Intruder
Intruder is a UK-based exposure management SaaS platform delivering AI-powered vulnerability scanning, attack surface management, cloud security, container image scanning, and penetration testing to mid-market organizations and lean security teams, serving 3,000+ customers.
- Company typePrivate
- Founded2015
- HeadquartersLondon, United Kingdom
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Intruder does
Intruder is a UK-based, privately held cybersecurity company founded in 2015 by Chris Wallis and operating through its legal entity Intruder Systems Ltd (Company No. 09529593, headquartered at 71-75 Shelton Street, London). It builds an exposure management platform that combines vulnerability scanning, attack surface management, cloud security posture management (CSPM), container image scanning, secrets detection, and AI-assisted penetration testing into a single SaaS offering. The proprietary AI Pentesting capability deploys autonomous agents that actively validate scanner findings against target systems using methods employed by human pentesters, while GregAI provides conversational triage of vulnerabilities. The platform runs 170,000+ infrastructure, application, and attack surface checks and integrates with 15+ enterprise tools including AWS, Google Cloud, Azure, GitHub, Jira, Okta, Auth0, Drata, and Vanta.
The go-to-market is hybrid, pairing product-led growth through a permanent free plan and self-serve portal with a sales-assisted enterprise motion targeting mid-market organizations of approximately $50M+ revenue and 400-6,000 employees - a segment the company frames as structurally underserved by both enterprise and SMB security vendors. Pricing is tiered across Free, Essential, Cloud, Pro, and Enterprise plans (monthly/annual billing), with Enterprise contracts incorporating bolt-on false-positive reduction and ad-hoc testing delivered by Intruder consultants. The company has served 3,000+ customers including NHS, Fujifilm, Drata, Virgin Active, PostHog, Iwoca, Cinch, Farmatodo, The Alan Turing Institute, and Middlesex County UK, spanning healthcare, manufacturing, education, finance, retail, government, and technology.
The business has demonstrated capital efficiency uncommon for a growth-stage SaaS company: $14M ARR against only ~$1.5M cumulative equity and grant funding (CyLon Ventures, NCSC For Startups, Pitch@Palace, plus a 2020 round), with 50-60 employees operating across nine countries, full SOC 2 Type 2 certification, ISO 27001-aligned governance, and PCI DSS-hosted infrastructure. Recent product velocity has been concentrated in AI-native capabilities (AI Pentesting, GregAI, Container Image Scanning) and ecosystem expansion (DomainTools DNSDB integration for subdomain discovery), reflected in 81% YoY enterprise ARR growth during 2025 with 51% new-business growth and 250% expansion-revenue growth.
Intruder firmographics
Firmographics- Name
- Intruder
- Legal name
- Intruder Systems Ltd
- Website
- https://intruder.io
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Intruder is a UK-based exposure management SaaS platform delivering AI-powered vulnerability scanning, attack surface management, cloud security, container image scanning, and penetration testing to mid-market organizations and lean security teams, serving 3,000+ customers.
- Ownership category
- akta.pro rank
Intruder industry classification
Industry- Product category
- Cybersecurity / Exposure Management Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- Data Security & Privacy for Cloud (DLP, DSPM, Tokenization) (HDABAHAK), Cloud Data Security (DSPM, Cloud DLP) (HDADADAJ)
Keywords
Where Intruder is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Intruder business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- SaaS Subscription (Exposure Management Platform): Intruder operates on a SaaS subscription model providing access to its exposure management platform. Plans include Essential, Cloud, Pro, and Enterprise tiers with monthly or annual billing. The company reported 81% growth in enterprise customer annual recurring revenue during 2025, driven by new product launches and customer consolidation across multiple sectors. Enterprise ARR grew 81% with 51% increase in new business and approximately 250% increase in expansion revenue.
- Free Tier / Freemium: Permanent free plan providing vulnerability scanning, cloud security checks, container image scanning, and AI pentesting tools at no cost. The free tier supports up to five external targets, one cloud environment, two container images, and limited AI pentesting credits for up to three users. This serves as a lower-friction entry point for teams to prove value before expanding to paid coverage.
- Professional Services (Enterprise): Enterprise plan includes bolt-on services such as false positive reduction and ad-hoc testing where Intruder consultants investigate and confirm issues found during monthly assessments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free permanent plan for lean security teams |
| Subscription | Monthly or Annual | Essential plan - External vulnerability scanning |
| Subscription | Monthly or Annual | Cloud plan - Adds cloud security posture management |
| Subscription | Monthly or Annual | Pro plan - Adds AI pentesting and advanced features |
| Subscription | Annual or Multi-year contract | Enterprise plan - Full platform with consultant support |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Intruder product offering
Product offeringCore offering
Intruder sells a cloud-based exposure management SaaS platform that continuously discovers, scans, prioritizes, and validates vulnerabilities and misconfigurations across external infrastructure, cloud environments, web applications, APIs, and container images. The platform combines vulnerability management, attack surface monitoring, cloud security posture management, and AI-driven penetration testing into a single integrated subscription product aimed at security and IT teams.
Product overview
Intruder is an exposure management platform offering a unified portfolio of security products designed for mid-market organizations and lean security teams. The core platform combines AI Pentesting, Attack Surface Management, Cloud Security, Vulnerability Management, and GregAI Security Analyst into a single integrated system. Key modules include External and Internal Vulnerability Scanning, DAST for web applications, API Security, Container Image Scanning, Secrets Detection, and Compliance Reporting for SOC 2, ISO 27001, PCI DSS, HIPAA, and DORA. The platform is available across multiple pricing tiers (Free, Essential, Cloud, Pro, Enterprise) with a 14-day free trial option. Recent additions include AI Pentesting with autonomous agents for vulnerability validation and GregAI as an AI-powered security analyst. The platform integrates with major cloud providers (AWS, Azure, GCP), DevOps tools (Jira, GitHub, GitLab), identity providers (Okta, Auth0), and compliance platforms (Drata, Vanta).
Differentiator
Problem solved
Functional benefit
Brands
- GregAI: AI-powered virtual security analyst integrated into the Intruder platform
- AI Pentesting
- cvemon
- Autoswagger
Products and services
- AI Pentesting AI-driven penetration testing capability using autonomous agents to actively investigate and validate vulnerability scanner findings, providing the depth of a human pentest on demand. Covers issue-level investigations including injection flaws, client-side attacks, and information disclosure, with full-scope web application pentests available across Cloud, Pro, and Enterprise plans.
- Cloud Security (CSPM) Cloud Security Posture Management providing daily configuration checks for AWS, Azure, and Google Cloud environments, with automated vulnerability detection across cloud infrastructure and container image scanning integration with major cloud registries.
- Attack Surface Management Continuous monitoring and automated discovery of the external attack surface, including subdomain enumeration via the DomainTools DNSDB integration, detection of shadow IT, and alerting on newly exposed assets and unknown subdomains across extended networks.
- GregAI Security Analyst AI-powered virtual security analyst integrated into the Intruder platform that helps teams respond faster to security findings through natural language interactions and automated analysis of vulnerability data, providing intelligent context around vulnerabilities.
- Vulnerability Management Comprehensive vulnerability scanning platform with 140,000+ checks covering infrastructure, applications, and emerging threats, including risk-based prioritization to reduce alert fatigue, cyber hygiene reporting for compliance demonstration, and emerging threat detection triggered automatically when new CVEs are disclosed.
- cvemon Free vulnerability intelligence tool providing real-time CVE tracking and threat intelligence for security teams.
- Autoswagger Open-source tool for checking API authentication flaws in Swagger/OpenAPI specifications, available on GitHub.
Quantifiable outcome
- 81% growth in enterprise customer ARR during 2025
- +6 more outcomes
Companies that use Intruder
Customer profileNamed customers18 records
Segments3 records
Ideal customer profiles2 records
Intruder technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration19 records
AI capability7 records
Feature7 records
Intruder partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered supporting and core.
- Treble (PR Agency)supportingB2B technology PR agency handling Intruder's public relations. Treble's Cybersecurity Practice Group grew over 400% year-over-year, emerging as the agency's fastest-growing business unit. Treble selected for specialized domain expertise and high-velocity campaign execution capabilities. Treble client roster includes KnowBe4, Intruder, Filigran, and ThreatDown.
- DomainToolscoreIntegration partnership to incorporate DomainTools' FarSight passive DNS database into Intruder's Attack Surface Management platform. Enables Enterprise plan customers to automatically detect related subdomains across extended networks. Pilot program with 60 customers showed 100% detected increased subdomains, with 44% identifying more than 10 additional subdomains and 23% uncovering more than 50 additional subdomains. Partnership targets Shadow IT risks arising from misconfigurations and accidental exposures.
- AWS (Amazon Web Services)coreNative integration with AWS Elastic Container Registry for container image scanning. AWS is also a supported cloud environment for Cloud Security Posture Management and vulnerability scanning.
- Google Cloud PlatformcoreNative integration with Google Cloud Artifact Registry for container image scanning. GCP supported for Cloud Security Posture Management and vulnerability scanning. Intruder's services are hosted on Google Cloud Platform in the London (UK) region.
- Microsoft AzurecoreNative integration with Azure Container Registry for container image scanning. Azure supported for Cloud Security Posture Management and vulnerability scanning.
- Integration Partners EcosystemcorePlatform integrates with 15+ tools and services including Okta, Auth0, Microsoft, Cloudflare, GitHub, Jira, Dev.to, Slack, Microsoft Teams, GitLab, Azure DevOps, and CircleCI for compliance and workflow management.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Intruder competitors and assessment
Company assessmentBroad incumbents
- Qualys: Qualys offers the TruRisk Platform spanning VMDR, CSPM, container security, and web app scanning on a SaaS basis. It is one of the closest large incumbents to Intruder's unified exposure management positioning.
- Microsoft Defender Vulnerability Management: Microsoft bundles vulnerability management, CSPM, and exposure assessment into Defender for Cloud / Defender Vulnerability Management, often included for Microsoft-heavy estates. It is a meaningful competitor because it ships with the Microsoft security stack at near-zero incremental cost.
- Tenable: Tenable is the established vulnerability management leader (Nessus) with an exposure management platform covering on-prem, cloud, and container environments. It directly overlaps Intruder in external/internal vulnerability scanning, CSPM-adjacent capabilities, and DAST, but at a much larger enterprise scale.
- Rapid7: Rapid7's Insight Platform combines InsightVM (vulnerability management), InsightConnect (SOAR), and Metasploit, with active expansion into cloud security and exposure management. It directly competes in external vulnerability scanning and continuous assessment.
- CrowdStrike (Falcon Spotlight / Falcon Cloud Security): CrowdStrike bundles vulnerability management (Spotlight), CSPM, and exposure assessment into its Falcon endpoint platform. It is a major competitor for security teams consolidating tools and adds well-funded R&D pressure on standalone players like Intruder.
Direct peers
- Horizon3.ai (NodeZero): Horizon3.ai offers autonomous penetration testing via the NodeZero platform that continuously validates exploitability of vulnerabilities. It is the closest direct competitor to Intruder's AI Pentesting capability.
- Orca Security: Orca Security provides agentless cloud security (CSPM, CWPP, DSPM, vulnerability management) with an asset-centric exposure model. It directly competes with Intruder's cloud configuration checks and attack surface coverage for mid-market and enterprise customers.
- Wiz: Wiz is an agentless cloud security platform covering CSPM, CWPP, vulnerability scanning, and DSPM, and is expanding into broader exposure management. Acquired by Google/Alphabet (~$32B), it represents the most aggressive end of the cloud security competitive set impacting Intruder's CSPM and attack surface modules.
- Lacework: Lacework delivers agent-based cloud workload protection with compliance and vulnerability scanning across AWS, Azure, and GCP. It competes with Intruder's CSPM and container image scanning offerings in the cloud security market.
Emerging players
- Snyk: Snyk focuses on developer security (SCA, SAST, container, IaC) with growing exposure to application and cloud vulnerability scanning. It is a tangential peer for Intruder's DAST, API, and container scanning surface area in mid-market DevOps-driven deployments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Intruder social profiles
Digital presenceIntruder compliance and trust
Trust signalCompliance6 records
Intruder financial estimates
Financial estimateRevenue estimate
Valuation estimate
Intruder leadership team
Management profileNumber of profiles
Profiles4 records
Intruder funding detail
Funding detailFunding overview
Funding rounds5 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Intruder M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Intruder
What does Intruder do?
Intruder sells a cloud-based exposure management SaaS platform that continuously discovers, scans, prioritizes, and validates vulnerabilities and misconfigurations across external infrastructure, cloud environments, web applications, APIs, and container images. The platform combines vulnerability management, attack surface monitoring, cloud security posture management, and AI-driven penetration testing into a single integrated subscription product aimed at security and IT teams.
Is Intruder a public or private company?
Intruder is a private company. It is classified as venture growth investor backed and is currently operating.
When was Intruder founded?
Intruder was founded in 2015. It employs 51 to 100 people.
Where is Intruder based?
Intruder is headquartered in London, United Kingdom, in the Europe region.
How does Intruder make money?
Three revenue lines are on record. SaaS Subscription (Exposure Management Platform) is the primary driver. The others are free Tier / Freemium and professional Services (Enterprise).
Who are Intruder's main competitors?
Broad incumbents on record are Qualys, Microsoft Defender Vulnerability Management, Tenable, Rapid7 and CrowdStrike (Falcon Spotlight / Falcon Cloud Security). Direct peers are Horizon3.ai (NodeZero), Orca Security, Wiz and Lacework. Snyk is listed as an emerging player.
Does Intruder have an API?
Yes. Intruder offers a Developer Hub (developers.intruder.io) providing APIs and integrations for developers. The platform includes a Status API for monitoring service status (operational, degraded, under_maintenance states), which returns JSON with page state, components, and notices. The API supports rate limiting of 10 requests per second and returns paginated results for components and notices collections (max 25 records per request). Developer documentation is at developers.intruder.io/docs.
What industry is Intruder in?
Intruder's product category is Cybersecurity / Exposure Management Software. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of HDABAHAK, Data Security & Privacy for Cloud (DLP, DSPM, Tokenization). Its NAICS code is 54151 and its SIC code is 7372.