zvelo
zvelo (OTCMKTS: ZVLO) builds proprietary AI-driven URL classification and threat intelligence feeds, licensing them to OEM security, ad tech, and communications partners via annual subscriptions. Its platform analyzes clickstream from 1B+ endpoints to power SASE, XDR, web filtering, and brand safety products.
- Company typePublic
- Founded1984
- HeadquartersGreenwood Village, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What zvelo does
zvelo is a publicly traded (OTCMKTS: ZVLO) cybersecurity and web intelligence company headquartered in Greenwood Village, Colorado, that builds and licenses URL classification databases and threat intelligence feeds to OEM partners. Originally founded as eSoft, Inc. in 1984 and rebranded to zvelo in 2010 after divesting its UTM appliance business, the company focuses exclusively on data services for network security, ad tech, communications, and threat intelligence platform vendors.
The company's product portfolio centers on the zveloDB URL database (covering 500+ content categories across 200+ languages with claimed 99.9% ActiveWeb coverage and 99%+ accuracy), the zveloCAT real-time classification engine, and the zveloCTI Cyber Threat Intelligence suite (PhishBlocklist, PhishScan, Malicious Detailed Detection Feed), with newer SaaS App Intelligence extending into DLP and SaaS security posture. Underlying technology combines proprietary AI/ML with a hybrid human-supervised machine learning approach, trained on clickstream traffic from over 1 billion users and endpoints across the OEM partner network and enriched with OSINT and third-party threat feeds. The platform architecture, in its third generation since 2018, uses NLU, anomaly detection, and predictive analytics for URL categorization and threat identification.
zvelo operates a 100% OEM channel model, licensing data feeds via annual subscription to embedded partners including Trend Micro, Proofpoint, Zscaler, AWS, ESET, Trellix, Infoblox, Recorded Future, Cognyte, PowerDNS, and Todyl, supplemented by real-time API services (PhishScan) and professional services. Revenue is primarily subscription-based recurring with select usage-based API and professional services streams. The company employs 101-250 people across US and Philippines offices and is led by President & CEO Jeff Finn.
zvelo firmographics
Firmographics- Name
- zvelo
- Legal name
- zvelo, Inc.
- Website
- https://zvelo.com
- Company type
- Public
- Founded year
- 1984
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- zvelo (OTCMKTS: ZVLO) builds proprietary AI-driven URL classification and threat intelligence feeds, licensing them to OEM security, ad tech, and communications partners via annual subscriptions. Its platform analyzes clickstream from 1B+ endpoints to power SASE, XDR, web filtering, and brand safety products.
- Ownership category
- akta.pro rank
zvelo industry classification
Industry- Product category
- Threat Intelligence & URL Classification
- NAICS
- Software Publishers (5132), Other Computer Related Services (541519)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industry
- Software-Defined Perimeter (SDP) / Zero Trust Network Access (ZTNA) (HDADABAC)
Keywords
Where zvelo is headquartered
LocationHeadquarters
- HQ city
- Greenwood Village
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
zvelo business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales
Revenue model
- Data Subscription Licensing (OEM): zvelo licenses URL database, threat intelligence, and categorization services to OEM partners on a subscription basis. Partners integrate zvelo data into their security, filtering, and brand safety products. This is the primary revenue model with 100% focus on OEM Channel.
- API/Cloud Services: Real-time API query services for URL categorization, phishing verification, and threat intelligence. Services include PhishScan for immediate phishing verification and zveloCAT for real-time classification.
- Professional Services: Custom data services, integration support, and specialized threat research for enterprise partners.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise OEM Subscription - Custom Pricing |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
zvelo product offering
Product offeringCore offering
zvelo provides AI-based URL classification databases and curated cyber threat intelligence feeds delivered on a 100% OEM channel basis. Its data services — including the zveloDB URL database, real-time zveloCAT classification engine, phishing and malicious IOC feeds, and SaaS application intelligence — are licensed to network security, ad tech, and communications vendors who embed zvelo intelligence into web filtering, SASE, XDR, ZTNA, DLP, and brand safety products.
Product overview
zvelo is a cybersecurity and web intelligence company offering a unified platform of URL classification and threat intelligence products. The core product is zveloDB™ URL Database (comprehensive URL classification) powered by the zveloCAT™ real-time classification engine. The zveloCTI™ Cyber Threat Intelligence suite includes PhishBlocklist™ (phishing feed), PhishScan™ (real-time API), and Malicious Detailed Detection Feed™ (malicious IOC enrichment), plus SaaS App Intelligence for SaaS application security. All products leverage proprietary AI/ML-based web classification and threat detection, combining clickstream data from 1 billion users/endpoints with OSINT and third-party feeds for comprehensive coverage across domains, full-path URLs, phishing threats, and malicious activities.
Differentiator
Problem solved
Functional benefit
Products and services
- zveloDB™ URL Database Industry-leading URL classification database providing comprehensive, real-time categorizations of domains, full-path URLs, and web content with 99.9% coverage and over 99% accuracy across 500+ categories and 200+ languages. Licensed to OEM partners for web filtering, DNS filtering, parental controls, and brand safety applications.
- zveloCAT™ Real-Time URL Classifications Real-time URL classification engine that categorizes web content instantly using AI-based threat detection and human-supervised machine learning at page-level granularity. Delivered as a cloud API query service for embedding into security products.
- zveloCTI™ Cyber Threat Intelligence Comprehensive cyber threat intelligence platform delivering curated phishing and malicious IOCs with claimed 30% better detection coverage than competing feeds. Powers SASE, SIEM, SOAR, and other security tools via raw data feeds.
- PhishBlocklist™ Curated phishing threat intelligence feed identifying unique phishing URLs enriched with metadata including date detected, targeted brand, and other attributes, designed to maximize protection while virtually eliminating false positives.
- PhishScan™ Cloud API query service providing real-time phishing verification lookups with immediate yes/no response as to whether a URL or IP is phishing. Targeted at email, SMS, and web surfing applications requiring instant verification.
- Malicious Detailed Detection Feed™ Curated malicious threat intelligence data feed identifying and enriching malicious IOCs with metadata attributes such as date detected, malware family, and key intelligence attributes for security analysis and enrichment.
- SaaS App Intelligence Advanced intelligence on SaaS applications providing data sensitivity risk assessments, categorizations, and insights to prevent data leakage and exfiltration. Empowers customers to control access to SaaS applications for DLP use cases.
Quantifiable outcome
- 30% better detection coverage than other threat intelligence feeds
- +4 more outcomes
Companies that use zvelo
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles4 records
zvelo technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability6 records
Feature8 records
zvelo partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered core, flagship and major.
- Internet Watch Foundation (IWF)coreNon-profit partnership dedicated to making the internet safer by tackling child sexual abuse content online. zvelo collaborates with IWF to contribute to efforts protecting children and making the web safer.
- National Center for Missing & Exploited Children (NCMEC)corePartnership supporting NCMEC's mission to find missing children and prevent child exploitation. zvelo contributes intelligence and categorization services to support child safety online.
- Anti-Phishing Working Group (APWG)coreIndustry consortium focused on unifying the global response to cybercrime. zvelo participates as member contributing phishing detection intelligence and industry expertise.
- Trend MicroflagshipEnterprise OEM partnership where Trend Micro integrates zvelo's URL database and threat intelligence into network security and endpoint protection products.
- ProofpointflagshipOEM integration of zvelo threat intelligence into Proofpoint's email and data security platforms for phishing detection and threat enrichment.
- Recorded FutureflagshipIntegration of zvelo threat intelligence into Recorded Future's security intelligence platform for threat enrichment.
- ESETmajorOEM integration of zvelo malicious detection and URL classification into ESET endpoint security solutions.
- TrellixmajorOEM integration for XDR (Extended Detection and Response) solutions incorporating zvelo threat intelligence.
- ZscalerflagshipIntegration of zvelo URL classification and threat intelligence into Zscaler's SASE (Secure Access Service Edge) cloud security platform.
- AWSflagshipCloud infrastructure partnership integrating zvelo threat intelligence services within AWS security offerings.
- InfobloxmajorIntegration of zvelo threat intelligence into Infoblox DNS infrastructure and security solutions.
- CognytemajorOEM integration of zvelo threat intelligence into Cognyte's security analytics platform.
Scale indicators9 records
Recent moves9 records
Expansion highlights5 records
zvelo competitors and assessment
Company assessmentDirect peers
- BrightCloud (Comcast): BrightCloud provides URL/IP reputation, web classification, and threat intelligence feeds sold to network security vendors and ISPs. It is the closest direct competitor to zvelo's zveloDB and zveloCTI offerings, with comparable OEM/channel-led go-to-market.
- Webroot (OpenText): Webroot's URL classification and reputation services power third-party security products for web filtering and endpoint protection. Like zvelo, it monetizes real-time threat intelligence data feeds to OEM partners across the cybersecurity ecosystem.
- Cyren: Cyren offers URL categorization, anti-phishing, and web security threat intelligence feeds used by security vendors and ISPs. It is a direct competitor in OEM-licensed URL/web threat data, especially in email and DNS security channels.
- Netcraft: Netcraft provides anti-phishing, cybercrime detection, and threat intelligence feeds focused on web/brand abuse. Its data services overlap directly with zvelo's PhishBlocklist and malicious detection feed products, particularly for brand protection and financial-sector customers.
- Kaspersky Threat Intelligence: Kaspersky offers URL reputation, phishing, and malicious IOC data feeds that integrate into security products. Comparable to zveloCTI in product structure and OEM-oriented threat data monetization.
- DomainTools: DomainTools provides DNS, WHOIS, and domain intelligence data feeds used for threat investigation and phishing response. It is comparable to zvelo in serving security OEMs and SOC teams with curated, infrastructure-level threat data.
Broad incumbents
- Cisco Talos: Cisco Talos is one of the largest commercial threat intelligence operations, offering URL/IP reputation feeds, IOC data, and threat research. It overlaps with zvelo at the OEM threat-feed layer but operates as part of Cisco's much broader security portfolio.
- Recorded Future (Mastercard): Recorded Future is a tier-1 threat intelligence platform used by enterprises and governments. It overlaps with zvelo in malicious IOC and phishing intelligence, but is much larger in scope and serves as both a zvelo partner and a competitive alternative.
- VirusTotal (Google): VirusTotal aggregates multiple URL/file scanning engines and reputation sources and is widely used by security teams. As a Google-owned broad incumbent, it offers an alternative free/cheap source of threat signal data to what zvelo sells commercially.
Emerging players
- URLhaus / abuse.ch: URLhaus is a community-driven malicious URL sharing project operated by abuse.ch. It is an open, lower-cost alternative for phishing and malware URL data, putting pricing pressure on commercial feeds like PhishBlocklist for budget-sensitive customers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
zvelo social profiles
Digital presencezvelo financial estimates
Financial estimateRevenue estimate
Valuation estimate
zvelo leadership team
Management profileNumber of profiles
Profiles7 records
zvelo funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
zvelo M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about zvelo
What does zvelo do?
zvelo provides AI-based URL classification databases and curated cyber threat intelligence feeds delivered on a 100% OEM channel basis. Its data services — including the zveloDB URL database, real-time zveloCAT classification engine, phishing and malicious IOC feeds, and SaaS application intelligence — are licensed to network security, ad tech, and communications vendors who embed zvelo intelligence into web filtering, SASE, XDR, ZTNA, DLP, and brand safety products.
Is zvelo a public or private company?
zvelo is a public company. It is classified as public and is currently operating.
When was zvelo founded?
zvelo was founded in 1984. It employs 101 to 250 people.
Where is zvelo based?
zvelo is headquartered in Greenwood Village, United States, in the North America region.
How does zvelo make money?
Three revenue lines are on record. Data Subscription Licensing (OEM) is the primary driver. The others are API/Cloud Services and professional Services.
Who are zvelo's main competitors?
Direct peers on record are BrightCloud (Comcast), Webroot (OpenText), Cyren, Netcraft, Kaspersky Threat Intelligence and DomainTools. Broad incumbents are Cisco Talos, Recorded Future (Mastercard) and VirusTotal (Google). URLhaus / abuse.ch is listed as an emerging player.
Does zvelo have an API?
Yes. zvelo offers a web categorization API for integrating URL classification services. The API enables real-time content categorization, malicious URL detection, and phishing verification. Integration is available via cloud API query service or raw data feeds. zvelo also provides PhishScan™ as a cloud API query service for real-time phishing verification lookups with immediate yes/no response for URLs/IPs. The services support enterprise and partner access for security tool enrichment (SIEM, SOAR, SASE). Developer documentation is at tools.zvelo.com.
What industry is zvelo in?
zvelo's product category is Threat Intelligence & URL Classification. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADABAC, Software-Defined Perimeter (SDP) / Zero Trust Network Access (ZTNA). Its NAICS code is 5132.