OnDefend
OnDefend is a Jacksonville-based offensive cybersecurity firm combining elite human red team operators with its proprietary AI-powered BlindSPOT platform to deliver penetration testing, adversary emulation, and continuous security validation to enterprise and government clients across critical industries.
- Company typePrivate
- Founded2016
- HeadquartersJacksonville, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What OnDefend does
OnDefend is a Jacksonville, Florida-based offensive cybersecurity firm founded in 2016 that combines elite human red team operators with its proprietary AI-powered BlindSPOT platform to validate enterprise security postures against real-world adversaries. The company delivers penetration testing across network, application, cloud, hardware/IoT, AI/LLM, and cryptography environments, alongside adversary emulation services (red teaming, purple teaming, social engineering) and advisory offerings including risk assessments, compliance readiness, tabletop exercises, and Virtual CISO support. Its Continuous Security Inspector program and Security Control Validation offering shift portions of testing from point-in-time engagements to persistent, intelligence-driven subscriptions.
The technical core is BlindSPOT, a proprietary Breach & Attack Simulation SaaS platform launched in 2021. BlindSPOT automates repeatable attack activity, validates the effectiveness of prevention, detection, and response controls under realistic adversary pressure, and runs a Security Insights Engine that compounds tradecraft and intelligence across every engagement. AI is embedded directly into operator workflows through large language model-assisted reverse engineering, AI-driven static analysis across large codebases, automated authorization testing, and AI-enhanced reporting with reproduction evidence. The firm integrates with enterprise SecOps tooling, with documented support for Microsoft Defender for Endpoint autoscoring and alert validation.
OnDefend operates as a private LLC with a hybrid revenue model spanning professional services engagements and recurring SaaS subscriptions, priced via custom quotes rather than published rate cards. Distribution is primarily direct enterprise field sales targeting CISOs, supplemented by channel partnerships with Modis and ACI Learning. The customer base spans government, defense/intelligence, financial services, healthcare, energy, professional services, and technology, with named enterprise logos including TikTok USDS (where OnDefend serves as an Independent Security Inspector under Project Texas), Gartner, BigBear.ai, Popular Bank, Deloitte, Entergy, Baptist Health, and Florida Blue. The company reported 116% revenue growth in 2024 and was named JAXUSA 2025 Innovator of the Year for Cybersecurity Innovation.
OnDefend firmographics
Firmographics- Name
- OnDefend
- Legal name
- OnDefend, LLC
- Website
- https://ondefend.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- OnDefend is a Jacksonville-based offensive cybersecurity firm combining elite human red team operators with its proprietary AI-powered BlindSPOT platform to deliver penetration testing, adversary emulation, and continuous security validation to enterprise and government clients across critical industries.
- Ownership category
- akta.pro rank
OnDefend industry classification
Industry- Product category
- Offensive Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where OnDefend is headquartered
LocationHeadquarters
- HQ city
- Jacksonville
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
OnDefend business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales
Revenue model
- Penetration Testing Services: Professional services revenue from network, application, cloud, hardware, and AI/LLM penetration testing engagements. Delivered by elite red team operators with engagements scoped to client needs.
- Red Teaming & Adversary Emulation: Adversary emulation services including red teaming, purple teaming, and social engineering operations. Simulations built around real-life attack scenarios for enterprise clients.
- BlindSPOT SaaS Platform: Breach and Attack Simulation (BAS) Software-as-a-Service platform. Customers can access BlindSPOT for attack simulations, control validation, remediation verification, and testing insights. In some engagements, customers operate BlindSPOT directly as a SaaS solution.
- Advisory & Consulting Services: Cybersecurity risk assessments, compliance readiness, tabletop exercises, and Virtual CISO services.
- Continuous Security Inspector (CSI) Program: Continuous, intelligence-driven security testing program combining persistent red team testing with AI-powered capabilities. Provides ongoing validation rather than point-in-time assessments.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
OnDefend product offering
Product offeringCore offering
OnDefend provides offensive cybersecurity testing and advisory services, combining elite human red team operators with its proprietary AI-powered BlindSPOT platform. The firm delivers network, application, cloud, hardware, AI/LLM, and cryptography penetration testing; red, purple, and social engineering adversary emulation; and advisory services such as risk assessments, compliance readiness, tabletop exercises, and Virtual CISO engagements. Continuous programs—including the Continuous Security Inspector (CSI), Security Control Validation, Election Security, OT, and Facilities programs—provide persistent, intelligence-driven validation rather than point-in-time assessments.
Product overview
OnDefend is an advanced adversarial cybersecurity firm that combines elite human offensive security expertise with proprietary AI-powered technology. The core offering is the BlindSPOT platform—a Breach & Attack Simulation (BAS) SaaS product that automates attack simulation, validates security controls, and delivers AI-powered security insights. This platform powers the Continuous Security Inspector (CSI) program and other testing programs. The service portfolio spans penetration testing (network, application, cloud, hardware, AI/LLM, cryptography), adversary emulation (red teaming, purple teaming, social engineering), and advisory services (risk assessments, compliance readiness, tabletop exercises, virtual CISO). Specialized programs include Security Control Validation, Facilities Security, OT Security, and Election Security. The company operates primarily as a services business with BlindSPOT as the enabling technology platform.
Differentiator
Problem solved
Functional benefit
Products and services
- BlindSPOT Proprietary Breach & Attack Simulation (BAS) SaaS platform that automates repeatable attack activity, validates security controls, and delivers AI-powered security insights to power continuous, intelligence-driven security testing for enterprise customers.
- Continuous Security Inspector (CSI) An intelligence-driven red team testing program that continuously emulates real-world adversaries to uncover hidden attack paths and operational risk across network, software, cloud, hardware, IoT, and AI environments.
- Network Penetration Testing Identifies exploitable vulnerabilities and attack paths across internal, external, and wireless networks, VPN, remote access, and Active Directory environments for enterprise clients.
- Application Penetration Testing Assesses web, mobile, desktop, and API applications through dynamic and source code testing to uncover exploitable vulnerabilities, business logic flaws, and attack paths.
- Cloud Penetration Testing Assesses AWS, Azure, GCP, OCI, IBM Cloud, GovCloud, hybrid, and custom cloud environments to uncover misconfigurations, identity weaknesses, and attack paths.
- Hardware & Integrated Systems Testing Assesses devices, firmware, and supply-chain integrity to uncover hidden vulnerabilities, undocumented components, and unauthorized communications in hardware and embedded systems.
- AI & LLM Penetration Testing Assesses AI and LLM systems, including LLM applications and agents, custom models, and integration layers, to uncover weaknesses that could lead to manipulation, data leakage, or unsafe behavior.
- Cryptography Testing Tests network and transport encryption, APIs and token-based systems, and post-quantum cryptography implementations for cryptographic weaknesses.
- Red Teaming Services Emulates determined adversaries to demonstrate how attackers penetrate, persist, and achieve real-world impact across people, process, and technology for enterprise clients.
- Purple Teaming Services Collaborative attack simulations uniting red teams and blue teams to identify protection, detection, and response gaps in enterprise security operations.
- Social Engineering Operations Realistic phishing, vishing, smishing, and physical deception testing to evaluate how people and processes respond to human-focused attack techniques.
- Cybersecurity Risk Assessments Security controls, governance, operational readiness, and compliance assessments for enterprise organizations.
- Compliance Readiness Gap assessments, control testing, and audit readiness services to prepare organizations for regulatory and compliance obligations.
- Tabletop Exercises Incident response testing, disaster recovery/business continuity, crisis management, and cross-team/vendor coordination exercises for enterprise clients.
- Virtual CISO Senior cybersecurity leadership services delivered without executive overhead for organizations needing CISO-level strategic guidance.
- Security Control Validation as a Service Continuous validation that security controls prevent, detect, and respond under adversary pressure for enterprise clients.
- Facilities Security Program Emulates adversaries across physical and cyber domains to expose cross-domain attack paths and resilience gaps in physical facilities.
- Operational Technology (OT) Security Program Continuously simulates adversaries within converged IT/OT environments to identify operational disruption pathways in operational technology settings.
- Election Security Program Independent, evidence-based validation of election infrastructure defenses and response capabilities, designed to assess readiness against real-world cyber threats before Election Day.
Quantifiable outcome
- Double-digit percentage efficiency gains in penetration testing engagements through AI integration
- +1 more outcomes
Companies that use OnDefend
Customer profileNamed customers13 records
Segments5 records
Ideal customer profiles5 records
OnDefend technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability5 records
Feature7 records
OnDefend partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered flagship, core and minor.
- TikTok U.S. Data Security (USDS)flagshipOnDefend appointed alongside HaystackID as Independent Security Inspectors (ISIs) for TikTok USDS as part of Project Texas. The partnership involves continuous technical security testing and validation of the TikTok U.S. platform, source code, and user information. OnDefend uses its advanced security testing team and proprietary BlindSPOT platform to identify and address vulnerabilities within the TikTok application and network infrastructure. This high-profile national security engagement represents OnDefend's most significant public-facing security validation role.
- HaystackIDflagshipOnDefend partnered with HaystackID to jointly serve as Independent Security Inspectors for TikTok USDS, with additional support from Mandiant Consulting. HaystackID provides specialized data services for legal, compliance, regulatory, and cyber events, while OnDefend contributes offensive security testing expertise and BlindSPOT technology.
- Mandiant ConsultingcoreMandiant Consulting provides security assessment services as part of the TikTok USDS Independent Security Inspector collaboration. Recognized as market leader in threat intelligence and expertise gained on frontlines of cybersecurity.
- OraclecoreTikTok USDS leverages Oracle Cloud infrastructure for secure storage of protected U.S. user data, content recommendation, and moderation systems. OnDefend's security testing encompasses validation of this cloud infrastructure as part of its ISI responsibilities.
- ACI LearningminorOnDefend and ACI Learning announced a promotional agreement to extend reach and offer security services to ACI Learning's client base through joint go-to-market activities.
- ModiscoreOnDefend extended its market reach through partnership with Modis, offering security services to Modis' clients throughout the U.S. This channel partnership leverages Modis' existing IT services relationships to deliver OnDefend's cybersecurity offerings to a broader client base.
Scale indicators4 records
Recent moves7 records
Expansion highlights6 records
OnDefend competitors and assessment
Company assessmentDirect peers
- Bishop Fox: Bishop Fox is a leading U.S.-based offensive security firm offering penetration testing, red teaming, and attack surface management to enterprise and government clients. It is the most direct comparable to OnDefend in services portfolio, customer profile, and elite-operator positioning.
- NetSPI: NetSPI provides penetration testing, attack surface management, and vulnerability management as a SaaS-enabled services platform (Resolve). It competes head-to-head with OnDefend in enterprise pen testing and shares the hybrid services-plus-platform GTM model.
- Praetorian: Praetorian offers offensive security services including penetration testing, red teaming, and attack surface management with a proprietary platform (Chariot). It mirrors OnDefend's combination of elite human testers and proprietary technology.
- TrustedSec: TrustedSec is a U.S. offensive-security consultancy specializing in penetration testing, red teaming, and incident response. It competes with OnDefend for enterprise and government engagements with a similarly elite-operator value proposition.
- NCC Group: NCC Group is a global cybersecurity firm with a substantial offensive-security practice (pentesting, red teaming, escrow). It is a larger, publicly listed peer competing in the same enterprise pen testing and assurance category.
- Coalfire: Coalfire delivers offensive security, compliance, and risk advisory services to enterprise and government clients. It overlaps with OnDefend's advisory and pen testing portfolio and shares the regulated-vertical focus (FedRAMP, PCI, healthcare).
Broad incumbents
- Mandiant (Google Cloud): Mandiant, owned by Google Cloud, is a market leader in incident response, threat intelligence, and offensive security assessments. It is a co-ISI alongside OnDefend for TikTok USDS and a broad incumbent competitor for high-end red team work.
- CrowdStrike Services: CrowdStrike's professional services arm offers adversary emulation, red team, and SOC consulting bundled with its Falcon endpoint platform. It competes with OnDefend for enterprise security budgets from a much larger platform base.
- Rapid7: Rapid7 offers penetration testing and managed security services alongside its InsightVM and Metasploit platforms. It competes with OnDefend in vulnerability management and offensive security testing for mid-market and enterprise buyers.
Emerging players
- Scythe: Scythe is an emerging adversary emulation platform vendor competing with Breach and Attack Simulation tools. It overlaps with OnDefend's BlindSPOT in automating attack simulation and is a relevant emerging competitor in the platform layer.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
OnDefend social profiles
Digital presenceOnDefend compliance and trust
Trust signalCompliance1 record
OnDefend financial estimates
Financial estimateRevenue estimate
Valuation estimate
OnDefend leadership team
Management profileNumber of profiles
Profiles15 records
OnDefend funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OnDefend M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OnDefend
What does OnDefend do?
OnDefend provides offensive cybersecurity testing and advisory services, combining elite human red team operators with its proprietary AI-powered BlindSPOT platform. The firm delivers network, application, cloud, hardware, AI/LLM, and cryptography penetration testing; red, purple, and social engineering adversary emulation; and advisory services such as risk assessments, compliance readiness, tabletop exercises, and Virtual CISO engagements. Continuous programs—including the Continuous Security Inspector (CSI), Security Control Validation, Election Security, OT, and Facilities programs—provide persistent, intelligence-driven validation rather than point-in-time assessments.
Is OnDefend a public or private company?
OnDefend is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was OnDefend founded?
OnDefend was founded in 2016. It employs 1 to 10 people.
Where is OnDefend based?
OnDefend is headquartered in Jacksonville, United States, in the North America region.
How does OnDefend make money?
Five revenue lines are on record. Penetration Testing Services are the primary driver. The others are red Teaming & Adversary Emulation, blindSPOT SaaS Platform, advisory & Consulting Services and continuous Security Inspector (CSI) Program.
Who are OnDefend's main competitors?
Direct peers on record are Bishop Fox, NetSPI, Praetorian, TrustedSec, NCC Group and Coalfire. Broad incumbents are Mandiant (Google Cloud), CrowdStrike Services and Rapid7. Scythe is listed as an emerging player.
Does OnDefend have an API?
No public API is recorded for OnDefend.
What industry is OnDefend in?
OnDefend's product category is Offensive Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 5415 and its SIC code is 7373.