox for enterprise security services wallet share.
- Optiv: Optiv is a large cybersecurity solutions integrator and advisory firm offering offensive security, advisory, and managed services; a broad incumbent competitor for Fortune 100 offensive security contracts alongside Bishop Fox.
- Palo Alto Networks Unit 42: Unit 42 is Palo Alto Networks' threat intelligence and incident response / consulting arm, offering penetration testing, red teaming, and threat advisory bundled with the broader Palo Alto platform; competes with Bishop Fox on enterprise offensive security engagements.
Direct peers
- Mandiant: Mandiant (now part of Google Cloud) is a direct competitor in offensive security, incident response, and managed detection; ranked #4 in the same 2026 expert consultancy review (9.0/10), with significantly larger scale and threat-intelligence distribution post-Google acquisition.
- NCC Group: NCC Group is a UK-based global cybersecurity consultancy offering penetration testing, red teaming, and managed security services; ranked #2 (9.2/10) in the same 2026 expert review and competes head-to-head with Bishop Fox in financial services and European enterprise markets.
- Coalfire: Coalfire is a US cybersecurity advisory and penetration testing firm ranked #5 (8.8/10) in the same 2026 expert review; competes directly with Bishop Fox on application, cloud, and compliance-aligned offensive security engagements.
- Atlant Security: Atlant Security is a top-ranked cybersecurity consultancy ranked #1 (9.7/10) in the 2026 expert review, specializing in offensive security, red teaming, and security assessments; positioned as a direct Bishop Fox competitor for enterprise offensive security programs.
Emerging players
- Rapid7: Rapid7 is a security analytics and vulnerability management vendor (InsightAppSec, Metasploit) whose application security testing and managed services overlap with Bishop Fox's pen testing and ASM offerings; an emerging platform-style competitor.
- Bugcrowd: Bugcrowd operates a crowdsourced security testing platform (penetration testing, bug bounty, ASM) that overlaps with Bishop Fox's Cosmos continuous testing and application pen testing services; an emerging platform-style competitor in continuous offensive security.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Bishop Fox social profiles
Digital presenceBishop Fox compliance and trust
Trust signalCompliance3 records
Bishop Fox financial estimates
Financial estimateRevenue estimate
Valuation estimate
Bishop Fox leadership team
Management profileNumber of profiles
Profiles8 records
Bishop Fox subsidiaries and ownership
Company hierarchySubsidiaries3 records
Bishop Fox funding detail
Funding detailFunding overview
Funding rounds3 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Bishop Fox M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Bishop Fox
What does Bishop Fox do?
Bishop Fox is an offensive security firm that delivers adversary-driven cybersecurity services — penetration testing, red teaming, and continuous threat exposure management — to large enterprises and regulated industries. Its proprietary Cosmos Platform and Cosmos AI Engine power AI-augmented application penetration testing that combines automated exploitation with mandatory human expert validation, delivered as a managed service with portal-based onboarding. The company also maintains a widely adopted portfolio of open-source security tools (Sliver, Eyeballer, CloudFox, AIMap, Joro) and aligns engagements to compliance frameworks including DORA, PCI DSS v4.0.1, FDA 524B, ISO 27001, SOC 2, CJIS, and TPN.
Is Bishop Fox a public or private company?
Bishop Fox is a private company. It is classified as venture growth investor backed and is currently operating.
When was Bishop Fox founded?
Bishop Fox was founded in 2006. It employs 251 to 500 people.
Where is Bishop Fox based?
Bishop Fox is headquartered in Tempe, United States, in the North America region.
How does Bishop Fox make money?
Three revenue lines are on record. Professional Security Services are the primary driver. The others are managed Continuous Services (CTEM) and cosmos Platform / Cosmos AI (AI-Powered Application Pen Testing).
Who are Bishop Fox's main competitors?
Broad incumbents on record are Trustwave, Secureworks, Optiv and Palo Alto Networks Unit 42. Direct peers are Mandiant, NCC Group, Coalfire and Atlant Security. Emerging players are Rapid7 and Bugcrowd.
Does Bishop Fox have an API?
No public API is recorded for Bishop Fox.
What industry is Bishop Fox in?
Bishop Fox's product category is Offensive Security Services. Its primary akta.pro industry code is BPAKADAD, Threat & Vulnerability Assessments (TVA), with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 54151 and its SIC code is 8734.