GMO Flatt Security
GMO Flatt Security is a Tokyo-based application security firm providing AI-powered vulnerability diagnosis (Takumi), cloud security posture management (Shisho Cloud), secure coding training (KENRO), and expert manual penetration testing to software development organizations across Japan.
- Company typePrivate
- Founded2017
- HeadquartersTokyo, Japan
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What GMO Flatt Security does
GMO Flatt Security is a Tokyo-based application security firm founded in May 2017 and rebranded under the GMO Internet Group umbrella in January 2025. It serves software development organizations — primarily Japanese SaaS, FinTech, healthcare, and enterprise customers — with a hybrid model that pairs expert manual penetration testing (web, mobile, cloud, LLM, MCP, GraphQL, IoT, blockchain, and supply chain) with proprietary AI-powered automation. Headcount is disclosed at 1–10 in the firmographic record, but operational scope (100+ Takumi customers, 20M+ packages blocked per day, 100+ CVEs) suggests this is understated; this likely reflects the number reported to GMO Internet Group's security segment rather than the full practitioner base.
The company's technology stack centers on three products. Takumi byGMO is an AI security diagnosis agent that performs hybrid SAST/DAST analysis on GitHub-linked code and live environments, generates patches, unit tests, and reports, and submits fixes as GitHub Pull Requests; Takumi Runner monitors GitHub Actions CI/CD, and Takumi Guard blocks malicious npm packages at the registry layer. Shisho Cloud byGMO provides continuous CSPM/CIEM across AWS, Google Cloud, and Azure. KENRO byGMO is a hands-on secure-coding training platform with an automated judging engine (Patent No. 7463021). Manual professional services (Standard Plan at 500,000 JPY per web app, Professional Plan from 1,000,000 JPY) remain a core revenue layer that funds the vulnerability research engine — 100+ disclosed CVEs and a $30,000 international hacking competition prize — which in turn feeds the AI product. Distribution is direct (website inquiry, Slack-based engagement) supplemented by the GMO Internet Group's enterprise channel.
GMO Flatt Security firmographics
Firmographics- Name
- GMO Flatt Security
- Legal name
- GMO Flatt Security株式会社
- Website
- https://flatt.tech
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- GMO Flatt Security is a Tokyo-based application security firm providing AI-powered vulnerability diagnosis (Takumi), cloud security posture management (Shisho Cloud), secure coding training (KENRO), and expert manual penetration testing to software development organizations across Japan.
- Ownership category
- akta.pro rank
GMO Flatt Security industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (5415), Custom Computer Programming Services (541511), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage) (HDAAAKAG)
Keywords
Where GMO Flatt Security is headquartered
LocationHeadquarters
- HQ city
- Tokyo
- HQ country
- Japan
- HQ region
- Asia
Offices1 record
Markets served
GMO Flatt Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure, Others
Revenue model
- Manual Vulnerability Assessment & Penetration Testing: Professional security assessment services delivered by expert engineers. Includes Standard Plan (500,000 JPY per web application using AI-based black-box scanning) and Professional Plan (from 1,000,000 JPY based on engineer working days) for comprehensive manual assessments. Additional specialized diagnostics for cloud platforms, mobile apps, LLM applications, blockchain, IoT, and more.
- Takumi AI Security Agent Subscription: AI-powered security diagnostic agent subscription. Basic Plan at 70,000 JPY/month includes 250 credits/month for security diagnosis, 3,000 minutes/month of Takumi Runner, and Guard protection for 15 managed members. OSS developer free tier available.
- KENRO Secure Coding Training: Cloud-based secure coding learning platform subscription. No initial cost, browser-based exercises. Targets developer organizations for security skill development.
- Software Supply Chain Diagnosis: Cross-functional evaluation of CI/CD environment, permission design, and information leakage risks from code. Also includes incident response training. Priced per estimate.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Standard Plan - AI-based automated vulnerability diagnosis at 500,000 JPY per web application |
| Subscription | Multi-year contract | Professional Plan - Expert engineer-based comprehensive vulnerability detection from 1,000,000 JPY |
| Subscription | Monthly | Takumi AI Agent - Basic Plan at 70,000 JPY/month with 250 credits |
| Subscription | Monthly | KENRO - Secure coding training with no initial cost |
| One time/ perpetual license | Pay-as-you-go | Software Supply Chain Diagnosis - Quote-based pricing |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels10 records
GMO Flatt Security product offering
Product offeringCore offering
GMO Flatt Security provides custom vulnerability assessment, penetration testing, and consulting for software development organizations, complemented by AI-powered and SaaS products: Takumi (Japan's first security diagnosis AI agent combining SAST and DAST with automated remediation), Shisho Cloud (continuous CSPM/CIEM for AWS, GCP, and Azure), and KENRO (browser-based secure coding training). Services are scoped per application and technology stack, while Takumi and KENRO are sold as recurring subscriptions with self-serve onboarding.
Product overview
GMO Flatt Security offers a comprehensive security portfolio combining AI-powered automation with expert manual services. The core products include Takumi byGMO (Japan's first security diagnosis AI agent with whitebox/blackbox scanning and automatic remediation), Shisho Cloud byGMO (automated CSPM/CIEM with DAST), and KENRO byGMO (secure coding training platform). Expert manual services include penetration testing, vulnerability assessment across 15+ specializations (web apps, mobile, cloud, LLM, MCP, GraphQL, Firebase, containers, IoT, blockchain, etc.), and consulting services. The company emphasizes a hybrid approach combining AI agent diagnosis with human expert penetration testing.
Differentiator
Problem solved
Functional benefit
Brands
- Takumi: 日本初・セキュリティ診断AIエージェント (Japan's first AI security diagnostic agent). Provides automated vulnerability detection, static analysis (white-box), dynamic analysis (black-box), automatic vulnerability fixing, and supply chain protection through Takumi Runner and Takumi Guard.
- Shisho Cloud
- KENRO
Products and services
- Takumi byGMO Japan's first security diagnosis AI agent that combines white-box (SAST) source code analysis linked to GitHub with black-box (DAST) crawling of demo environments, automatically generates vulnerability remediation patches, unit tests, and reports submitted as GitHub Pull Requests. Includes Takumi Runner for GitHub Actions monitoring and Takumi Guard for malicious package blocking. Sold as a SaaS subscription with an OSS developer free tier.
- Shisho Cloud byGMO Automated continuous vulnerability diagnosis platform combining Cloud Security Posture Management (CSPM) and Cloud Infrastructure Entitlements Management (CIEM) with DAST for AWS, Google Cloud, and Azure environments.
- KENRO byGMO Browser-based secure coding training platform that combines hands-on hacking exercises with code fortification exercises covering OWASP Top 10 vulnerabilities, featuring an automated judging system for vulnerability fix validation. Targets developer organizations with no initial cost and free partial-content trial.
- Manual Vulnerability Assessment and Penetration Testing Services Comprehensive manual vulnerability assessment and penetration testing delivered by expert security engineers, with white-box source code diagnosis included as standard. Offered in a Standard Plan using AI-based black-box scanning and a Professional Plan based on engineer working days, with risk-focus prioritization of high-severity areas. Priced from 500,000 JPY per web application (Standard) and from 1,000,000 JPY (Professional).
- Software Supply Chain Diagnosis and Attack Exercise Cross-functional evaluation of CI/CD environments, permission design, and information leakage risks from code, combined with incident response training for development teams. Priced per estimate.
- Security Consulting Services Secure development consulting and secure generative AI consulting engagements that help software development organizations minimize process-level security risk.
Quantifiable outcome
- AI development era speed: reports delivered within hours to one day, compared to traditional external vendor timelines
- +4 more outcomes
Companies that use GMO Flatt Security
Customer profileNamed customers10 records
Segments3 records
Ideal customer profiles3 records
GMO Flatt Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability7 records
Feature7 records
GMO Flatt Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- GMO Internet Group (東証プライム上場: 9449)coreGMO Flatt Security is a member company of GMO Internet Group, a Tokyo Stock Exchange Prime-listed company (9449). The company operates within GMO's security business segment alongside GMO Security 24, GMO Cybersecurity by Ier, and other security services. This provides brand credibility, group cross-selling opportunities, and shared infrastructure.
Scale indicators5 records
Recent moves7 records
Expansion highlights6 records
GMO Flatt Security competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first security platform offering SAST, SCA, and container security. Directly comparable to Takumi's hybrid SAST/DAST approach and supply chain protection (Takumi Guard), targeting similar developer and DevSecOps buyer personas with subscription-based tooling.
- Veracode: Enterprise application security testing platform providing SAST, DAST, and software composition analysis. Closely aligned with GMO Flatt Security's hybrid AI/manual assessment model for large development organizations.
- Checkmarx: Application security platform specializing in SAST, SCA, and IaC scanning. Comparable to Takumi's whitebox-first approach and to GMO Flatt Security's manual whitebox diagnosis service included as standard.
- Semgrep: Code analysis platform offering SAST with custom rules and AI-assisted code scanning. Directly comparable to Takumi's AI-augmented source code analysis for development teams without dedicated security engineers.
- PortSwigger (Burp Suite): Provider of Burp Suite, the dominant tool used by penetration testers worldwide. Closely aligned with GMO Flatt Security's manual penetration testing and blackbox vulnerability assessment practice, particularly the Standard Plan AI-based web app scanning.
- Invicti (formerly Netsparker): Application security platform with automated DAST scanning and proof-based vulnerability verification. Comparable to Takumi's blackbox analysis capability and GMO Flatt Security's web application diagnostic services.
Broad incumbents
- GitHub Advanced Security: Integrated code scanning, secret scanning, and dependency review built into GitHub. Directly competes with Takumi's GitHub-integrated SAST workflow and Dependabot PR triage, but as part of GitHub's broader developer platform rather than a specialized security vendor.
- Trend Micro: Tokyo-headquartered global cybersecurity vendor offering application security, cloud security, and AI security capabilities. Overlaps with GMO Flatt Security's web app, cloud, and AI/LLM assessment services as part of a much broader security portfolio.
Regional players
- NRI Secure Technologies: Leading Japanese security consulting firm offering vulnerability assessment, penetration testing, and managed security services. Closest direct competitor in the Japanese enterprise assessment market, operating primarily in Japan rather than competing globally.
- LAC Co., Ltd. Japanese cybersecurity company providing vulnerability diagnosis, penetration testing, and security monitoring services. Comparable to GMO Flatt Security's manual assessment practice, with similar enterprise focus but a different product mix and Japan-centric footprint.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
GMO Flatt Security social profiles
Digital presenceGMO Flatt Security compliance and trust
Trust signalCompliance1 record
GMO Flatt Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
GMO Flatt Security leadership team
Management profileNumber of profiles
Profiles2 records
GMO Flatt Security funding detail
Funding detailFunding overview
Funding rounds5 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GMO Flatt Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GMO Flatt Security
What does GMO Flatt Security do?
GMO Flatt Security provides custom vulnerability assessment, penetration testing, and consulting for software development organizations, complemented by AI-powered and SaaS products: Takumi (Japan's first security diagnosis AI agent combining SAST and DAST with automated remediation), Shisho Cloud (continuous CSPM/CIEM for AWS, GCP, and Azure), and KENRO (browser-based secure coding training). Services are scoped per application and technology stack, while Takumi and KENRO are sold as recurring subscriptions with self-serve onboarding.
Is GMO Flatt Security a public or private company?
GMO Flatt Security is a private company. It is classified as corporate owned and is currently operating.
When was GMO Flatt Security founded?
GMO Flatt Security was founded in 2017. It employs 1 to 10 people.
Where is GMO Flatt Security based?
GMO Flatt Security is headquartered in Tokyo, Japan, in the Asia region.
How does GMO Flatt Security make money?
Four revenue lines are on record. Manual Vulnerability Assessment & Penetration Testing is the primary driver. The others are takumi AI Security Agent Subscription, KENRO Secure Coding Training and software Supply Chain Diagnosis.
Who are GMO Flatt Security's main competitors?
Direct peers on record are Snyk, Veracode, Checkmarx, Semgrep, PortSwigger (Burp Suite) and Invicti (formerly Netsparker). Broad incumbents are GitHub Advanced Security and Trend Micro. Regional players are NRI Secure Technologies and LAC Co., Ltd..
Does GMO Flatt Security have an API?
No public API is recorded for GMO Flatt Security.
What industry is GMO Flatt Security in?
GMO Flatt Security's product category is Application Security Testing. Its primary akta.pro industry code is HDAAAKAG, AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage). Its NAICS code is 5415 and its SIC code is 7371.