Developer docs
API playgroundTry for free, no card

Search company profiles

Invicti Security

Full company profile

uuid0004xk5

Namestring
Invicti Security
Legal namestring
Invicti Security Corp
Websiteurl
invicti.com
Company typeenum
Private
Founded yearint
2017
Descriptiontext

Invicti Security is a privately held application security (AppSec) platform vendor headquartered in Austin, Texas, serving over 3,600 enterprise and government customers including NASA, the Federal Aviation Administration, the United Nations, OECD, KPMG, Deloitte, EY, Cisco, Verizon, Ericsson, ING Bank, Allianz, Pepsi, Kraft Heinz, and Channel 4. The company was formed in 2017 through the combination of DAST pioneers Netsparker (founded 2009) and Acunetix, and extended its capabilities with the 2023 acquisition of Kondukto for Application Security Posture Management (ASPM). Invicti primarily targets CTOs, CISOs, engineering leaders, and DevSecOps teams operating in government, financial services, healthcare, IT/telecom, and other regulated verticals with complex application portfolios.

The Invicti platform unifies DAST, SAST, SCA, container security, API security testing, secrets detection, infrastructure-as-code scanning, attack surface management, and ASPM within a single cloud-hosted SaaS solution, most recently consolidated under the Invicti AppSec Core product launched in June 2026. The technical foundation centers on proof-based scanning that validates exploitable vulnerabilities with claimed 99.98% accuracy, runtime intelligence that correlates findings across scan types for risk-based prioritization, AI-powered remediation guidance, agentic prioritization that pre-scores application risk, and DAST-to-SAST correlation linking static code locations to runtime exploitability. Distribution relies on direct enterprise field sales and inside sales, supplemented by an MSSP program, AWS and Microsoft Azure marketplace listings, and over 110 technology integrations spanning CI/CD, ITSM, identity, SIEM, WAF, and cloud infrastructure categories.

Invicti operates a SaaS subscription model with annual contracts and quote-based enterprise pricing, with entry-level deployments starting around $7,000 per year and pricing scaling on number of targets, deployment model, and feature add-ons. The company maintains a global footprint across North America and EMEA (USA, UK, Germany, France, Netherlands), publishes compliance reporting aligned to ISO 27001 and SOC 2, and received the 2026 Miercom Certified Secure certification as the only tested DAST vendor to detect all 31 critical vulnerabilities across 11 benchmark targets. Recent strategic activity includes the DAST-to-SAST correlation launch (April 2026), the Invicti AppSec Core platform launch (June 2026), and the appointment of Katie Bullard to the board (May 2026) to support go-to-market scaling.

Short descriptiontext

Invicti Security provides a unified, proof-based application security platform combining DAST, SAST, SCA, ASPM, and AI-driven prioritization for 3,600+ enterprise and government customers worldwide, including NASA, FAA, United Nations, KPMG, and Cisco.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
251–500
akta.pro rankint
HeadquartersAustin, United States
HQ citystring
Austin
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
application security testing, web application security, API security testing, software composition analysis, vulnerability management platform
Industry3 codes
1Application Security Testing (SAST/DAST/IAST/SCA)
CodeHDADACACPrimaryYes
2Attack Surface Management (EASM/CAASM)
CodeHDADAHACPrimaryNo
3Vulnerability Management & Penetration Testing Services
CodeBPAEADADPrimaryNo
NAICS code2 codes
  • Other Computer Related Services541519
  • Computer Systems Design and Related Services54151
SIC code2 codes
  • Services-Prepackaged Software7372
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Application Security
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1SaaS Subscription (Invicti Platform)
TypeSubscription Recurring
Description

Cloud-hosted SaaS platform with subscription-based pricing. Entry-level costs start at approximately $7,000 per year, shaped by number of targets, deployment model, and feature add-ons. Available as cloud-hosted solution with simplified onboarding and CI/CD integrations.

aijourn.com
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Pricing details1 tier
1Enterprise tier with full platform access
ModelSubscriptionBilling cadenceAnnual
Notes

Entry-level costs start at approximately $7,000 per year. Pricing shaped by number of targets, deployment model, and feature add-ons. Cloud-hosted SaaS deployment.

beaglesecurity.com
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 record
1Invicti AppSec Core
Description

An all-in-one application security platform that combines proof-based DAST scanning with SAST, SCA, container security, secrets detection, and automated SBOM generation to eliminate duplicate findings and correlate vulnerabilities across environments.

aijourn.com
Core offering1 text field

Invicti Security provides a unified application security platform that combines proof-based DAST, SAST, SCA, container security, secrets detection, API security testing, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate findings from every testing tool, prioritizes vulnerabilities by real risk, and delivers AI-powered remediation guidance to enterprise development and security teams.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 6 values shown
  • 99.98% confirmation accuracy for exploitable vulnerabilities
+5 more records
Product overview1 text field

Invicti Security offers a unified AppSec platform (Invicti Platform) that combines multiple security testing capabilities: SAST, SCA (Open Source), DAST, container security, secrets detection, IaC scanning, API security testing, attack surface management, cloud app security, AI-powered scanning, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate results from every testing tool, confirms what's real, and drives faster fixes through AI, automation, and ASPM. Key products include Invicti AppSec Core (all-in-one platform), DAST (proof-based dynamic scanning with 99.98% accuracy), SAST (static code analysis), SCA (software composition analysis with SBOM generation), Container Security, API Security Testing, Agentic Penetration Testing, and ASPM (formerly Kondukto). The platform is designed to eliminate false positives and prioritize vulnerabilities by real risk.

Product and service8 records
1Invicti AppSec Core
CategoryApplication Security Platform
Description

All-in-one application security platform combining proof-based DAST scanning with SAST, SCA, container security, secrets detection, IaC scanning, and automated SBOM generation to eliminate duplicate findings and correlate vulnerabilities across environments.

2DAST
CategoryApplication Security Testing
Description

Industry-leading Dynamic Application Security Testing engine delivering proof-based scanning with 99.98% accuracy, fully integrated into the SDLC, scaling across teams and application portfolios.

3SAST
CategoryApplication Security Testing
Description

Static Application Security Testing that connects static analysis to verified runtime vulnerabilities, code ownership, and remediation guidance.

4SCA (Software Composition Analysis)
CategorySoftware Composition Analysis
Description

Discovers vulnerable open-source dependencies, generates SBOMs, identifies container risks, and prioritizes remediation with runtime intelligence.

5Container Security
CategoryContainer Security
Description

Secures containerized applications with image scanning, software supply chain analysis, and runtime-informed prioritization.

6API Security Testing
CategoryAPI Security
Description

Scans REST, SOAP, and GraphQL APIs with the same depth and accuracy as web apps, discovering shadow APIs and reconstructing API specs automatically.

7Application Security Posture Management (ASPM)
CategoryApplication Security Posture Management
Description

Runtime-verified ASPM that unifies, validates, prioritizes, and acts on application security risk, providing a single source of truth with policy enforcement and audit-ready reporting.

8Agentic Penetration Testing
CategoryPenetration Testing
Description

Automates real-world attack techniques for autonomous penetration testing that simulates attacker behavior without human intervention.

Scale indicator7 records

Each record includes

Type, Value, Description, Source

Partnership9 partners
1AWS
Strategic tierCoreTypeTechnology or Integration
Description

Amazon Web Services integration and marketplace listing for WAF monitoring, security scanning, and AWS Marketplace procurement.

invicti.com
Strategic tierCoreTypeTechnology or Integration
Description

GitHub Actions integration for automating tasks within the software development lifecycle and CI/CD pipelines.

3Azure Pipelines
Strategic tierCoreTypeTechnology or Integration
Description

Azure DevOps integration providing CI/CD pipeline features for DevOps workflow automation.

invicti.com
Strategic tierCoreTypeTechnology or Integration
Description

Jenkins automation server integration with plugins for build automation and security testing integration.

Strategic tierCoreTypeTechnology or Integration
Description

JIRA issue tracking integration for agile project management and bug tracking with security vulnerability tickets.

Strategic tierCoreTypeTechnology or Integration
Description

ServiceNow integrations for Application Vulnerability Response and Vulnerability Response, helping track, prioritize, and resolve vulnerabilities.

Strategic tierCoreTypeTechnology or Integration
Description

Okta identity and access management integration for SSO and SCIM-based user provisioning.

8Azure Active Directory
Strategic tierCoreTypeTechnology or Integration
Description

Azure AD integration for identity management, secure SSO, and multi-factor authentication.

invicti.com
Strategic tierCoreTypeTechnology or Integration
Description

GitLab integration for source control repositories and CI/CD pipeline security automation.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Application security platform specializing in SCA, SAST, and supply chain security with enterprise GTM. Direct overlap with Invicti's SCA and SAST modules and listed as a partner/integration reference in Invicti's ecosystem.

TypeBroad incumbent
Description

Cloud-based security and compliance platform with web application scanning (Qualys WAS) within a broader vulnerability management and compliance suite. Adjacent competitor in enterprise web app and API security assessments.

TypeDirect peer
Description

Runtime application security platform combining IAST, RASP, SAST, and SCA. Competes head-to-head with Invicti on the runtime/IAST and proof-based vulnerability validation thesis, targeting similar enterprise AppSec buyers.

TypeDirect peer
Description

Established AppSec testing vendor offering SAST, DAST, SCA, and software composition analysis. Direct competitor targeting the same enterprise/CISO buyer, with comparable focus on accuracy and remediation workflows.

TypeBroad incumbent
Description

Large vulnerability management and exposure platform offering web app scanning alongside Nessus-based infrastructure scanning. Competes in enterprise vulnerability discovery with broader exposure management positioning.

TypeBroad incumbent
Description

DevSecOps platform with built-in SAST, DAST, SCA, container, and IaC scanning bundled into a broader source-control and CI/CD platform. Competes as a broad incumbent where AppSec is one feature among many rather than a specialized focus.

TypeDirect peer
Description

Developer-first security platform offering SAST, SCA, container, and IaC security with PLG and enterprise GTM motions. Direct competitor in the same AppSec testing category, overlapping heavily with Invicti's SAST, SCA, and container modules.

TypeDirect peer
Description

Enterprise AppSec platform providing SAST, SCA, DAST, and ASPM (Checkmarx One). Direct competitor across the unified AppSec platform thesis, particularly in large enterprise and regulated verticals where Invicti also wins.

TypeBroad incumbent
Description

Broad security vendor offering DAST (InsightAppSec) and vulnerability management (InsightVM) within a wider portfolio including SIEM and detection. Competes with Invicti in AppSec while also offering adjacent security operations products.

TypeBroad incumbent
Description

Native SAST, SCA, and secret scanning tightly integrated into the GitHub developer ecosystem. Represents the mega-platform threat to standalone AppSec vendors by bundling security into the developer's primary toolchain.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers20 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment7 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration62 records

Each record includes

Title, Type, Description, Source

AI capability5 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature9 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles7 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries1 record

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance2 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A2 records

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Invicti Security

Application Securityinvicti.com

Invicti Security provides a unified, proof-based application security platform combining DAST, SAST, SCA, ASPM, and AI-driven prioritization for 3,600+ enterprise and government customers worldwide, including NASA, FAA, United Nations, KPMG, and Cisco.

What Invicti Security does

Invicti Security is a privately held application security (AppSec) platform vendor headquartered in Austin, Texas, serving over 3,600 enterprise and government customers including NASA, the Federal Aviation Administration, the United Nations, OECD, KPMG, Deloitte, EY, Cisco, Verizon, Ericsson, ING Bank, Allianz, Pepsi, Kraft Heinz, and Channel 4. The company was formed in 2017 through the combination of DAST pioneers Netsparker (founded 2009) and Acunetix, and extended its capabilities with the 2023 acquisition of Kondukto for Application Security Posture Management (ASPM). Invicti primarily targets CTOs, CISOs, engineering leaders, and DevSecOps teams operating in government, financial services, healthcare, IT/telecom, and other regulated verticals with complex application portfolios.

The Invicti platform unifies DAST, SAST, SCA, container security, API security testing, secrets detection, infrastructure-as-code scanning, attack surface management, and ASPM within a single cloud-hosted SaaS solution, most recently consolidated under the Invicti AppSec Core product launched in June 2026. The technical foundation centers on proof-based scanning that validates exploitable vulnerabilities with claimed 99.98% accuracy, runtime intelligence that correlates findings across scan types for risk-based prioritization, AI-powered remediation guidance, agentic prioritization that pre-scores application risk, and DAST-to-SAST correlation linking static code locations to runtime exploitability. Distribution relies on direct enterprise field sales and inside sales, supplemented by an MSSP program, AWS and Microsoft Azure marketplace listings, and over 110 technology integrations spanning CI/CD, ITSM, identity, SIEM, WAF, and cloud infrastructure categories.

Invicti operates a SaaS subscription model with annual contracts and quote-based enterprise pricing, with entry-level deployments starting around $7,000 per year and pricing scaling on number of targets, deployment model, and feature add-ons. The company maintains a global footprint across North America and EMEA (USA, UK, Germany, France, Netherlands), publishes compliance reporting aligned to ISO 27001 and SOC 2, and received the 2026 Miercom Certified Secure certification as the only tested DAST vendor to detect all 31 critical vulnerabilities across 11 benchmark targets. Recent strategic activity includes the DAST-to-SAST correlation launch (April 2026), the Invicti AppSec Core platform launch (June 2026), and the appointment of Katie Bullard to the board (May 2026) to support go-to-market scaling.

Invicti Security firmographics

Firmographics
Name
Invicti Security
Legal name
Invicti Security Corp
Website
https://invicti.com
Company type
Private
Founded year
2017
Operating status
Operating
Headcount range
251–500 employees
Short description
Invicti Security provides a unified, proof-based application security platform combining DAST, SAST, SCA, ASPM, and AI-driven prioritization for 3,600+ enterprise and government customers worldwide, including NASA, FAA, United Nations, KPMG, and Cisco.
Ownership category
akta.pro rank

Invicti Security industry classification

Industry
Product category
Application Security
NAICS
Other Computer Related Services (541519), Computer Systems Design and Related Services (54151)
SIC
Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
akta.pro secondary industries
Attack Surface Management (EASM/CAASM) (HDADAHAC), Vulnerability Management & Penetration Testing Services (BPAEADAD)

Keywords

  • Application security testing
  • Web application security
  • API security testing
  • Software composition analysis
  • Vulnerability management platform

Where Invicti Security is headquartered

Location

Headquarters

HQ city
Austin
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Invicti Security business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations

Revenue model

  1. SaaS Subscription (Invicti Platform): Cloud-hosted SaaS platform with subscription-based pricing. Entry-level costs start at approximately $7,000 per year, shaped by number of targets, deployment model, and feature add-ons. Available as cloud-hosted solution with simplified onboarding and CI/CD integrations.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualEnterprise tier with full platform access

Go-to-market motion1 record

Distribution channels5 records

Marketing channels9 records

Invicti Security product offering

Product offering

Core offering

Invicti Security provides a unified application security platform that combines proof-based DAST, SAST, SCA, container security, secrets detection, API security testing, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate findings from every testing tool, prioritizes vulnerabilities by real risk, and delivers AI-powered remediation guidance to enterprise development and security teams.

Product overview

Invicti Security offers a unified AppSec platform (Invicti Platform) that combines multiple security testing capabilities: SAST, SCA (Open Source), DAST, container security, secrets detection, IaC scanning, API security testing, attack surface management, cloud app security, AI-powered scanning, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate results from every testing tool, confirms what's real, and drives faster fixes through AI, automation, and ASPM. Key products include Invicti AppSec Core (all-in-one platform), DAST (proof-based dynamic scanning with 99.98% accuracy), SAST (static code analysis), SCA (software composition analysis with SBOM generation), Container Security, API Security Testing, Agentic Penetration Testing, and ASPM (formerly Kondukto). The platform is designed to eliminate false positives and prioritize vulnerabilities by real risk.

Differentiator

Problem solved

Functional benefit

Brands

  • Invicti AppSec Core: An all-in-one application security platform that combines proof-based DAST scanning with SAST, SCA, container security, secrets detection, and automated SBOM generation to eliminate duplicate findings and correlate vulnerabilities across environments.

Products and services

  • Invicti AppSec Core All-in-one application security platform combining proof-based DAST scanning with SAST, SCA, container security, secrets detection, IaC scanning, and automated SBOM generation to eliminate duplicate findings and correlate vulnerabilities across environments.
  • DAST Industry-leading Dynamic Application Security Testing engine delivering proof-based scanning with 99.98% accuracy, fully integrated into the SDLC, scaling across teams and application portfolios.
  • SAST Static Application Security Testing that connects static analysis to verified runtime vulnerabilities, code ownership, and remediation guidance.
  • SCA (Software Composition Analysis) Discovers vulnerable open-source dependencies, generates SBOMs, identifies container risks, and prioritizes remediation with runtime intelligence.
  • Container Security Secures containerized applications with image scanning, software supply chain analysis, and runtime-informed prioritization.
  • API Security Testing Scans REST, SOAP, and GraphQL APIs with the same depth and accuracy as web apps, discovering shadow APIs and reconstructing API specs automatically.
  • Application Security Posture Management (ASPM) Runtime-verified ASPM that unifies, validates, prioritizes, and acts on application security risk, providing a single source of truth with policy enforcement and audit-ready reporting.
  • Agentic Penetration Testing Automates real-world attack techniques for autonomous penetration testing that simulates attacker behavior without human intervention.

Quantifiable outcome

  • 99.98% confirmation accuracy for exploitable vulnerabilities
  • +5 more outcomes

Companies that use Invicti Security

Customer profile

Named customers20 records

Segments7 records

Ideal customer profiles3 records

Invicti Security technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration62 records

AI capability5 records

Feature9 records

Invicti Security partnerships and signals

Strategic signal

Partnerships

Nine partnerships are on record, tiered core.

  • AWScoreTechnology or IntegrationAmazon Web Services integration and marketplace listing for WAF monitoring, security scanning, and AWS Marketplace procurement.
  • GitHub ActionscoreTechnology or IntegrationGitHub Actions integration for automating tasks within the software development lifecycle and CI/CD pipelines.
  • Azure PipelinescoreTechnology or IntegrationAzure DevOps integration providing CI/CD pipeline features for DevOps workflow automation.
  • JenkinscoreTechnology or IntegrationJenkins automation server integration with plugins for build automation and security testing integration.
  • JIRAcoreTechnology or IntegrationJIRA issue tracking integration for agile project management and bug tracking with security vulnerability tickets.
  • ServiceNowcoreTechnology or IntegrationServiceNow integrations for Application Vulnerability Response and Vulnerability Response, helping track, prioritize, and resolve vulnerabilities.
  • OktacoreTechnology or IntegrationOkta identity and access management integration for SSO and SCIM-based user provisioning.
  • Azure Active DirectorycoreTechnology or IntegrationAzure AD integration for identity management, secure SSO, and multi-factor authentication.
  • GitLab CI/CDcoreTechnology or IntegrationGitLab integration for source control repositories and CI/CD pipeline security automation.

Scale indicators7 records

Recent moves6 records

Expansion highlights6 records

Invicti Security competitors and assessment

Company assessment

Direct peers

  • Mend (formerly WhiteSource): Application security platform specializing in SCA, SAST, and supply chain security with enterprise GTM. Direct overlap with Invicti's SCA and SAST modules and listed as a partner/integration reference in Invicti's ecosystem.
  • Contrast Security: Runtime application security platform combining IAST, RASP, SAST, and SCA. Competes head-to-head with Invicti on the runtime/IAST and proof-based vulnerability validation thesis, targeting similar enterprise AppSec buyers.
  • Veracode: Established AppSec testing vendor offering SAST, DAST, SCA, and software composition analysis. Direct competitor targeting the same enterprise/CISO buyer, with comparable focus on accuracy and remediation workflows.
  • Snyk: Developer-first security platform offering SAST, SCA, container, and IaC security with PLG and enterprise GTM motions. Direct competitor in the same AppSec testing category, overlapping heavily with Invicti's SAST, SCA, and container modules.
  • Checkmarx: Enterprise AppSec platform providing SAST, SCA, DAST, and ASPM (Checkmarx One). Direct competitor across the unified AppSec platform thesis, particularly in large enterprise and regulated verticals where Invicti also wins.

Broad incumbents

  • Qualys: Cloud-based security and compliance platform with web application scanning (Qualys WAS) within a broader vulnerability management and compliance suite. Adjacent competitor in enterprise web app and API security assessments.
  • Tenable (Nessus / Tenable.io): Large vulnerability management and exposure platform offering web app scanning alongside Nessus-based infrastructure scanning. Competes in enterprise vulnerability discovery with broader exposure management positioning.
  • GitLab: DevSecOps platform with built-in SAST, DAST, SCA, container, and IaC scanning bundled into a broader source-control and CI/CD platform. Competes as a broad incumbent where AppSec is one feature among many rather than a specialized focus.
  • Rapid7 (InsightAppSec / InsightVM): Broad security vendor offering DAST (InsightAppSec) and vulnerability management (InsightVM) within a wider portfolio including SIEM and detection. Competes with Invicti in AppSec while also offering adjacent security operations products.
  • GitHub Advanced Security: Native SAST, SCA, and secret scanning tightly integrated into the GitHub developer ecosystem. Represents the mega-platform threat to standalone AppSec vendors by bundling security into the developer's primary toolchain.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks5 records

Key highlights7 records

Customer concentration

Invicti Security social profiles

Digital presence

Invicti Security compliance and trust

Trust signal

Compliance2 records

Invicti Security financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Invicti Security leadership team

Management profile

Number of profiles

Profiles7 records

Invicti Security subsidiaries and ownership

Company hierarchy

Subsidiaries1 record

Invicti Security funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Invicti Security M&A and investment

M&A and investment

M&A2 records

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Invicti Security

What does Invicti Security do?

Invicti Security provides a unified application security platform that combines proof-based DAST, SAST, SCA, container security, secrets detection, API security testing, and Application Security Posture Management (ASPM). The platform uses runtime intelligence to validate findings from every testing tool, prioritizes vulnerabilities by real risk, and delivers AI-powered remediation guidance to enterprise development and security teams.

Is Invicti Security a public or private company?

Invicti Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.

When was Invicti Security founded?

Invicti Security was founded in 2017. It employs 251 to 500 people.

Where is Invicti Security based?

Invicti Security is headquartered in Austin, United States, in the North America region.

How does Invicti Security make money?

One revenue line is on record: saaS Subscription (Invicti Platform).

Who are Invicti Security's main competitors?

Direct peers on record are Mend (formerly WhiteSource), Contrast Security, Veracode, Snyk and Checkmarx. Broad incumbents are Qualys, Tenable (Nessus / Tenable.io), GitLab, Rapid7 (InsightAppSec / InsightVM) and GitHub Advanced Security.

Does Invicti Security have an API?

Yes. Invicti Team and Enterprise has a full-featured REST API which allows for easy integration. The platform supports webhooks for custom integrations with issue tracking systems that do not have their own built-in integration. Developer documentation is at docs.invicti.com.

What industry is Invicti Security in?

Invicti Security's product category is Application Security. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDADAHAC, Attack Surface Management (EASM/CAASM). Its NAICS code is 541519 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
WebProNewsAI Agents That Hack Like Humans: The Rise of Agentic PentestingAgentic pentesting, using autonomous AI agents to plan and execute attacks, is moving from experiment to production. Depthfirst launched its platform on September 30, and vendors like Invicti and Pentera are adopting hybrid models. The technology aims to match the speed of AI-driven attackers, but governance and safety remain critical.Cyber Security NewsTop 10 Best DAST Tools in 2026 [Ranked & Scored]Ten dynamic application security testing (DAST) tools are ranked for 2026, with PortSwigger's Burp Suite leading at 9.3. Invicti and StackHawk follow, with the ranking emphasizing authenticated, schema-fed, SPA-capable scanning. The article advises feeding schemas and credentials to avoid false positives.Third NewsInvicti Rises as a Leader in Dynamic Application Security Testing for 2026Invicti Security was named a Leader in the 2026 IDC MarketScape for Dynamic Application Security Testing, covering 16 vendors. The report highlights its proof-based scanning, AI-driven testing, and API discovery, noting 48% of AI coding tool users face increased security issues. Invicti plans to expand into a holistic application security platform.PR NewswireInvicti named a Leader in 2026 IDC MarketScape for dynamic application security testingInvicti Security was named a Leader in the IDC MarketScape for dynamic application security testing in 2026. The assessment recognized its proof-based scanning, AI-assisted testing, and API discovery. The company plans to expand its DAST foundation into an all-in-one application security platform.SourcesecurityInvicti's free security platform for water utilitiesInvicti has announced a free three-month access initiative to its application security platform for qualifying U.S. water utilities, prompted by FBI and EPA warnings about cyber threats targeting internet-connected operational technology at water facilities. The program includes guided onboarding and engineering support to help utilities discover web application and API exposure, confirm exploitable vulnerabilities, and prioritize actionable risks. The initiative aims to address growing concerns that adversaries are systematically hunting for unsecured internet-facing assets at critical infrastructure operators.Third NewsInvicti Provides Complimentary Application Security Support for U.S. Water Utilities Amid Cyber ThreatsInvicti Security is offering three months of complimentary access to its application security platform for qualifying U.S. water utilities, responding to recent warnings from the FBI and EPA about cyberattacks targeting internet-connected operational technologies at water facility infrastructure. The free program includes discovery and inventory of web applications and APIs, vulnerability scanning with prioritization of exploitable risks, and ongoing support from Invicti engineers. This initiative aims to help critical infrastructure operators address security gaps before potential breaches can disrupt essential services or expose sensitive operational data.PR NewswireFollowing FBI and EPA warnings, Invicti offers complimentary AppSec support to U.S. water utilitiesInvicti Security is offering qualifying U.S. water utilities three months of complimentary access to its application security platform to help them identify and address vulnerabilities in web applications and APIs. The initiative comes after FBI and EPA issued warnings about increased cyberattacks targeting internet-connected operational technology at water utilities. The program includes guided onboarding and support from Invicti engineers to help teams discover assets, scan for weaknesses, confirm exploitable vulnerabilities, and prioritize remediation.SourcesecurityInvicti agentic pentest: AI-powered security testingInvicti Security has launched the Invicti Agentic Pentest, a penetration testing solution that combines autonomous AI agents with its proof-based Dynamic Application Security Testing (DAST) technology to identify vulnerabilities more efficiently than traditional methods. The hybrid approach uses specialized AI agents for real-time testing strategy adaptation while relying on deterministic DAST for established vulnerabilities, reportedly reducing costs and testing delays. Early-access deployments demonstrated the system's ability to uncover complex attack paths and business logic vulnerabilities that traditional penetration testing methods missed.Third NewsInvicti Unveils Agentic Pentest: The Future of Penetration TestingInvicti Security has launched the Invicti Agentic Pentest, a new penetration testing solution that combines autonomous AI with its existing proof-based Dynamic Application Security Testing (DAST) technology. The hybrid approach aims to address limitations of traditional manual penetration testing (high cost and infrequent scheduling) and existing AI-driven solutions (inflated computational expenses). The product is designed for enterprise security teams and features proprietary AI agents that analyze application behavior, map attack surfaces, and dynamically adjust testing methodologies.PR NewswireInvicti Launches Agentic Pentest to Transform Modern Penetration TestingInvicti Security announced Invicti Agentic Pentest, combining autonomous AI reasoning with proof-based DAST for automated penetration testing. The hybrid approach targets multiple vulnerability classes and integrates with existing security workflows. The product is available as part of the Invicti platform.