PolySwarm
PolySwarm is a multi-engine malware intelligence platform serving security researchers and threat analysts. It aggregates competing antivirus engine verdicts through its proprietary PolyScore algorithm, complemented by CAPE/Triage sandbox analysis, YARA-based hunting, Private Communities, and LLM-powered reporting.
- Company typePrivate
- Founded2001
- HeadquartersSan Juan, Puerto Rico
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What PolySwarm does
PolySwarm, legally operating as Swarm Technologies Inc. and headquartered in San Juan, Puerto Rico, is a multi-engine malware intelligence platform that functions as a marketplace alternative to single-vendor antivirus solutions. The platform aggregates verdicts from a network of competing security engines on submitted artifacts — files, URLs, domains, QR codes, and IP addresses — and synthesizes them through its proprietary PolyScore algorithm into a single probability score indicating maliciousness, weighted by each engine's track record against specific malware families. Additional capabilities include dynamic sandboxing via CAPE (for payload and configuration extraction) and Triage (for scalable processing) supporting Windows, Linux, Android, and macOS detonation environments, YARA-based Live and Historical hunting with up to six months of retrospective matching, Private Communities for restricted-access analysis under NDA and GDPR constraints, and LLM-powered sample reports that summarize multi-engine and sandbox findings for analyst triage.
The business model combines a freemium self-service tier (Community) with Premium and Enterprise subscriptions and usage-based API quotas. Customers access the platform via a web UI (polyswarm.network), REST API v3/v4, Python SDK, CLI, and STIX/TAXII integrations for interoperability with existing security infrastructure. The go-to-market is product-led growth with low-friction signup via GitHub, Google, or email, supplemented by an enterprise demo-request sales motion for larger accounts requiring custom quotas and multi-year contracts. A complementary community-led motion operates through the NectarNet Rewards browser extension, which distributes NCT tokens to users who share threat intelligence data while browsing. The primary customer segment is security researchers and threat analysts conducting malware analysis, threat hunting, and incident response, served through a horizontal segmentation approach with no disclosed named enterprise logos. Headcount stands at 51–100 employees, and the company raised $26 million in March 2018 from BlockTower Capital and Science Blockchain with no subsequent disclosed funding rounds.
PolySwarm firmographics
Firmographics- Name
- PolySwarm
- Legal name
- Swarm Technologies Inc.
- Website
- https://polyswarm.io
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- PolySwarm is a multi-engine malware intelligence platform serving security researchers and threat analysts. It aggregates competing antivirus engine verdicts through its proprietary PolyScore algorithm, complemented by CAPE/Triage sandbox analysis, YARA-based hunting, Private Communities, and LLM-powered reporting.
- Ownership category
- akta.pro rank
Where PolySwarm is headquartered
LocationHeadquarters
- HQ city
- San Juan
- HQ country
- Puerto Rico
- HQ region
- Latin America
Markets served
PolySwarm business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription Plans: Tiered subscription model with Community (free), Premium, and Enterprise tiers. Enterprise plan shown with daily API limits of 12,500 requests and access to all features including sandboxing, hunting, and reporting.
- API Usage Quotas: Usage-based quotas tied to subscription tiers, with monthly limits on features like hash searches (example shown: 7,000,000/mo limit). Quotas reset on a monthly cycle.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier with basic malware scanning and community features |
| Subscription | Multi-year contract | Enterprise plan with high-volume API access and full feature set |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels4 records
PolySwarm product offering
Product offeringCore offering
PolySwarm operates a multi-engine malware intelligence platform where a distributed network of competing antivirus engines and arbiters analyze submitted artifacts (files, URLs, domains, IPs, QR codes) to provide threat verdicts. The platform consolidates engine outputs via the proprietary PolyScore algorithm into a single probability score, and supports dynamic sandbox analysis (CAPE and Triage), YARA-based threat hunting, and Private Communities for restricted analysis, accessible through web UI, REST API, Python SDK, and CLI.
Product overview
PolySwarm is a multi-engine malware intelligence platform offering a VirusTotal alternative marketplace where competing antivirus engines analyze submitted artifacts. The platform consists of a core web-based UI (PolySwarm UI) and API access via REST API and Python SDK. Customers interact through the PolySwarm CLI or programmatically via the Python SDK. Key capabilities include artifact scanning with PolyScore threat scoring, dynamic sandboxing via CAPE and Triage sandboxes, YARA-based threat hunting (Live and Historical), and Private Communities for restricted analysis. The ecosystem includes the NectarNet Rewards browser extension program and specialized engines like the DefenseNet phishing engine. PolyScore synthesizes multi-engine verdicts into authoritative threat probability scores, while LLM-powered reports provide AI-generated malware analysis summaries.
Differentiator
Problem solved
Functional benefit
Brands
- NectarNet: Browser extension rewards program allowing users to share threat intelligence data and earn NCT cryptocurrency tokens.
Products and services
- PolySwarm Platform Multi-engine malware intelligence platform where a network of competing antivirus engines analyzes submitted artifacts (files, URLs, domains, IPs) to provide threat verdicts and metadata, accessible via web UI, CLI, REST API, and Python SDK.
- PolySwarm Sandboxing Dynamic malware analysis capability supporting both CAPE sandbox (for payload and configuration extraction) and Triage sandbox (for scalable high-volume processing), covering Windows, Linux, Android, and macOS environments and files including PE executables, documents, archives, APKs, emails, and URLs.
- PolySwarm Hunting YARA-based threat hunting capability with Live Hunting for real-time artifact matching as samples are submitted, and Historical Hunting for retrospective analysis of past submissions (up to 6 months).
- Private Communities Invite-only community feature allowing teams to upload and analyze artifacts privately with restricted metadata access, supporting NDA, GDPR compliance, and other sensitive use cases.
- NectarNet Rewards Browser extension program (Chrome, Brave, Firefox) that rewards users with NCT tokens for sharing threat intelligence data while browsing the internet.
- DefenseNet Phishing Engine Specialized engine dedicated to phishing detection, added to the PolySwarm marketplace to provide dedicated threat intelligence for phishing threats.
Companies that use PolySwarm
Customer profileSegments1 record
Ideal customer profiles2 records
PolySwarm technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability8 records
Feature10 records
PolySwarm partnerships and signals
Strategic signalScale indicators1 record
Recent moves6 records
Expansion highlights6 records
PolySwarm competitors and assessment
Company assessmentBroad incumbents
- CrowdStrike: Endpoint security leader with native sandboxing (Falcon Sandbox), threat intelligence, and AI-driven triage built into the Falcon platform. Represents the bundled incumbent PolySwarm must integrate alongside rather than displace.
- Recorded Future: Large-scale threat intelligence platform owned by Mastercard with broad telemetry collection and AI-driven analytics. Overlaps with PolySwarm's threat intelligence and metadata search layer for enterprise buyers.
Direct peers
- VirusTotal: Google-owned multi-engine malware scanning platform that aggregates verdicts from dozens of antivirus engines. PolySwarm explicitly positions itself as a VirusTotal alternative with a marketplace-based, engine-incentivized model.
- ReversingLabs: File and binary analysis platform providing malware detection, classification, and threat intelligence. Overlaps with PolySwarm's file scanning, sandboxing, and PolyScore-style classification capabilities, primarily serving enterprise SOC and threat-intel teams.
- Intezer: Genetic malware analysis platform that identifies code reuse and family attribution across samples. Comparable to PolySwarm in providing deeper-than-AV malware analysis for security researchers and SOC analysts.
- Hybrid Analysis (CrowdStrike Falcon Sandbox): Free malware analysis service (formerly CrowdStrike's Falcon Sandbox) offering sandbox detonation and multi-engine scanning. Direct competitor to PolySwarm's combined scanning and CAPE/Triage sandboxing workflow.
- ANY.RUN: Interactive malware sandbox with multi-engine scanning and threat intelligence feeds targeting SOC analysts and incident responders. Comparable feature set across sandbox detonation, scanning, and threat-hunting use cases.
- Joe Sandbox: Deep malware analysis sandbox supporting Windows, macOS, Linux, Android, and iOS. Directly comparable to PolySwarm's CAPE/Triage sandboxing layer for advanced dynamic analysis.
Emerging players
- ThreatConnect: Threat intelligence platform combining data aggregation, scoring, and workflow tooling. Overlaps with PolySwarm's metadata search, IOC search, and STIX/TAXII-based intelligence distribution.
- Anomali: Threat intelligence platform aggregating feeds and providing analytics for SOC teams. Comparable in threat-intel aggregation and STIX/TAXII distribution, though less focused on multi-engine file scanning.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
PolySwarm social profiles
Digital presencePolySwarm financial estimates
Financial estimateRevenue estimate
Valuation estimate
PolySwarm leadership team
Management profileNumber of profiles
Profiles5 records
PolySwarm funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
PolySwarm M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about PolySwarm
What does PolySwarm do?
PolySwarm operates a multi-engine malware intelligence platform where a distributed network of competing antivirus engines and arbiters analyze submitted artifacts (files, URLs, domains, IPs, QR codes) to provide threat verdicts. The platform consolidates engine outputs via the proprietary PolyScore algorithm into a single probability score, and supports dynamic sandbox analysis (CAPE and Triage), YARA-based threat hunting, and Private Communities for restricted analysis, accessible through web UI, REST API, Python SDK, and CLI.
Is PolySwarm a public or private company?
PolySwarm is a private company. It is classified as venture growth investor backed and is currently operating.
When was PolySwarm founded?
PolySwarm was founded in 2001. It employs 51 to 100 people.
Where is PolySwarm based?
PolySwarm is headquartered in San Juan, Puerto Rico, in the Latin America region.
How does PolySwarm make money?
Two revenue lines are on record. Subscription Plans are the primary driver. The others are API Usage Quotas.
Who are PolySwarm's main competitors?
Broad incumbents on record are CrowdStrike and Recorded Future. Direct peers are VirusTotal, ReversingLabs, Intezer, Hybrid Analysis (CrowdStrike Falcon Sandbox), ANY.RUN and Joe Sandbox. Emerging players are ThreatConnect and Anomali.
Does PolySwarm have an API?
Yes. PolySwarm offers a public REST API v3 for customers to interact with the platform, enabling artifact scanning, hash searching, metadata searching, IOC searching, sandboxing, hunting with YARA rules, report generation, and LLM-powered analysis reports. Authentication uses API keys. Supports Python SDK v3 (polyswarm package) and CLI tool (polyswarm CLI). STIX/TAXII connectivity is available for threat intelligence sharing. The API supports private communities for restricted artifact access and scanning. Developer documentation is at docs.polyswarm.io/customers.