Cyber Trust Alliance
Cyber Trust Alliance provides HIPAA compliance software (CEBA) and cybersecurity risk assessment services — including vulnerability scanning, phishing simulation, and penetration testing — to U.S. healthcare organizations, primarily hospitals, physician practices, and healthcare technology firms.
- Company typePrivate
- Founded2013
- HeadquartersAustin, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Cyber Trust Alliance does
Cyber Trust Alliance is a privately-held Austin, Texas-based company that sells HIPAA compliance software and cybersecurity risk assessment services to U.S. healthcare organizations. Its core product is CEBA (Compliance Made Easy), a SaaS platform aligned to the HHS Office for Civil Rights protocol and the NIST cybersecurity framework that handles HIPAA Security, Privacy, and Breach Notification Rule assessments, document management, policy template workflows, and progress tracking. The platform is augmented by a suite of professional services including security risk assessments, external and internal network vulnerability scanning, phishing simulation, and penetration testing delivered through a proprietary Virtual Telassessment methodology that enables remote assessments without on-site presence.
The company generates revenue through annual subscription contracts for the CEBA platform bundled with quarterly phishing and vulnerability assessments, alongside one-time and recurring professional services engagements. Pricing is quote-based rather than publicly disclosed, with the company positioning CEBA as a cost-effective alternative to traditional consulting firms. Go-to-market combines direct enterprise field sales (website demo requests, phone, email with a 24-hour response commitment) with channel partnerships; a January 2026 agreement with HANYS Marketplace extends reach into New York member hospitals.
The company is founder-led by Randy Steinle (CEO/Co-Founder) and Kirk Lukan (Partner/Lead Developer), operates with 11-50 employees, and has raised approximately $798,000 across two 2022 funding events including a Newchip Accelerator participation. Named customers include Trinity Health (24 hospitals and clinics), US Eye (multi-location physician practices), TAP Innovations, and a long tail of independent medical practices, indicating a vertically specialized SMB-to-mid-market healthcare customer base rather than a broad enterprise book.
Cyber Trust Alliance firmographics
Firmographics- Name
- Cyber Trust Alliance
- Legal name
- Cyber Trust Alliance, Inc.
- Website
- https://cybertrustalliance.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Cyber Trust Alliance provides HIPAA compliance software (CEBA) and cybersecurity risk assessment services — including vulnerability scanning, phishing simulation, and penetration testing — to U.S. healthcare organizations, primarily hospitals, physician practices, and healthcare technology firms.
- Ownership category
- akta.pro rank
Cyber Trust Alliance industry classification
Industry- Product category
- Healthcare Compliance Software
- NAICS
- Software Publishers (513210)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Awareness, Training & Compliance Attestation (HDADAIAJ), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
Keywords
Where Cyber Trust Alliance is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Cyber Trust Alliance business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- CEBA Platform Subscription: SaaS platform subscription for compliance management with annual renewals. Includes quarterly phishing and vulnerability assessments, expert guidance, and compliance tracking.
- Professional Risk Assessment Services: One-time and recurring professional services including security risk assessments (HIPAA, SOC II, NIST), vulnerability assessments, phishing assessments, and penetration testing.
- Policy Management and Templates: Policy template access and management capabilities integrated within CEBA platform.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise and SMB pricing through demo/sales |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels7 records
Cyber Trust Alliance product offering
Product offeringCore offering
Cyber Trust Alliance sells the CEBA (Compliance Made Easy) software platform for managing HIPAA Security, Privacy, and Breach Notification Rule compliance, complemented by a suite of professional cybersecurity assessment services including security risk assessments, vulnerability assessments, phishing assessments, and penetration testing. The platform is built on the OCR protocol and NIST cybersecurity framework and uses a proprietary Virtual Telassessment methodology to deliver remote assessments.
Product overview
Cyber Trust Alliance offers a single unified product platform called CEBA (Compliance Made Easy), which serves as the core compliance management solution. CEBA is complemented by a suite of assessment services including Security Risk Assessments, Vulnerability Assessments, Phishing Assessments, and Penetration Testing. CEBA includes built-in Policy Management functionality and Ongoing Compliance Support as integral features. The platform is designed to help organizations achieve and maintain HIPAA compliance using the OCR protocol and NIST cybersecurity framework.
Differentiator
Problem solved
Functional benefit
Brands
- CEBA: A user-friendly, comprehensive compliance assessment, documentation, and risk management tool designed to help organizations achieve HIPAA Security, Privacy and Breach Notification Rule compliance. CEBA is based on the OCR protocol and NIST cybersecurity framework.
Products and services
- CEBA Compliance Solution
Quantifiable outcome
- More than 90% of healthcare organizations have suffered a security breach in the past 3 years - highlighting the critical need for compliance services
- +3 more outcomes
Companies that use Cyber Trust Alliance
Customer profileNamed customers4 records
Segments2 records
Ideal customer profiles4 records
Cyber Trust Alliance technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Cyber Trust Alliance partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- HANYS MarketplacecoreCyber Trust Alliance has partnered with HANYS Marketplace to provide cybersecurity risk assessment services to member hospitals across New York state. Through this partnership, HANYS member organizations gain access to Cyber Trust Alliance's risk assessment capabilities, enabling healthcare leaders to identify vulnerabilities, prioritize remediation efforts, and strengthen alignment with regulatory and industry frameworks. The initiative aims to help hospitals protect patient data, ensure operational resilience, and maintain continuity of care amid rising cyber threats targeting the healthcare sector.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Cyber Trust Alliance competitors and assessment
Company assessmentDirect peers
- Compliancy Group: Compliancy Group provides a HIPAA compliance platform (The Guard) targeted at medical practices and healthcare SMBs with compliance tracking, policy templates, and training. It competes head-to-head with CEBA on the SMB and mid-market medical practice buyer.
- Clearwater Compliance: Clearwater is a healthcare-focused cybersecurity and compliance firm offering HIPAA risk analysis, OCR-Quality assessments, and managed compliance services. It targets the same enterprise healthcare buyer as CTA with a more consulting-led model.
- Meditology Services: Meditology is a healthcare-dedicated cybersecurity and risk services firm delivering HIPAA risk assessments, penetration testing, and advisory to providers and payers — overlapping directly with CTA's professional services catalog.
- HIPAA One: HIPAA One offers a HIPAA compliance software platform with risk assessments and policy management for healthcare organizations. It is a direct competitor to CTA's CEBA in the same buyer segment (covered entities and business associates) with overlapping risk-assessment workflow.
- A-LIGN: A-LIGN is a cybersecurity and compliance assessment firm performing HIPAA, SOC 2, HITRUST, and penetration testing engagements. It overlaps with CTA's risk-assessment and pen-testing services, though A-LIGN also serves broader industries and frameworks.
- Accountable HQ: Accountable HQ is a HIPAA compliance management platform focused on small and mid-sized medical practices. Its bundled approach to HIPAA risk assessment, policy management, and training overlaps with CEBA's core feature set in the same end market.
- CynergisTek: CynergisTek (now part of Optiv-adjacent healthcare cybersecurity practice) provides HIPAA security assessments, managed security services, and advisory to hospitals and health systems. It competes with CTA for enterprise healthcare compliance mandates.
- HIPAA Secure Now: HIPAA Secure Now delivers HIPAA security risk assessments, employee training, and ongoing compliance support to healthcare practices. It is a direct peer to CTA on risk-assessment methodology and the recurring-compliance-service model.
Broad incumbents
- Coalfire: Coalfire is an established cybersecurity advisory firm offering HIPAA, HITRUST, and penetration testing services across multiple industries. It competes with CTA on enterprise healthcare assessments but operates at much larger scale and broader framework coverage.
- Optiv: Optiv is a large cybersecurity solutions integrator delivering managed security, risk advisory, and compliance services including HIPAA programs to enterprise clients. It competes with CTA on enterprise healthcare accounts as part of a much broader portfolio.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Cyber Trust Alliance social profiles
Digital presenceCyber Trust Alliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Trust Alliance leadership team
Management profileNumber of profiles
Profiles14 records
Cyber Trust Alliance funding detail
Funding detailFunding overview
Funding rounds2 records
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Trust Alliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Trust Alliance
What does Cyber Trust Alliance do?
Cyber Trust Alliance sells the CEBA (Compliance Made Easy) software platform for managing HIPAA Security, Privacy, and Breach Notification Rule compliance, complemented by a suite of professional cybersecurity assessment services including security risk assessments, vulnerability assessments, phishing assessments, and penetration testing. The platform is built on the OCR protocol and NIST cybersecurity framework and uses a proprietary Virtual Telassessment methodology to deliver remote assessments.
Is Cyber Trust Alliance a public or private company?
Cyber Trust Alliance is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cyber Trust Alliance founded?
Cyber Trust Alliance was founded in 2013. It employs 11 to 50 people.
Where is Cyber Trust Alliance based?
Cyber Trust Alliance is headquartered in Austin, United States, in the North America region.
How does Cyber Trust Alliance make money?
Three revenue lines are on record. CEBA Platform Subscription is the primary driver. The others are professional Risk Assessment Services and policy Management and Templates.
Who are Cyber Trust Alliance's main competitors?
Direct peers on record are Compliancy Group, Clearwater Compliance, Meditology Services, HIPAA One, A-LIGN, Accountable HQ, CynergisTek and HIPAA Secure Now. Broad incumbents are Coalfire and Optiv.
Does Cyber Trust Alliance have an API?
No public API is recorded for Cyber Trust Alliance.
What industry is Cyber Trust Alliance in?
Cyber Trust Alliance's product category is Healthcare Compliance Software. Its primary akta.pro industry code is BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 513210 and its SIC code is 7371.