Invicti Security
Invicti Security provides a unified, proof-based application security platform combining DAST, SAST, SCA, ASPM, and AI-driven prioritization for 3,600+ enterprise and government customers worldwide, including NASA, FAA, United Nations, KPMG, and Cisco.
- Company typePrivate
- Founded2017
- HeadquartersAustin, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Invicti Security does
Invicti Security is a privately held application security (AppSec) platform vendor headquartered in Austin, Texas, serving over 3,600 enterprise and government customers including NASA, the Federal Aviation Administration, the United Nations, OECD, KPMG, Deloitte, EY, Cisco, Verizon, Ericsson, ING Bank, Allianz, Pepsi, Kraft Heinz, and Channel 4. The company was formed in 2017 through the combination of DAST pioneers Netsparker (founded 2009) and Acunetix, and extended its capabilities with the 2023 acquisition of Kondukto for Application Security Posture Management (ASPM). Invicti primarily targets CTOs, CISOs, engineering leaders, and DevSecOps teams operating in government, financial services, healthcare, IT/telecom, and other regulated verticals with complex application portfolios.
The Invicti platform unifies DAST, SAST, SCA, container security, API security testing, secrets detection, infrastructure-as-code scanning, attack surface management, and ASPM within a single cloud-hosted SaaS solution, most recently consolidated under the Invicti AppSec Core product launched in June 2026. The technical foundation centers on proof-based scanning that validates exploitable vulnerabilities with claimed 99.98% accuracy, runtime intelligence that correlates findings across scan types for risk-based prioritization, AI-powered remediation guidance, agentic prioritization that pre-scores application risk, and DAST-to-SAST correlation linking static code locations to runtime exploitability. Distribution relies on direct enterprise field sales and inside sales, supplemented by an MSSP program, AWS and Microsoft Azure marketplace listings, and over 110 technology integrations spanning CI/CD, ITSM, identity, SIEM, WAF, and cloud infrastructure categories.
Invicti operates a SaaS subscription model with annual contracts and quote-based enterprise pricing, with entry-level deployments starting around $7,000 per year and pricing scaling on number of targets, deployment model, and feature add-ons. The company maintains a global footprint across North America and EMEA (USA, UK, Germany, France, Netherlands), publishes compliance reporting aligned to ISO 27001 and SOC 2, and received the 2026 Miercom Certified Secure certification as the only tested DAST vendor to detect all 31 critical vulnerabilities across 11 benchmark targets. Recent strategic activity includes the DAST-to-SAST correlation launch (April 2026), the Invicti AppSec Core platform launch (June 2026), and the appointment of Katie Bullard to the board (May 2026) to support go-to-market scaling.
Invicti Security firmographics
Firmographics- Name
- Invicti Security
- Legal name
- Invicti Security Corp
- Website
- https://invicti.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Invicti Security provides a unified, proof-based application security platform combining DAST, SAST, SCA, ASPM, and AI-driven prioritization for 3,600+ enterprise and government customers worldwide, including NASA, FAA, United Nations, KPMG, and Cisco.
- Ownership category
- akta.pro rank
Invicti Security industry classification
Industry- Product category
- Application Security
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Attack Surface Management (EASM/CAASM) (HDADAHAC), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where Invicti Security is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Invicti Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription (Invicti Platform): Cloud-hosted SaaS platform with subscription-based pricing. Entry-level costs start at approximately $7,000 per year, shaped by number of targets, deployment model, and feature add-ons. Available as cloud-hosted solution with simplified onboarding and CI/CD integrations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise tier with full platform access |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels9 records
Invicti Security product offering
Product offeringCore offering
Invicti Security provides a unified application security platform that combines proof-based DAST, SAST, SCA, container security, secrets detection, API security testing, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate findings from every testing tool, prioritizes vulnerabilities by real risk, and delivers AI-powered remediation guidance to enterprise development and security teams.
Product overview
Invicti Security offers a unified AppSec platform (Invicti Platform) that combines multiple security testing capabilities: SAST, SCA (Open Source), DAST, container security, secrets detection, IaC scanning, API security testing, attack surface management, cloud app security, AI-powered scanning, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate results from every testing tool, confirms what's real, and drives faster fixes through AI, automation, and ASPM. Key products include Invicti AppSec Core (all-in-one platform), DAST (proof-based dynamic scanning with 99.98% accuracy), SAST (static code analysis), SCA (software composition analysis with SBOM generation), Container Security, API Security Testing, Agentic Penetration Testing, and ASPM (formerly Kondukto). The platform is designed to eliminate false positives and prioritize vulnerabilities by real risk.
Differentiator
Problem solved
Functional benefit
Brands
- Invicti AppSec Core: An all-in-one application security platform that combines proof-based DAST scanning with SAST, SCA, container security, secrets detection, and automated SBOM generation to eliminate duplicate findings and correlate vulnerabilities across environments.
Products and services
- Invicti AppSec Core All-in-one application security platform combining proof-based DAST scanning with SAST, SCA, container security, secrets detection, IaC scanning, and automated SBOM generation to eliminate duplicate findings and correlate vulnerabilities across environments.
- DAST Industry-leading Dynamic Application Security Testing engine delivering proof-based scanning with 99.98% accuracy, fully integrated into the SDLC, scaling across teams and application portfolios.
- SAST Static Application Security Testing that connects static analysis to verified runtime vulnerabilities, code ownership, and remediation guidance.
- SCA (Software Composition Analysis) Discovers vulnerable open-source dependencies, generates SBOMs, identifies container risks, and prioritizes remediation with runtime intelligence.
- Container Security Secures containerized applications with image scanning, software supply chain analysis, and runtime-informed prioritization.
- API Security Testing Scans REST, SOAP, and GraphQL APIs with the same depth and accuracy as web apps, discovering shadow APIs and reconstructing API specs automatically.
- Application Security Posture Management (ASPM) Runtime-verified ASPM that unifies, validates, prioritizes, and acts on application security risk, providing a single source of truth with policy enforcement and audit-ready reporting.
- Agentic Penetration Testing Automates real-world attack techniques for autonomous penetration testing that simulates attacker behavior without human intervention.
Quantifiable outcome
- 99.98% confirmation accuracy for exploitable vulnerabilities
- +5 more outcomes
Companies that use Invicti Security
Customer profileNamed customers20 records
Segments7 records
Ideal customer profiles3 records
Invicti Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration62 records
AI capability5 records
Feature9 records
Invicti Security partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core.
- AWScoreAmazon Web Services integration and marketplace listing for WAF monitoring, security scanning, and AWS Marketplace procurement.
- GitHub ActionscoreGitHub Actions integration for automating tasks within the software development lifecycle and CI/CD pipelines.
- Azure PipelinescoreAzure DevOps integration providing CI/CD pipeline features for DevOps workflow automation.
- JenkinscoreJenkins automation server integration with plugins for build automation and security testing integration.
- JIRAcoreJIRA issue tracking integration for agile project management and bug tracking with security vulnerability tickets.
- ServiceNowcoreServiceNow integrations for Application Vulnerability Response and Vulnerability Response, helping track, prioritize, and resolve vulnerabilities.
- OktacoreOkta identity and access management integration for SSO and SCIM-based user provisioning.
- Azure Active DirectorycoreAzure AD integration for identity management, secure SSO, and multi-factor authentication.
- GitLab CI/CDcoreGitLab integration for source control repositories and CI/CD pipeline security automation.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
Invicti Security competitors and assessment
Company assessmentDirect peers
- Mend (formerly WhiteSource): Application security platform specializing in SCA, SAST, and supply chain security with enterprise GTM. Direct overlap with Invicti's SCA and SAST modules and listed as a partner/integration reference in Invicti's ecosystem.
- Contrast Security: Runtime application security platform combining IAST, RASP, SAST, and SCA. Competes head-to-head with Invicti on the runtime/IAST and proof-based vulnerability validation thesis, targeting similar enterprise AppSec buyers.
- Veracode: Established AppSec testing vendor offering SAST, DAST, SCA, and software composition analysis. Direct competitor targeting the same enterprise/CISO buyer, with comparable focus on accuracy and remediation workflows.
- Snyk: Developer-first security platform offering SAST, SCA, container, and IaC security with PLG and enterprise GTM motions. Direct competitor in the same AppSec testing category, overlapping heavily with Invicti's SAST, SCA, and container modules.
- Checkmarx: Enterprise AppSec platform providing SAST, SCA, DAST, and ASPM (Checkmarx One). Direct competitor across the unified AppSec platform thesis, particularly in large enterprise and regulated verticals where Invicti also wins.
Broad incumbents
- Qualys: Cloud-based security and compliance platform with web application scanning (Qualys WAS) within a broader vulnerability management and compliance suite. Adjacent competitor in enterprise web app and API security assessments.
- Tenable (Nessus / Tenable.io): Large vulnerability management and exposure platform offering web app scanning alongside Nessus-based infrastructure scanning. Competes in enterprise vulnerability discovery with broader exposure management positioning.
- GitLab: DevSecOps platform with built-in SAST, DAST, SCA, container, and IaC scanning bundled into a broader source-control and CI/CD platform. Competes as a broad incumbent where AppSec is one feature among many rather than a specialized focus.
- Rapid7 (InsightAppSec / InsightVM): Broad security vendor offering DAST (InsightAppSec) and vulnerability management (InsightVM) within a wider portfolio including SIEM and detection. Competes with Invicti in AppSec while also offering adjacent security operations products.
- GitHub Advanced Security: Native SAST, SCA, and secret scanning tightly integrated into the GitHub developer ecosystem. Represents the mega-platform threat to standalone AppSec vendors by bundling security into the developer's primary toolchain.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Invicti Security social profiles
Digital presenceInvicti Security compliance and trust
Trust signalCompliance2 records
Invicti Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Invicti Security leadership team
Management profileNumber of profiles
Profiles7 records
Invicti Security subsidiaries and ownership
Company hierarchySubsidiaries1 record
Invicti Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Invicti Security M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Invicti Security
What does Invicti Security do?
Invicti Security provides a unified application security platform that combines proof-based DAST, SAST, SCA, container security, secrets detection, API security testing, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate findings from every testing tool, prioritizes vulnerabilities by real risk, and delivers AI-powered remediation guidance to enterprise development and security teams.
Is Invicti Security a public or private company?
Invicti Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Invicti Security founded?
Invicti Security was founded in 2017. It employs 251 to 500 people.
Where is Invicti Security based?
Invicti Security is headquartered in Austin, United States, in the North America region.
How does Invicti Security make money?
One revenue line is on record: saaS Subscription (Invicti Platform).
Who are Invicti Security's main competitors?
Direct peers on record are Mend (formerly WhiteSource), Contrast Security, Veracode, Snyk and Checkmarx. Broad incumbents are Qualys, Tenable (Nessus / Tenable.io), GitLab, Rapid7 (InsightAppSec / InsightVM) and GitHub Advanced Security.
Does Invicti Security have an API?
Yes. Invicti Team and Enterprise has a full-featured REST API which allows for easy integration. The platform supports webhooks for custom integrations with issue tracking systems that do not have their own built-in integration. Developer documentation is at docs.invicti.com.
What industry is Invicti Security in?
Invicti Security's product category is Application Security. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDADAHAC, Attack Surface Management (EASM/CAASM). Its NAICS code is 541519 and its SIC code is 7372.