ThreatNG Security
ThreatNG Security is a private, New York-based cybersecurity vendor operating an agentless, zero-connector platform that unifies External Attack Surface Management, Digital Risk Protection, and Security Ratings for enterprise CISOs, MSSPs, and federal buyers.
- Company typePrivate
- Founded2020
- HeadquartersNew York, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What ThreatNG Security does
ThreatNG Security is a private cybersecurity vendor founded in 2020 and headquartered in New York that operates an Integrated External Risk Management Platform combining External Attack Surface Management (EASM), Digital Risk Protection (DRP), and Security Ratings into a single, purely external, agentless offering. The platform performs unauthenticated reconnaissance from the outside in without requiring internal connectors, agents, or API keys, and is built on a patented recursive discovery engine (US Patent No. 11,962,612 B2) that iteratively uses found attributes to uncover deeper layers of the attack surface, including leaked non-human identities, orphaned subdomains, and shadow infrastructure. Its proprietary technology stack comprises the Context Engine for Legal-Grade Attribution, the DarChain Attack Path Intelligence engine that chains isolated findings into prioritized exploit narratives, and the DarCache suite of curated intelligence repositories spanning vulnerabilities (NVD/KEV/EPSS/PoC), ransomware, dark-web mentions, compromised credentials, ESG violations, and infostealer logs.
The company serves three primary customer segments: enterprise security and risk leaders (CISOs, GRC, SOC), Managed Security Service Providers (MSSPs), and U.S. federal/public sector buyers requiring FedRAMP-aligned solutions. Its commercial model is built on entity-centric subscription licensing — a fixed per-domain-and-organization rate covering unlimited assets, scans, and support — supplemented by a free self-serve evaluation path, a direct enterprise sales motion, an MSSP partner channel, and a storefront cart. The platform differentiates on zero-connector architecture, compliance framework mapping across NIST, ISO 27001, FedRAMP, GDPR, HIPAA, PCI DSS, and Open FAIR, and a high-velocity release cadence (DarcUpdates) that has expanded coverage through 2025-2026 into lawsuits, layoff chatter, AI attack surface, and FedRAMP 20x KSIs.
ThreatNG Security firmographics
Firmographics- Name
- ThreatNG Security
- Legal name
- ThreatNG Security®
- Website
- https://threatngsecurity.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- ThreatNG Security is a private, New York-based cybersecurity vendor operating an agentless, zero-connector platform that unifies External Attack Surface Management, Digital Risk Protection, and Security Ratings for enterprise CISOs, MSSPs, and federal buyers.
- Ownership category
- akta.pro rank
ThreatNG Security industry classification
Industry- Product category
- External Attack Surface Management
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF), Insider Threat Program Design & Risk Assessments (BPAKADAM)
Keywords
Where ThreatNG Security is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Markets served
ThreatNG Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Entity-Centric Subscription Licensing: Recurring revenue priced per pairing of a domain and organization name (entity-centric) rather than per asset, user, or module. Includes unlimited asset discovery, scans, and support within the entity with transparent fixed pricing — eliminating tiered upcharges and licensing shell games.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Single entity-centric subscription: fixed per-entity price covering unlimited assets, scans, and support |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels9 records
ThreatNG Security product offering
Product offeringCore offering
ThreatNG Security operates an all-in-one, purely external, zero-connector Integrated External Risk Management Platform that unifies External Attack Surface Management (EASM), Digital Risk Protection (DRP), and Security Ratings. The platform performs unauthenticated, outside-in reconnaissance of an organization's digital footprint and fuses the results with curated DarCache intelligence repositories and a DarChain attack-path correlation engine to deliver Legal-Grade Attribution and prioritized remediation guidance for enterprise security, GRC, and SOC teams.
Product overview
ThreatNG Security is an all-in-one, purely external, zero-connector Integrated External Risk Management Platform that combines three core solutions — External Attack Surface Management (EASM), Digital Risk Protection (DRP), and Security Ratings — under a single agentless discovery engine. The platform's foundation is the patent-backed Context Engine™, which powers Legal-Grade Attribution and Contextual Certainty across all findings, while DarChain Attack Path Intelligence models multi-stage exploit narratives and identifies Attack Path Choke Points for prioritized remediation. Underpinning everything is the DarCache suite of intelligence repositories (DarCache Vulnerability, Rupture, Dark Web, Ransomware, ESG, Infostealer, and Mobile), which fuel the platform's continuous assessment and the eXposure Priority View dashboard. The offering is organized as a platform-plus-modules architecture: the core platform is extended by ten specialized Investigation Modules — Domain Intelligence, Sensitive Code Exposure, Search Engine Exploitation, Cloud and SaaS Exposure, the Social Media Investigation Module (SMIM, including Reddit Discovery and LinkedIn Discovery), Sentiment and Financials, Archived Web Pages, Dark Web Presence (with Ransomware Events, Compromised Credentials, Dark Web Mentions, and Infostealer Intelligence pillars), Technology Stack, and Username Exposure — together with dedicated Compliance Modules (External FedRAMP Assessment, External Open FAIR Assessment, External GRC Assessment Mappings) and use-case solutions such as Third-Party Risk Management (TPRM), Cloud and SaaS Exposure Management, Brand Protection (including Web3 Domain Defense), Due Diligence, and AI Attack Surface Management. Recent DarcUpdate releases in 2026 added the Lawsuits Module, Layoff Chatter Module, Associated Organizations Discovery, Website Control File Exposure, and Subdomain Intelligence enhancements, extending the platform into human risk and external GRC territory while preserving its zero-connector, agentless operating model.
Differentiator
Problem solved
Functional benefit
Brands
- DarCache: ThreatNG's branded suite of curated intelligence repositories (Data Reconnaissance Cache), including DarCache Vulnerability, DarCache Rupture, DarCache Dark Web, DarCache Ransomware, DarCache ESG, DarCache Mobile, and DarCache Infostealer.
- DarChain
- Context Engine
- DarcSight Labs
Products and services
- ThreatNG Security Platform
Companies that use ThreatNG Security
Customer profileSegments4 records
Ideal customer profiles3 records
ThreatNG Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
AI capability5 records
Feature9 records
ThreatNG Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered minor.
- Verizon (DBIR)minorCited repeatedly as the primary third-party data source for breach statistics underpinning ThreatNG's thought-leadership narrative (e.g., 31% of breaches from vulnerability exploitation, 48% involving third parties, 43-day median critical-vulnerability resolution).
- CISA Known Exploited Vulnerabilities (KEV) CatalogminorReferenced as the authoritative source for 'actively exploited in the wild' status used by ThreatNG to prioritize critical vulnerabilities and inform remediation urgency.
- MITRE ATT&CKminorReferenced as the framework to which ThreatNG maps external threat findings (e.g., in the Social Media Investigation Module and Forensic Evidence Packages) to provide strategic context for security leaders.
- Open FAIR™ (Factor Analysis of Information Risk)minorReferenced as the cyber risk quantification ontology that ThreatNG automatically maps verified, unauthenticated external exposures into, enabling board-ready financial loss magnitude and threat-event-frequency models.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
ThreatNG Security competitors and assessment
Company assessmentDirect peers
- SecurityScorecard: SecurityScorecard is a closely comparable EASM and security-ratings vendor that also scores enterprises from the outside in without internal connectors. It overlaps directly with ThreatNG's Security Ratings, EASM, and TPRM modules and competes for the same CISO/GRC buyer at similar price points.
- Bitsight: Bitsight is a direct competitor in security ratings and external attack surface management, selling into enterprise GRC and TPRM buyers with a comparable continuous-monitoring methodology. Both vendors compete for third-party risk management and security ratings budget at large enterprises.
- UpGuard: UpGuard delivers external attack surface management and security ratings with a similar outside-in approach, including TPRM and vendor-risk workflows. It is a direct peer competing for the same mid-market and enterprise segments ThreatNG targets with its entity-centric pricing model.
- ZeroFox: ZeroFox is a Digital Risk Protection specialist that monitors the open, deep, and dark web for brand impersonation, credential exposure, and executive threats — directly overlapping ThreatNG's Digital Risk Protection, Brand Protection, Dark Web Investigation, and Username Exposure modules.
Broad incumbents
- Palo Alto Networks (Cortex Xpanse): Palo Alto Networks acquired Xpanse to build Cortex Xpanse, a leading EASM product sold as part of the broader Cortex security platform. It competes with ThreatNG's EASM offering but bundles external attack surface with Prisma Cloud, Cortex XSIAM, and Cortex XDR for cross-sell at large enterprise accounts.
- CrowdStrike (Falcon Surface): CrowdStrike added external attack surface management through Falcon Surface as part of the broader Falcon platform. It competes with ThreatNG's EASM but sells primarily as an add-on to endpoint security contracts, leveraging an installed base and global enterprise sales motion ThreatNG cannot match.
- Tenable: Tenable is a vulnerability-management incumbent that has expanded into external attack surface and security-ratings territory (Tenable One). Its broad platform overlaps with ThreatNG's External Vulnerability Assessment and EASM modules and benefits from established enterprise and federal footprints.
- Rapid7: Rapid7 offers exposure management capabilities alongside its SIEM and vulnerability-management products, providing external attack surface insight as part of a broader security operations portfolio. It is a broad-incumbent peer competing for the same CISO and SOC buyer ThreatNG targets.
- Microsoft (Defender External Attack Surface Management): Microsoft Defender External Attack Surface Management is bundled into the broader Microsoft Security portfolio, including Defender for Cloud and Sentinel. It directly competes with ThreatNG's EASM but leverages Microsoft's installed base, Azure integration, and enterprise licensing as a structural distribution advantage.
Emerging players
- Cyble: Cyble is an emerging EASM and digital risk protection vendor that monitors the dark web, leaked credentials, and external attack surface for enterprise and MSSP buyers. It is a partial-overlap emerging player competing for similar mid-market and enterprise contracts but with a different focus on threat-intelligence-led sales.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
ThreatNG Security social profiles
Digital presenceThreatNG Security compliance and trust
Trust signalCompliance12 records
ThreatNG Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
ThreatNG Security leadership team
Management profileNumber of profiles
ThreatNG Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ThreatNG Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ThreatNG Security
What does ThreatNG Security do?
ThreatNG Security operates an all-in-one, purely external, zero-connector Integrated External Risk Management Platform that unifies External Attack Surface Management (EASM), Digital Risk Protection (DRP), and Security Ratings. The platform performs unauthenticated, outside-in reconnaissance of an organization's digital footprint and fuses the results with curated DarCache intelligence repositories and a DarChain attack-path correlation engine to deliver Legal-Grade Attribution and prioritized remediation guidance for enterprise security, GRC, and SOC teams.
Is ThreatNG Security a public or private company?
ThreatNG Security is a private company. It is classified as unknown and is currently operating.
When was ThreatNG Security founded?
ThreatNG Security was founded in 2020. It employs 1 to 10 people.
Where is ThreatNG Security based?
ThreatNG Security is headquartered in New York, United States, in the North America region.
How does ThreatNG Security make money?
One revenue line is on record: entity-Centric Subscription Licensing.
Who are ThreatNG Security's main competitors?
Direct peers on record are SecurityScorecard, Bitsight, UpGuard and ZeroFox. Broad incumbents are Palo Alto Networks (Cortex Xpanse), CrowdStrike (Falcon Surface), Tenable, Rapid7 and Microsoft (Defender External Attack Surface Management). Cyble is listed as an emerging player.
Does ThreatNG Security have an API?
No public API is recorded for ThreatNG Security.
What industry is ThreatNG Security in?
ThreatNG Security's product category is External Attack Surface Management. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of BPAKADAF, Security Architecture & Engineering Advisory (Zero Trust, IAM, Network). Its NAICS code is 54151 and its SIC code is 7373.