Detectify
Detectify is a Stockholm-based application security platform providing External Attack Surface Management and Dynamic Application Security Testing, combining crowdsourced ethical hacker intelligence with proprietary AI-driven fuzzing engines to serve 2,100+ enterprise and government organizations globally.
- Company typePrivate
- Founded2013
- HeadquartersStockholm, Sweden
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Detectify does
Detectify AB is a Stockholm-based application security company that delivers an External Attack Surface Management (EASM) and Dynamic Application Security Testing (DAST) platform to organizations managing complex, internet-facing digital footprints. The platform unifies Surface Monitoring (asset discovery across domains, subdomains, IPs, and technologies), Application Scanning (stateful crawling and fuzzing of custom web apps), API Scanning (payload-based testing of REST and GraphQL endpoints), and Internal Scanning (behind-the-firewall vulnerability assessment). It is differentiated by Crowdsource, a community of 400+ ethical hackers who have submitted over 7,769 vulnerability modules and 300+ zero-day discoveries, and by a proprietary seed-based dynamic fuzzing engine that generates over 922 quintillion payload permutations for a single vulnerability type, supporting a claimed 99.7% vulnerability assessment accuracy rate.
Detectify operates a subscription-based SaaS model with tiered and custom enterprise pricing scaled to attack-surface scope, ranging from a €90/month API Scanning entry point to quote-based enterprise contracts with SSO/SAML, dedicated CSM, multi-team setup, and Bring Your Own Key add-ons. The go-to-market combines product-led growth (2-week free trial, self-serve onboarding), enterprise field sales, a formal partner/reseller program, and AWS Marketplace distribution. Customers include technology organizations, government agencies (UK Government), CPG/retail (ABC Fitness, Tradesolution), media/gaming, and large enterprises such as Auth0, Grammarly, Bühler Group, evroc, Kivra, Trustly, and Storytel, collectively representing 2,100+ organizations and 10,000+ users across approximately 104 countries. The company is majority-owned by Insight Partners following its October 2024 majority-stake acquisition, which followed earlier funding rounds totaling approximately $42M+ since 2015, and is actively extending its platform into AI-orchestrated security workflows through Alfred AI and the MCP Server integration.
Detectify firmographics
Firmographics- Name
- Detectify
- Legal name
- Detectify AB
- Website
- https://detectify.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Detectify is a Stockholm-based application security platform providing External Attack Surface Management and Dynamic Application Security Testing, combining crowdsourced ethical hacker intelligence with proprietary AI-driven fuzzing engines to serve 2,100+ enterprise and government organizations globally.
- Ownership category
- akta.pro rank
Detectify industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Testing Laboratories and Services (54138)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Detectify is headquartered
LocationHeadquarters
- HQ city
- Stockholm
- HQ country
- Sweden
- HQ region
- Europe
Offices2 records
Markets served
Detectify business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Application Security Testing Platform Subscription: Detectify operates on a subscription-based SaaS model, charging organizations for access to its External Attack Surface Management platform. Pricing is based on attack surface scope (number of domains, subdomains, and assets), with tiered plans ranging from entry-level to enterprise. Enterprise pricing includes custom plans based on organizational needs and add-on features such as SSO, dedicated CSM, and bespoke integrations. API Scanning is listed at a starting price of €90/month.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Entry-level platform access with Surface Monitoring and core scanning capabilities |
| Subscription | Monthly | API Scanning standalone starting price |
| Subscription | Annual | Enterprise-tier custom pricing |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
Detectify product offering
Product offeringCore offering
Detectify provides a cloud-based External Attack Surface Management (EASM) and Dynamic Application Security Testing (DAST) platform that continuously discovers, classifies, and scans internet-facing assets including domains, IPs, web applications, and APIs. The platform combines crowdsourced ethical hacker research (400+ researchers contributing 7,769+ vulnerability modules and 300+ zero-days) with proprietary AI-driven fuzzing engines to deliver payload-based vulnerability testing with claimed 99.7% accuracy. Core offerings include Surface Monitoring, Application Scanning, API Scanning, and Internal Scanning, sold via annual SaaS subscriptions with enterprise add-ons.
Product overview
Detectify is a Stockholm-based application security platform offering a unified External Attack Surface Management (EASM) solution. The platform operates as a platform-plus-modules architecture built around a core Surface Monitoring engine that discovers and monitors all internet-facing assets. The portfolio includes three primary scanning products: Application Scanning (DAST for web apps), API Scanning (dynamic API security testing), and Internal Scanning (behind-the-firewall assessment). Supporting modules include Alfred AI (autonomous CVE testing), Asset Classification and Scan Recommendations (intelligent prioritization), Custom Policies (policy enforcement), and PCI ASV Scanning (compliance). The platform is distinguished by Crowdsource, a community of 400+ ethical hackers contributing vulnerability research, and the MCP Server integration enabling AI-orchestrated security workflows. All capabilities are tied together through a robust API enabling workflow automation.
Differentiator
Problem solved
Functional benefit
Brands
- Crowdsource: Community of ethical hackers that constantly discovers vulnerabilities across widely-used technologies
- Alfred AI
- MCP Server
Products and services
- Detectify EASM Platform Unified External Attack Surface Management (EASM) platform that combines asset discovery, vulnerability assessment, and continuous monitoring with payload-based testing for security teams managing internet-facing assets.
- Surface Monitoring External Attack Surface Management (EASM) product that continuously discovers and monitors all internet-facing assets — domains, subdomains, IPs, applications, and APIs — providing asset classification, technology fingerprinting, and customizable security policy enforcement.
- Application Scanning Dynamic Application Security Testing (DAST) solution that crawls, renders, and fuzzes custom-built web applications to find business-critical vulnerabilities, including authenticated and stateful testing of complex applications.
- API Scanning Dynamic API security testing solution that delivers payload-based, high-accuracy findings for REST and GraphQL APIs. Uses seed-based dynamic fuzzing with over 922 quintillion payload permutations to test for OWASP API Top 10 vulnerabilities including prompt injection and command injections.
- Internal Scanning High-velocity internal scanning solution that discovers and assesses vulnerabilities behind the firewall, featuring instant deployment and massive payload permutation for unmatched depth.
- IP Range Scanning Capability that enables organizations to continuously discover and monitor entire blocks of IP addresses for exposed infrastructure and hidden risks, bridging the gap between domain monitoring and IP infrastructure coverage.
- PCI ASV Scanning Payment Card Industry Approved Scanning Vendor (ASV) scanning for continuous attack surface compliance with PCI DSS requirements, delivered in partnership with Clone Systems.
- MCP Server Model Context Protocol integration layer built on Anthropic's MCP that embeds Detectify's security testing engines directly into AI-driven development workflows, enabling AI coding agents to autonomously find, validate, and remediate vulnerabilities.
- Alfred AI Autonomous AI engine that continuously scans global threat intelligence to automatically build and deploy payload-based tests for newly discovered CVEs, dramatically reducing time-to-market for vulnerability testing.
Quantifiable outcome
- 99.7% vulnerability assessment accuracy rate, reducing false positives and enabling security teams to focus on exploitable vulnerabilities.
- +6 more outcomes
Companies that use Detectify
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles4 records
Detectify technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability10 records
Feature12 records
Detectify partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- Clone SystemscoreDetectify partnered with Clone Systems to launch PCI ASV Scanning, a continuous attack surface compliance capability that enables organizations to meet PCI DSS requirements. This co-development partnership enables Detectify to offer Approved Scanning Vendor (ASV) scanning services as part of its platform, addressing a critical compliance need for customers in regulated industries.
- AWS MarketplacecoreDetectify's External Attack Surface Management solution is available on AWS Marketplace, enabling AWS customers worldwide to discover, purchase, and deploy Detectify through integrated AWS billing and procurement processes. This marketplace listing lowers barriers to entry for cloud-native enterprises and accelerates sales cycles through existing AWS relationships.
- AnthropiccoreDetectify's MCP Server is built on Anthropic's Model Context Protocol, integrating Detectify's security testing engines directly into AI-driven development workflows. This technical integration enables AI coding agents to autonomously find, validate, and remediate vulnerabilities within AI-powered coding environments, extending Detectify's reach into the emerging AI-native development tooling ecosystem.
- Partner Program (Resellers and Integrators)minorDetectify operates a formal partner program recruiting resellers, system integrators, and managed security service providers (MSSPs) to extend market reach. The program enables partners to resell or embed Detectify's EASM capabilities as part of their broader security service offerings to end customers.
Scale indicators12 records
Recent moves6 records
Expansion highlights6 records
Detectify competitors and assessment
Company assessmentDirect peers
- Censys: Censys is an attack surface management platform that, like Detectify, continuously discovers external assets, fingerprints technologies, and monitors exposures for enterprise security teams. Both sell EASM as a subscription SaaS to enterprise security buyers.
- PortSwigger (Burp Suite): PortSwigger's Burp Suite is the leading DAST tool for web application security testing, directly overlapping with Detectify's Application Scanning. Both target application security teams with dynamic scanning of web apps and APIs.
- CyCognito: CyCognito is an EASM platform that maps external attack surfaces and prioritizes risk for enterprise security teams, directly competing with Detectify's Surface Monitoring. Both target similar enterprise and government buyers.
- UpGuard: UpGuard is an attack surface management and vendor risk management platform competing directly with Detectify's Surface Monitoring for EASM budget. Both serve enterprise security and risk teams with subscription-based SaaS.
Broad incumbents
- Rapid7: Rapid7 provides vulnerability management, application security (InsightAppSec/DAST), and managed detection services that overlap with Detectify's EASM and DAST offerings. Both serve mid-market and enterprise buyers through subscription SaaS.
- Tenable: Tenable is a major vulnerability management and exposure management platform (Nessus, Tenable One) that directly overlaps with Detectify's EASM and vulnerability scanning capabilities. It serves a similarly broad enterprise and government customer base.
- Qualys: Qualys offers a cloud-based security and compliance platform with VM, EASM, and web application scanning modules that compete head-on with Detectify's portfolio. Both target enterprise customers with subscription-based SaaS delivery.
Emerging players
- HackerOne: HackerOne operates the largest bug bounty and vulnerability disclosure platform, closely related to Detectify's Crowdsource ethical hacker community. Both leverage crowdsourced security researcher intelligence as a core product pillar.
- Intruder: Intruder is a vulnerability scanning platform with EASM and continuous monitoring features, overlapping with Detectify's Surface Monitoring and scanning products. It targets a similar customer profile but skews more toward SMB and mid-market.
- runZero: runZero provides asset discovery and exposure management with strong internal network visibility, overlapping with Detectify's Surface Monitoring and newly launched Internal Scanning. Both target enterprise security teams seeking continuous asset inventory.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Detectify social profiles
Digital presenceDetectify compliance and trust
Trust signalCompliance2 records
Detectify financial estimates
Financial estimateRevenue estimate
Valuation estimate
Detectify leadership team
Management profileNumber of profiles
Profiles9 records
Detectify funding detail
Funding detailFunding overview
Funding rounds5 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Detectify M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Detectify
What does Detectify do?
Detectify provides a cloud-based External Attack Surface Management (EASM) and Dynamic Application Security Testing (DAST) platform that continuously discovers, classifies, and scans internet-facing assets including domains, IPs, web applications, and APIs. The platform combines crowdsourced ethical hacker research (400+ researchers contributing 7,769+ vulnerability modules and 300+ zero-days) with proprietary AI-driven fuzzing engines to deliver payload-based vulnerability testing with claimed 99.7% accuracy. Core offerings include Surface Monitoring, Application Scanning, API Scanning, and Internal Scanning, sold via annual SaaS subscriptions with enterprise add-ons.
Is Detectify a public or private company?
Detectify is a private company. It is classified as private equity controlled and is currently operating.
When was Detectify founded?
Detectify was founded in 2013. It employs 11 to 50 people.
Where is Detectify based?
Detectify is headquartered in Stockholm, Sweden, in the Europe region.
How does Detectify make money?
One revenue line is on record: application Security Testing Platform Subscription.
Who are Detectify's main competitors?
Direct peers on record are Censys, PortSwigger (Burp Suite), CyCognito and UpGuard. Broad incumbents are Rapid7, Tenable and Qualys. Emerging players are HackerOne, Intruder and runZero.
Does Detectify have an API?
Yes. Detectify offers a robust API that enables customers to automate workflows, export vulnerability data, and integrate findings into existing systems. The API provides complete feature parity with the platform, allowing users to programmatically manage assets, scan profiles, vulnerabilities, and reports. The API is used by customers to feed high-fidelity scan data into internal systems and AI engines for automated triage and remediation workflows. Developer documentation is at developer.detectify.com.
What industry is Detectify in?
Detectify's product category is Application Security Testing. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 54138 and its SIC code is 7372.