Mitigant
Mitigant is a Potsdam-based German cybersecurity startup that provides a multi-cloud Adversarial Exposure Validation platform — combining Cloud Attack Emulation, CSPM, KSPM, and GenAI/AI Red Teaming — for AWS, Azure, GCP, and Kubernetes environments, sold via self-serve PLG and direct enterprise motion.
- Company typePrivate
- Founded2021
- HeadquartersPotsdam, Germany
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Mitigant does
Mitigant GmbH (rebranded from Resility GmbH in 2023) is a Potsdam-based German cybersecurity company founded in 2021 that operates an Adversarial Exposure Validation platform for multi-cloud environments. Its product surface spans four core modules — Cloud Attack Emulation (CAE) for safe, reversible adversary simulation mapped to MITRE ATT&CK and MITRE ATLAS; Cloud Security Posture Management (CSPM) for continuous misconfiguration and compliance monitoring; Kubernetes Security Posture Management (KSPM) for container and cluster security; and Security for GenAI for AI workload validation — augmented by six purpose-built solutions (AI Red Teaming, Cloud Penetration Testing, Detection Validation, SOC Team Optimization, Continuous Compliance, Incident Readiness) and developer-facing capabilities including Attack-as-Code, an Attack API, GitHub Actions integration, and the recently launched Attack Builder. Underlying the platform is a Security Chaos Engineering methodology, 500+ pre-built attack scenarios across AWS, Azure, GCP and Kubernetes, and AI-driven analysis (notably using Google's Gemini, per the 2025 Google for Startups Growth Academy case study) to translate raw findings into prioritized remediation, Sigma detection rules, and executive reporting.
Mitigant operates a hybrid go-to-market: a product-led growth motion anchored by a 30-day free trial and demo environment (no credit card required), paired with a direct enterprise sales motion for large organizations requiring custom attack scenarios, multi-cloud emulations, AI Red Teaming, and API access, and a partner channel for MSPs, MSSPs, consultants and resellers. Pricing is structured in three monthly subscription tiers — Basic (50 attacks, 1,000 cloud resources), Standard (100 attacks, 10,000 resources), and Enterprise (200 attacks, unlimited compliance) — with a 20% multi-product discount, positioning the product broadly from early-stage startups through large enterprises. EU-based positioning, German data sovereignty, and first-class support for NIS2, DORA, BSI-C5 and GDPR are core to the value proposition for regulated European buyers.
Commercially, Mitigant remains very early-stage: headcount is reported at 1–10 employees, revenue is not publicly disclosed, and capitalization to date appears to come exclusively from non-dilutive German federal and Brandenburg state grants (BIG FuE 2022–2024, StartUpSecure/BMBF 2022, BIF 2023, Gründung Innovativ 2024–2026) plus a 2021 seed involving adesso ventures, Brandenburg Kapital and HTGF. The named customer base skews toward small startups and SMBs (Nooxit, Notch, Mitto, Adair, MontBlancAI, TechMiners) with a small number of mid-market and enterprise accounts (KM.ON Asia, DAMOVO, adesso, GlobalDots). Distribution leverage has been augmented by selection into the Google for Startups Growth Academy: AI for Cybersecurity program (Feb 2025) and by research outputs referenced by Splunk in its AWS Bedrock Security Analytics Story.
Mitigant firmographics
Firmographics- Name
- Mitigant
- Legal name
- Mitigant GmbH
- Website
- https://mitigant.io
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Mitigant is a Potsdam-based German cybersecurity startup that provides a multi-cloud Adversarial Exposure Validation platform — combining Cloud Attack Emulation, CSPM, KSPM, and GenAI/AI Red Teaming — for AWS, Azure, GCP, and Kubernetes environments, sold via self-serve PLG and direct enterprise motion.
- Ownership category
- akta.pro rank
Mitigant industry classification
Industry- Product category
- Cloud-Native Security Validation / Adversarial Exposure Validation
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- Cloud Network Security (Microsegmentation, Cloud Firewall) (HDADADAH), Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
Keywords
Where Mitigant is headquartered
LocationHeadquarters
- HQ city
- Potsdam
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Mitigant business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Cloud Attack Emulation (CAE) Subscription: SaaS subscription model for cloud attack emulation with tiered pricing based on number of attacks per month (50-200 attacks). Includes cloud pentest quota, custom attack scenarios, multi-cloud attacks, and Attack API access.
- Cloud Security Posture Management (CSPM) Subscription: SaaS subscription for cloud security posture management with tiered pricing based on cloud resource count (1000-10000+ resources). Includes compliance standards, drift analysis, and vulnerability prioritization.
- Kubernetes Security Posture Management (KSPM) Subscription: SaaS subscription for Kubernetes security with tiered pricing based on node count (50-70+ nodes). Includes image registry scanning and container security monitoring.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Basic tier for early-stage startups with 50 attacks and 1000 cloud resources |
| Subscription | Monthly | Standard tier for mid-phase startups and SMEs with 100 attacks and 10000 cloud resources |
| Subscription | Monthly | Enterprise tier for large enterprises and scale-ups with 200 attacks and unlimited compliance |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels9 records
Mitigant product offering
Product offeringCore offering
Mitigant provides an AI-powered Adversarial Exposure Validation SaaS platform that continuously validates cloud security across AWS, Azure, GCP, and Kubernetes. It combines Cloud Attack Emulation (CAE) — 500+ plug-and-play, safe, reversible attacks mapped to MITRE ATT&CK/ATLAS — with Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Security for GenAI, plus an Attack-as-Code API for CI/CD integration.
Product overview
Mitigant is an EU-based, German-built Adversarial Exposure Validation platform that provides a unified multi-cloud security solution across AWS, Azure, Google Cloud, and Kubernetes. The platform consists of four core products: Cloud Attack Emulation (CAE) for safe, reversible attack simulation mapped to MITRE ATT&CK/ATLAS; Cloud Security Posture Management (CSPM) for continuous compliance monitoring; Kubernetes Security Posture Management (KSPM) for container security; and Security for GenAI for AI workload protection. These core modules are complemented by six purpose-built solution modules: AI Red Teaming, Cloud Penetration Testing, Detection Validation, SOC Team Optimization, Continuous Compliance, and Incident Readiness. The platform is offered in three tiers (Basic, Standard, Enterprise) with cloud-specific variants for AWS, Azure, and Kubernetes. Key features include Attack-as-Code for CI/CD integration, Attack Scheduler for automated execution, Attack Builder for custom attack creation, and AI-powered analysis for attack reporting and remediation guidance.
Differentiator
Problem solved
Functional benefit
Products and services
- Cloud Attack Emulation (CAE) Adversarial Exposure Validation platform that proactively verifies cloud infrastructure's resilience against cloud attacks using safe, reversible attack emulation mapped to MITRE ATT&CK and MITRE ATLAS. Includes 500+ plug-and-play attacks, AI-powered analysis, Sigma detection rules, and an Attack Builder for custom attacks.
- Cloud Security Posture Management (CSPM) Continuous cloud security and compliance monitoring across CIS Benchmarks, NIS2, DORA, NIST, PCI-DSS, SOC 2, and more, with drift analysis, inventory management, and automated assessments for AWS, Azure, and GCP.
- Kubernetes Security Posture Management (KSPM)
- Security for GenAI
- AI Red Teaming
- Cloud Penetration Testing Streamlined cloud penetration testing solution that enables organizations to run cloud penetration tests without waiting months, with bundled pentest quotas per tier and integration with Prowler and Wiz CSPM.
- Detection Validation
- SOC Team Optimization
- Continuous Compliance
- Incident Readiness
Quantifiable outcome
- Validates cloud security gaps up to 5X faster with Gemini
- +3 more outcomes
Companies that use Mitigant
Customer profileNamed customers12 records
Segments4 records
Ideal customer profiles4 records
Mitigant technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration21 records
AI capability6 records
Feature9 records
Mitigant partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered flagship, core and minor.
- Google for StartupsflagshipMitigant selected for Google for Startups Growth Academy: AI for Cybersecurity program. Google provides mentorship, industry expert support, and has published a case study showing Mitigant validates cloud security gaps up to 5X faster with Gemini. Program supports startups worldwide leveraging AI for cybersecurity.
- AWS (Amazon Web Services)coreDeep integration with AWS for cloud attack emulation, CSPM, and AI Red Teaming. Supports AWS services including IAM, S3, Bedrock, SecretManager, and more. MITRE ATT&CK technique coverage for AWS environments.
- Microsoft AzurecoreFull cloud attack emulation and CSPM support for Azure environments including EntraID, storage accounts, virtual machines, and Kubernetes services.
- Google Cloud PlatformcoreCloud attack emulation and security posture management support for Google Cloud Platform environments.
- KubernetescoreKubernetes Security Posture Management (KSPM) with vulnerability prioritization, image registry scanning, and continuous asset inventory for Kubernetes environments.
- CISPAminorOne of four startup incubators supporting Mitigant through the StartUpSecure initiative. Located in Saarbrücken, Germany.
- ATHENE DarmstadtflagshipPrimary startup incubator supporting Mitigant through the StartUpSecure initiative. Mitigant accesses BMBF funding through this center.
- KASTEL KarlsruheminorOne of four startup incubators supporting Mitigant through the StartUpSecure initiative. Located in Karlsruhe, Germany.
- Ruhr-Universität Bochum (CUBE5)minorOne of four startup incubators supporting Mitigant through the StartUpSecure initiative. Located in Bochum, Germany.
- MITRE (ATT&CK/ATLAS)coreAll attack scenarios mapped to MITRE ATT&CK and MITRE ATLAS frameworks for standardized threat modeling and detection engineering.
Scale indicators9 records
Recent moves7 records
Expansion highlights6 records
Mitigant competitors and assessment
Company assessmentDirect peers
- Orca Security: Agentless cloud security platform providing CSPM, CWPP, and compliance across AWS, Azure, GCP, and Kubernetes. Sidewinder competitor in the European mid-market on cloud-native agentless security.
- Aqua Security: Cloud-native application protection platform (CNAPP) specialist in Kubernetes/container security. Closely comparable KSPM/Kubernetes attack-emulation capability to Mitigant's Kubernetes Security Posture Management.
- SafeBreach: Breach and Attack Simulation (BAS) platform validating security controls against real-world attacks. Closest peer to Mitigant's Cloud Attack Emulation product in continuous security validation methodology.
- Cymulate: Exposure management and BAS vendor offering continuous threat exposure validation across cloud, endpoint, and email. Competes with Mitigant on the BAS-adjacent positioning for enterprise security teams.
- Lacework: Agent-based cloud security platform (Polygraph) for AWS, Azure, GCP, and Kubernetes with anomaly-driven posture. Competes with Mitigant on cloud-native security validation, particularly in mid-market and enterprise segments.
- AttackIQ: Adversarial Exposure Validation platform built on MITRE ATT&CK, offering continuous security control validation. Comparable to Mitigant's CAE and Detection Validation modules in approach and buyer (security validation leads).
- Sysdig: Cloud security built on Falco runtime detection, offering CSPM, CWPP, and Kubernetes threat detection. Comparable in Kubernetes/cloud-native depth and runtime-validation adjacency.
Broad incumbents
- Wiz: Cloud security platform leader in CNAPP/CSPM, recently acquired by Google for ~$32B. Direct integration partner of Mitigant; competes on cloud posture and increasingly on validation/attack-path analysis across AWS, Azure, GCP, and Kubernetes.
- CrowdStrike Falcon Cloud Security: Agent-based cloud workload protection and posture management bundled with the Falcon platform. Competes on agent depth and integrated SOC tooling; adjacent to Mitigant's agentless validation approach.
- Palo Alto Networks (Prisma Cloud / Cortex): Prisma Cloud is a CNAPP platform with CSPM and CWPP; Cortex XSIAM/XDR bundles BAS-style validation. Largest incumbent Mitigant competes against on cloud-native security validation, and collaborator via Palo Alto Unit 42.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Mitigant social profiles
Digital presenceMitigant compliance and trust
Trust signalCompliance6 records
Mitigant financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mitigant leadership team
Management profileNumber of profiles
Profiles3 records
Mitigant funding detail
Funding detailFunding overview
Funding rounds1 record
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mitigant M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mitigant
What does Mitigant do?
Mitigant provides an AI-powered Adversarial Exposure Validation SaaS platform that continuously validates cloud security across AWS, Azure, GCP, and Kubernetes. It combines Cloud Attack Emulation (CAE) — 500+ plug-and-play, safe, reversible attacks mapped to MITRE ATT&CK/ATLAS — with Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Security for GenAI, plus an Attack-as-Code API for CI/CD integration.
Is Mitigant a public or private company?
Mitigant is a private company. It is classified as venture growth investor backed and is currently operating.
When was Mitigant founded?
Mitigant was founded in 2021. It employs 1 to 10 people.
Where is Mitigant based?
Mitigant is headquartered in Potsdam, Germany, in the Europe region.
How does Mitigant make money?
Three revenue lines are on record. Cloud Attack Emulation (CAE) Subscription is the primary driver. The others are cloud Security Posture Management (CSPM) Subscription and kubernetes Security Posture Management (KSPM) Subscription.
Who are Mitigant's main competitors?
Direct peers on record are Orca Security, Aqua Security, SafeBreach, Cymulate, Lacework, AttackIQ and Sysdig. Broad incumbents are Wiz, CrowdStrike Falcon Cloud Security and Palo Alto Networks (Prisma Cloud / Cortex).
Does Mitigant have an API?
Yes. Mitigant provides an Attack API that enables agile attack orchestration and Attack-as-Code capabilities. The API allows security teams to integrate adversary emulation into Detection-as-Code (DaC) pipelines, automate attack execution on daily, weekly, or monthly schedules, and programmatically orchestrate security validation tasks. Built on the Mitigant API and leveraging GitHub Actions, Attack-as-Code brings software engineering principles to offensive security, enabling repeatability, consistency, and manageability of security testing. Developer documentation is at mitigant.io/en/platform.
What industry is Mitigant in?
Mitigant's product category is Cloud-Native Security Validation / Adversarial Exposure Validation. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of HDADADAH, Cloud Network Security (Microsegmentation, Cloud Firewall). Its NAICS code is 5415 and its SIC code is 7372.