Enzoic
Enzoic is a Boulder, Colorado-based credential intelligence platform founded in 2016 that prevents account takeover by screening passwords and credentials against a continuously updated breach database via Active Directory integration and REST APIs for enterprise security teams.
- Company typePrivate
- Founded2016
- HeadquartersBoulder, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Enzoic does
Enzoic, operating legally as PasswordPing Ltd. d/b/a Enzoic, is a Boulder, Colorado-based credential intelligence and account takeover prevention company founded in 2016. The firm maintains a continuously updated database of compromised credentials derived from automated 24/7 collection across the public Internet, Dark Web, and private sources, combined with human analyst research. Its core products are Enzoic for Active Directory, a Windows filter driver that enforces password policy and continuously monitors for credential exposure within enterprise AD environments, and a suite of REST APIs (Passwords, Credentials, Exposures, Breach Monitoring, Identity Breach Monitoring, and BIN Monitoring) that expose the credential intelligence database to third-party applications. Add-on modules cover identity breach monitoring, payment card BIN monitoring, and password breach monitoring, while AD Lite is offered as a free auditing tool to drive product-led adoption.
Enzoic monetizes through subscription-based API access and tiered Active Directory software licenses (Premium and Enterprise), supplemented by a freemium tier (AD Lite) and an OEM-style Security Data Partnerships program. Go-to-market is hybrid: an API-first motion targets developers and security teams, an enterprise field sales motion covers larger deployments, and product-led growth through AD Lite drives top-of-funnel awareness. Customer logos span healthcare (Cedar Sinai, Blue Cross), education (University of Kentucky, University of Southern California), technology (Backblaze, Kingston Technology, LogMeIn, OneLogin), automotive/retail (Carvana), and media (Motion Picture Association). Named verticals targeted on the website include hospitals and healthcare, government, education, and financial services, with use cases framed around ATO protection, NIST 800-63B compliance, CMMC compliance, and IAM platform enhancement. In December 2024 Enzoic acquired VeriClouds to deepen credential security capabilities and in October 2024 entered the CIS CyberMarket distribution partnership to reach public-sector buyers.
Enzoic firmographics
Firmographics- Name
- Enzoic
- Legal name
- PasswordPing Ltd. d/b/a Enzoic
- Website
- https://enzoic.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Enzoic is a Boulder, Colorado-based credential intelligence platform founded in 2016 that prevents account takeover by screening passwords and credentials against a continuously updated breach database via Active Directory integration and REST APIs for enterprise security teams.
- Ownership category
- akta.pro rank
Enzoic industry classification
Industry- Product category
- Credential Intelligence and Account Takeover Prevention Software
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Account Takeover (ATO) Prevention (HDADALAA)
- akta.pro secondary industries
- Credential Stuffing & Password Attack Protection (HDADALAC), Account Takeover (ATO) Prevention (FSAMALAF)
Keywords
Where Enzoic is headquartered
LocationHeadquarters
- HQ city
- Boulder
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Enzoic business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- API Subscriptions: Subscription-based access to Enzoic's credential intelligence APIs including Passwords API, Credentials API, Exposures API, Breach Monitoring API, Identity Breach Monitoring API, and BIN Monitoring API. Pricing likely tiered based on API call volume.
- Active Directory Software Licenses: Licensing for Enzoic for Active Directory product with tiered plans including Premium and Enterprise features. Multi-policy support, User Credentials Monitoring, and advanced remediation options available in premium tiers.
- Free Tier / Freemium: AD Lite provides free password auditing tool for Active Directory. Free trial options available for evaluation before purchase commitment.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free tier with basic password auditing |
| Subscription | Annual | Paid enterprise tiers (Premium and Enterprise) |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
Enzoic product offering
Product offeringCore offering
Enzoic provides a credential intelligence and account takeover prevention platform that screens passwords, usernames, and PII against a continuously updated database of breached and dark-web-exposed records. Its primary offerings are the Enzoic for Active Directory software (a Windows filter driver with real-time password validation and continuous monitoring/remediation) and the Enzoic REST APIs (Passwords, Credentials, Exposures, Breach Monitoring, Identity Breach Monitoring, and BIN Monitoring) for embedding into authentication, IAM, and SIEM workflows. Customers include security and IT teams at enterprises in healthcare, government, education, and financial services who need to block compromised credentials at password selection and detect exposures continuously.
Product overview
Enzoic is a credential intelligence and account takeover prevention platform offering a portfolio of products: Enzoic for Active Directory (core product - version 3.6) provides password screening and continuous monitoring directly within Windows Active Directory environments; Enzoic APIs enables programmatic access to credential intelligence for custom integrations; and add-on modules provide specialized monitoring for identity breaches, password exposures, and payment card BINs. The platform is designed to prevent credential-based attacks without adding friction to legitimate user authentication, with solutions targeting ATO protection, NIST compliance, and broader cybersecurity compliance requirements.
Differentiator
Problem solved
Functional benefit
Products and services
- Enzoic for Active Directory Password protection software that integrates into Windows Active Directory via a filter driver to enforce additional password rules, prevent users from selecting compromised credentials at password selection time, continuously monitor credential exposure, and automate remediation such as email notifications, forced password change, and account disable.
- Enzoic APIs Suite of hosted REST APIs providing programmatic access to Enzoic's compromised credential database for integration into authentication workflows, IAM platforms, SIEM systems, and custom applications, including Passwords API, Credentials API, Exposures API, Breach Monitoring API, Identity Breach Monitoring API, and BIN Monitoring API.
- Identity Breach Monitoring Monitors for the exposure of personally identifiable information (PII) on the dark web and other sources to reduce the risk of identity theft and data abuse through actionable dark-web threat intelligence.
- Password Breach Monitoring Provides real-time alerts when accounts and credentials are exposed in data breaches, enabling organizations to receive notifications about credential exposures for monitored email addresses and domains.
- Payment Card BIN Monitoring Enables financial institutions to track credit and debit card numbers for Dark Web exposure by monitoring Bank Identification Number (BIN) ranges.
- Enzoic for Active Directory LITE Free password auditing tool for Active Directory that reveals domain password vulnerabilities in seconds, allowing organizations to assess current risk exposure without requiring a full deployment.
Quantifiable outcome
- 97% of identity attacks are password spray attacks (Microsoft finding cited by Enzoic)
- +3 more outcomes
Companies that use Enzoic
Customer profileNamed customers10 records
Segments8 records
Ideal customer profiles5 records
Enzoic technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability2 records
Feature8 records
Enzoic partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- VeriCloudscoreEnzoic announced acquisition of VeriClouds on December 9, 2024. This acquisition strengthens Enzoic's credential intelligence capabilities and expands their technical capabilities in the credential screening space.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Enzoic competitors and assessment
Company assessmentEmerging players
- LastPass: Password manager with dark-web monitoring and compromised-credential alerts; adjacent competitor for end-user credential screening use cases.
- Transmit Security: Identity-security vendor offering fraud/risk and credential intelligence capabilities that overlap with Enzoic's ATO Protection and BIN Monitoring offerings.
- 1Password: Consumer and enterprise password manager with Watchtower breach-monitoring; acquired Have I Been Pwned and competes in credential exposure alerting and password screening.
Broad incumbents
- Okta: IAM platform with native compromised-credential detection and threat insight features; competes for the same identity-security budget and increasingly bundles credential screening that Enzoic sells via its Enhancing IAM solution.
- Recorded Future: Broader threat intelligence platform that includes compromised-credential feeds and dark-web monitoring across the same buyer set (enterprise security teams, SIEM consumers).
- IntSights (Rapid7 Threat Intelligence): Threat intelligence (acquired by Rapid7) with dark-web credential and account-exposure monitoring feeding enterprise SOC tooling, addressing similar buyer needs to Enzoic's breach and identity monitoring APIs.
- Flashpoint: Threat intelligence and fraud-prevention vendor that ingests compromised credentials from illicit communities and offers adjacent ATO and identity-exposure intelligence products.
- Microsoft Entra ID Protection: Native cloud identity protection within the Microsoft Entra (Azure AD) ecosystem that screens for leaked credentials and risky sign-ins — a direct substitute for Enzoic's AD and API offerings in Microsoft-heavy estates.
Direct peers
- SpyCloud: Direct competitor offering a credential exposure and ATO prevention platform with a large dark-web-collected breach database and APIs/plugins for AD, IAM, and SIEM. Closest functional analogue to Enzoic's APIs and AD product.
- Have I Been Pwned: Troy Hunt's breach-notification service and credential corpus that Enzoic explicitly overlaps with via its Exposures API, Breach Monitoring API, and Identity Breach Monitoring module.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights8 records
Customer concentration
Enzoic social profiles
Digital presenceEnzoic compliance and trust
Trust signalCompliance2 records
Enzoic financial estimates
Financial estimateRevenue estimate
Valuation estimate
Enzoic leadership team
Management profileNumber of profiles
Profiles3 records
Enzoic subsidiaries and ownership
Company hierarchySubsidiaries1 record
Enzoic funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Enzoic M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Enzoic
What does Enzoic do?
Enzoic provides a credential intelligence and account takeover prevention platform that screens passwords, usernames, and PII against a continuously updated database of breached and dark-web-exposed records. Its primary offerings are the Enzoic for Active Directory software (a Windows filter driver with real-time password validation and continuous monitoring/remediation) and the Enzoic REST APIs (Passwords, Credentials, Exposures, Breach Monitoring, Identity Breach Monitoring, and BIN Monitoring) for embedding into authentication, IAM, and SIEM workflows. Customers include security and IT teams at enterprises in healthcare, government, education, and financial services who need to block compromised credentials at password selection and detect exposures continuously.
Is Enzoic a public or private company?
Enzoic is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Enzoic founded?
Enzoic was founded in 2016. It employs 11 to 50 people.
Where is Enzoic based?
Enzoic is headquartered in Boulder, United States, in the North America region.
How does Enzoic make money?
Three revenue lines are on record. API Subscriptions are the primary driver. The others are active Directory Software Licenses and free Tier / Freemium.
Who are Enzoic's main competitors?
Emerging players on record are LastPass, Transmit Security and 1Password. Broad incumbents are Okta, Recorded Future, IntSights (Rapid7 Threat Intelligence), Flashpoint and Microsoft Entra ID Protection. Direct peers are SpyCloud and Have I Been Pwned.
Does Enzoic have an API?
Yes. Enzoic offers a REST API that allows developers to integrate compromised credential detection into their applications. The API supports Passwords API (checking if passwords are compromised), Credentials API (checking username/password combinations), Exposures API (retrieving breach details), Breach Monitoring API (registering email addresses/domains for breach notifications), Identity Breach Monitoring API, and BIN Monitoring API. APIs are implemented as RESTful web services with JSON payloads, accessed via HTTPS with basic auth (API key as username, API secret as password). The API uses a partial hash approach where only the first 10 hex characters of password hashes are sent, ensuring no clear text or credential hash data leaves the customer environment. Developer documentation is at docs.enzoic.com/enzoic-api-developer-documentation.
What industry is Enzoic in?
Enzoic's product category is Credential Intelligence and Account Takeover Prevention Software. Its primary akta.pro industry code is HDADALAA, Account Takeover (ATO) Prevention, with a secondary code of HDADALAC, Credential Stuffing & Password Attack Protection. Its NAICS code is 5415 and its SIC code is 7371.