DarkLight
- Company typePrivate
- Founded2014
- HeadquartersRedmond, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What DarkLight does
DarkLight, Inc. was a private Redmond, Washington-based cybersecurity software company that built and commercialized a single product, the Cyio platform (Latin for 'to-know'). Cyio is a knowledge-driven AI platform designed as an all-sensor fusion solution for Continuous Threat Exposure Management (CTEM); it ingests vulnerability and assessment data from scanners such as Tenable, Rapid7, Qualys, and Synqly, enriches it with multiple threat intelligence sources (NVD, CISA KEV, EPSS, Rapid7 Metasploit, Offensive Security Exploit Database, and Resecurity Context), and applies business-context mapping (a NIST-based Information Systems construct) to continuously repopulate risk scores — at minimum daily — and propose remediation actions. The technology originated at the Pacific Northwest National Laboratory (a U.S. Department of Energy national lab) to support an NSA effort and incorporates MITRE ATT&CK framework alignment for threat analysis. Native mail-handler integrations route remediation actions into Jira, ServiceNow, ConnectWise, and Microsoft Teams workflows.
DarkLight operated on a SaaS subscription revenue model with quote-based, demo-gated enterprise pricing and no publicly disclosed tiers. Go-to-market combined direct enterprise sales with a channel-led motion through MSSPs, the Tenable Assure Partner Program (Bronze level), the HackFactory partnership in Washington D.C. (targeting DoD and CMMC ecosystem buyers), and ecosystem engagements such as Space ISAC and the Cyber Readiness Institute. Target customers spanned mid-market and enterprise organizations seeking CTEM and risk prioritization, MSSPs serving multiple tenants, and small businesses needing automation, with a secondary focus on space-sector and DoD-contractor verticals requiring FedRAMP and CMMC alignment. In June 2025, DarkLight was acquired by Liongard, and Cyio was rebranded as Liongard Cyio to extend Liongard's attack-surface-management capabilities into AI-driven vulnerability prioritization for managed service providers. At the time of acquisition, DarkLight had a headcount of 1-10 employees and a leadership team consisting of CEO Dan Wachtler, CISO Aaron Shaha, and EVP of Engineering Paul Patrick.
DarkLight firmographics
Firmographics- Name
- DarkLight
- Legal name
- DarkLight, Inc.
- Website
- https://darklight.ai
- Company type
- Private
- Founded year
- 2014
- Operating status
- Acquired
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
DarkLight industry classification
Industry- Product category
- Cybersecurity Risk Management
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Attack Surface Management (EASM/CAASM) (HDADAHAC)
- akta.pro secondary industry
- Continuous Controls Monitoring (CCM) (HDADAHAE)
Keywords
Where DarkLight is headquartered
LocationHeadquarters
- HQ city
- Redmond
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
DarkLight business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cyio SaaS Subscription: Cloud-based AI-powered cybersecurity platform subscription providing continuous threat exposure management, risk prioritization, and vulnerability analysis capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise SaaS subscription - pricing not publicly disclosed |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels10 records
DarkLight product offering
Product offeringCore offering
DarkLight developed Cyio, an AI-powered cybersecurity platform engineered for Continuous Threat Exposure Management (CTEM). The platform uses an all-sensor fusion architecture to ingest signals from across an organization's security stack, applies continuous threat intelligence and a knowledge-based AI engine to prioritize exposures, and automates remediation workflows via ticketing and mail-handler integrations aligned to MITRE ATT&CK and NIST frameworks.
Product overview
DarkLight offers a single unified product: the Cyio platform, an AI-powered cybersecurity platform for Continuous Threat Exposure Management (CTEM). Cyio was originally developed at the Pacific Northwest National Laboratory and uses a knowledge-driven AI approach to automate vulnerability analysis, risk prioritization, and reporting. The platform integrates with existing vulnerability scanners (Tenable, Rapid7, Qualys), enriches data with multiple threat intelligence sources (NVD, CISA KEV, EPSS, Resecurity Context™), and provides actionable recommendations with native integrations to ticketing systems (Jira, ServiceNow, Microsoft Teams). DarkLight was acquired by Liongard in June 2025.
Differentiator
Problem solved
Functional benefit
Brands
- Cyio: Cyio (Latin for 'to-know') is DarkLight's flagship knowledge-driven AI platform for Continuous Threat Exposure Management (CTEM). It provides automated cyber risk prioritization, threat intelligence application, vulnerability management, and compliance reporting for organizations.
Products and services
- Cyio Platform
Quantifiable outcome
- Cuts manual processing and analysis time by 90% for threat intelligence analysis
- +2 more outcomes
Companies that use DarkLight
Customer profileNamed customers2 records
Segments5 records
Ideal customer profiles4 records
DarkLight technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
AI capability6 records
Feature9 records
DarkLight partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core, important and minor.
- LiongardcoreLiongard acquired Darklight Cyio platform to expand its attack surface management platform, integrating AI-powered cyber risk solutions to enhance vulnerability prioritization and threat intelligence for MSPs. The acquisition aims to improve security posture management, operational efficiency, and scalability for managed service providers. Cyio is rebranded as Liongard Cyio post-acquisition.
- HackFactoryimportantDarkLight expanded into the Washington D.C. metropolitan area through a strategic partnership with HackFactory, a startup studio and growth lab. The partnership establishes DarkLight at HackFactory's facilities targeting MSSPs supporting DoD and CMMC programs. The partnership leverages HackFactory's innovation ecosystem for collaboration and enhanced cybersecurity solutions development.
- TenablecoreDarkLight achieved Bronze Level membership in the Tenable Assure Partner Program, strengthening its security portfolio with Tenable Exposure Management solutions. The partnership enables DarkLight to offer a comprehensive view of vulnerabilities across various environments, coupled with Cyio's analytical depth for strategic decision-making. This addresses complexities of modern corporate environments.
- Space ISACcoreDarkLight joined Space ISAC at the Small Business level to contribute to cyber threat information sharing within the commercial space industry. DarkLight's expertise in FedRAMP and CMMC complements Space ISAC's mission to enhance cybersecurity for space sector companies. As a member, DarkLight actively contributes to collaborative defense efforts and information sharing.
- ResecuritycoreDarkLight partnered with Resecurity to integrate their Context threat intelligence solution, which identifies indications of cyber intrusions and data breaches. This enables DarkLight to deliver high-quality cyber threat intelligence data to enrich client risk assessments within Cyio, reducing blind spots and improving enterprise cybersecurity posture. The partnership provides comprehensive risk assessments tailored to each client's unique business context.
- Cyber Readiness InstituteminorDarkLight is associated with the Cyber Readiness Institute, launched by senior leaders from the Commission on Enhancing National Cybersecurity. CRI focuses on providing free content and tools to improve resilience of small and medium enterprises to secure global value chains, aligning with DarkLight's mission for SMB cybersecurity.
Scale indicators1 record
Recent moves7 records
Expansion highlights6 records
DarkLight competitors and assessment
Company assessmentBroad incumbents
- Rapid7: Rapid7 offers InsightVM vulnerability management and exposure analytics and is a DarkLight integration partner. It is comparable as a broad incumbent selling vulnerability prioritization and remediation workflows into enterprise and MSSP segments.
- Tenable: Tenable is a public vulnerability management and exposure management platform (Nessus, Tenable One) that DarkLight integrates with and is a Tenable Assure Partner. It is comparable as the dominant vulnerability scanning incumbent that also competes for CTEM and risk prioritization spend.
- Qualys: Qualys provides the Qualys VMDR platform for vulnerability management, detection, and response, and is a DarkLight integration partner. It is comparable as an established enterprise scanner and risk management incumbent in the same VM/CTEM category.
Direct peers
- Brinqa: Brinqa is a cyber risk prioritization platform that fuses vulnerability, asset, and threat data into business-context risk views. It is a direct peer to Cyio, both targeting CTEM programs with knowledge-driven risk scoring and remediation orchestration.
- Vulcan Cyber: Vulcan Cyber provides vulnerability prioritization and remediation orchestration, integrating with Tenable, Rapid7, and Qualys and pushing actions into Jira and ServiceNow. It is a direct peer to DarkLight, both delivering risk prioritization plus ticketing workflow for enterprise and MSSP CTEM programs.
- Axonius: Axonius is a cybersecurity asset management and attack surface management platform that correlates data from scanners, cloud, and identity systems. It is comparable as an asset-centric exposure management platform that overlaps with Cyio's all-sensor fusion and CTEM use cases.
- JupiterOne: JupiterOne provides a cyber asset attack surface management and governance platform that unifies asset, vulnerability, and compliance data. It is a direct peer to Cyio in the asset-and-context-driven exposure management category.
- Noetic Cyber: Noetic Cyber delivers a continuous asset and exposure management platform with graph-based relationship mapping and automated remediation workflows. It is a direct peer to DarkLight, both offering continuous exposure management with ticketing integrations.
- Kenna Security (Cisco): Kenna Security (now part of Cisco) provides risk-based vulnerability management using exploit intelligence and asset context to prioritize remediation. It is a direct peer to Cyio, both applying threat intel and business context to vulnerability prioritization.
Emerging players
- XM Cyber: XM Cyber provides continuous exposure management and attack path simulation that prioritizes vulnerabilities by exploitability. It is an emerging player comparable to DarkLight in the CTEM and risk prioritization space, with a different focus on attack path analytics.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
DarkLight social profiles
Digital presenceDarkLight financial estimates
Financial estimateRevenue estimate
Valuation estimate
DarkLight leadership team
Management profileNumber of profiles
Profiles5 records
DarkLight funding detail
Funding detailFunding overview
Funding rounds3 records
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DarkLight M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DarkLight
What does DarkLight do?
DarkLight developed Cyio, an AI-powered cybersecurity platform engineered for Continuous Threat Exposure Management (CTEM). The platform uses an all-sensor fusion architecture to ingest signals from across an organization's security stack, applies continuous threat intelligence and a knowledge-based AI engine to prioritize exposures, and automates remediation workflows via ticketing and mail-handler integrations aligned to MITRE ATT&CK and NIST frameworks.
Is DarkLight a public or private company?
DarkLight is a private company. It is classified as corporate owned and is currently acquired.
When was DarkLight founded?
DarkLight was founded in 2014. It employs 1 to 10 people.
Where is DarkLight based?
DarkLight is headquartered in Redmond, United States, in the North America region.
How does DarkLight make money?
One revenue line is on record: cyio SaaS Subscription.
Who are DarkLight's main competitors?
Broad incumbents on record are Rapid7, Tenable and Qualys. Direct peers are Brinqa, Vulcan Cyber, Axonius, JupiterOne, Noetic Cyber and Kenna Security (Cisco). XM Cyber is listed as an emerging player.
Does DarkLight have an API?
No public API is recorded for DarkLight.
What industry is DarkLight in?
DarkLight's product category is Cybersecurity Risk Management. Its primary akta.pro industry code is HDADAHAC, Attack Surface Management (EASM/CAASM), with a secondary code of HDADAHAE, Continuous Controls Monitoring (CCM). Its NAICS code is 5415 and its SIC code is 7373.