ThreatAware
ThreatAware is a London-based cybersecurity SaaS company offering an agentless Cyber Asset Attack Surface Management platform that integrates with 200+ security tools via API, providing enterprise customers in the UK, US, and Canada with unified asset visibility, security control validation, and automated remediation workflows.
- Company typePrivate
- Founded2018
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What ThreatAware does
ThreatAware is a London-headquartered, private cybersecurity SaaS company founded in 2018 that operates a Cyber Asset Attack Surface Management (CAASM) platform for large enterprise organizations. The platform is agentless and connects to customers' existing security and IT tools via API in under 30 minutes, ingesting data from 200+ integrations (EDR, SIEM, vulnerability management, MDM, ITSM, and identity systems including CrowdStrike, Microsoft Defender, Sentinel One, Sophos, and Tenable). Its core proprietary technology, patented Timeline Matching, creates device fingerprints by analyzing behavioral activity patterns across connected tools — uncovering 20–30% more assets than conventional methods and exposing 'stealth' devices invisible to individual security tools. The platform is sold as a three-tier subscription: Connect (asset visibility), Discover (security control validation), and Protect (full platform with automated remediation workflows and AI-powered reporting).
The company serves enterprise customers primarily in the UK, US, and Canada, with named customers spanning retail (Sainsbury's, Ocado, Harrods, AO World, Tate), financial services (BGF, Euronet), legal (Bird & Bird, Institute of Directors), healthcare/research (Wellcome Trust), charity (RNLI), and manufacturing (James Jones). ThreatAware grew to 100+ clients while bootstrapped and profitable, without any external capital, before raising its first funding round — a $25 million Series A from growth equity firm One Peak in February 2026 — to scale North American operations and accelerate product development, including the launch of an AI-Powered Security Workspace ('Labs') that lets security teams build custom applications via natural language prompts. The company maintains ISO 27001 and Cyber Essentials certifications, is GDPR and CCPA compliant, and supports compliance frameworks including DORA, ISO 27001, NIST CSF, and Cyber Essentials Plus for its customers.
ThreatAware firmographics
Firmographics- Name
- ThreatAware
- Legal name
- ThreatAware Ltd
- Website
- https://threataware.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ThreatAware is a London-based cybersecurity SaaS company offering an agentless Cyber Asset Attack Surface Management platform that integrates with 200+ security tools via API, providing enterprise customers in the UK, US, and Canada with unified asset visibility, security control validation, and automated remediation workflows.
- Ownership category
- akta.pro rank
ThreatAware industry classification
Industry- Product category
- Cyber Asset Attack Surface Management (CAASM) Software
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Guards and Patrol Services (561612), Security Systems Services (56162), Investigation, Guard, and Armored Car Services (56161), Investigation and Security Services (5616)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG), Fraud Risk & Financial Crime Controls Advisory (BPAKADAL), Insider Threat Program Design & Risk Assessments (BPAKADAM), Deception Technology & Threat Hunting (HDADAGAI)
Keywords
Where ThreatAware is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
ThreatAware business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Platform Subscription: ThreatAware operates as a cloud-based SaaS platform with subscription pricing. The platform offers three tiers: Connect (comprehensive asset visibility), Discover (security control validation), and Protect (complete platform with automated workflows and AI reporting). Pricing is quote-based and likely structured per organization or tier.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Connect - Comprehensive Asset Visibility |
| Subscription | Annual | Discover - Security Control Validation |
| Subscription | Annual | Protect - Complete Security Platform |
Go-to-market motion3 records
Distribution channels1 record
Marketing channels8 records
ThreatAware product offering
Product offeringCore offering
ThreatAware is a cloud-based Cyber Asset Management platform that integrates via API with an organization's existing security and IT tools to provide a single, unified inventory of every device and to validate that security controls are installed, operational and effective. It is sold as a three-tier SaaS subscription (Connect, Discover, Protect) using patented Timeline Matching technology to discover 20-30% more assets than conventional methods, and includes automated remediation workflows and AI-powered reporting for cyber hygiene, CAASM, and compliance use cases.
Product overview
ThreatAware is a unified Cyber Asset Intelligence Platform architected as a three-tier subscription model: Connect (foundation tier for comprehensive asset visibility and discovery), Discover (mid-tier adding security control validation to confirm agents are functioning correctly), and Protect (full platform with automated remediation workflows and AI Advanced Reporting for proactive defense). The platform centers on patented Timeline Matching technology that discovers 20-30% more assets than conventional methods by creating unique device fingerprints. Protect is the premium tier including an Action Centre for closed-loop remediation and exclusive access to AI-powered features. The platform integrates with 200+ security and IT tools via API, requires no agents, and deploys in under 30 minutes.
Differentiator
Problem solved
Functional benefit
Products and services
- ThreatAware Connect Subscription tier that discovers every device in the corporate environment by connecting to existing security tools via API, using patented timeline-matching technology to identify devices and eliminate duplicates.
- ThreatAware Discover Subscription tier that validates that security agents (EDR, MFA, encryption, patching, etc.) are deployed, functioning and properly configured, exposing silent failures where tools appear healthy but are not protecting devices.
- ThreatAware Protect Full-platform subscription tier delivering complete cyber asset management with automated remediation workflows (Action Centre), AI Advanced Reporting, and proactive defense capabilities for enterprise customers.
Quantifiable outcome
- Discovers 10% of devices that are completely undetected by existing security tools
- +5 more outcomes
Companies that use ThreatAware
Customer profileNamed customers12 records
Segments3 records
Ideal customer profiles2 records
ThreatAware technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration207 records
AI capability6 records
Feature7 records
ThreatAware partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered strategic and supporting.
- TinesstrategicIntegration partnership enabling Bird & Bird to trigger automated security workflows in Tines for immediate remediation when ThreatAware surfaces security gaps. Key factor in Bird & Bird's platform selection decision, allowing automated responses without manual intervention.
- Gartner Peer InsightssupportingCompany maintains presence on Gartner Peer Insights platform showcasing customer reviews and ratings in the Cyber Asset Attack Surface Management category, influencing enterprise buying decisions.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
ThreatAware competitors and assessment
Company assessmentDirect peers
- Axonius: Axonius is the leading dedicated Cyber Asset Attack Surface Management (CAASM) platform and ThreatAware's closest direct competitor. Both platforms correlate asset and security control data from existing tools, target enterprise CISOs, and compete in the same Gartner Peer Insights CAASM category.
- Claroty: Claroty provides asset visibility and security control validation primarily for operational technology and cyber-physical systems, with xDome extending into IT asset management. It overlaps ThreatAware's CAASM positioning for organizations that require unified IT/OT visibility, including enterprise security operations teams.
- Armis: Armis offers an asset intelligence platform that discovers devices, validates security controls, and monitors managed/unmanaged/IoT/OT/IoMT assets. It competes head-to-head with ThreatAware on enterprise CAASM buying cycles and asset visibility use cases.
- JupiterOne: JupiterOne is a CAASM platform that aggregates cyber asset data from cloud, endpoint, identity, and SaaS sources into a unified graph. It is a direct competitor to ThreatAware in mid-market and enterprise security operations, with overlapping compliance and asset inventory use cases.
- runZero: runZero provides asset inventory and exposure management with active scanning, agentless discovery, and OT/IoT coverage. It competes with ThreatAware on enterprise asset discovery, particularly for organizations that need scan-based visibility in addition to API correlation.
- Noetic Cyber: Noetic Cyber delivers a CAASM platform focused on continuous asset inventory, security control coverage, and automated remediation workflows. It directly competes with ThreatAware's Discover and Protect tiers on security posture management and compliance mapping.
- Sevco Security: Sevco Security provides an asset intelligence platform that unifies endpoint, vulnerability, identity, and configuration data for IT and security operations teams. It is a direct CAASM peer competing for similar enterprise buyers and use cases as ThreatAware.
Broad incumbents
- Wiz: Wiz is a cloud security platform with strong cloud asset and security posture visibility that increasingly overlaps with CAASM buying decisions. While focused on cloud, Wiz's breadth, scale, and agentless model make it a broader incumbent whose capabilities intersect ThreatAware's IT estate visibility story.
- Tenable: Tenable offers enterprise vulnerability management and asset inventory via Tenable One, an exposure management platform that competes for security operations budgets. ThreatAware integrates with Tenable but Tenable's broader portfolio is a partial substitute for organizations consolidating on a single exposure platform.
- CrowdStrike: CrowdStrike's Falcon platform combines endpoint protection with asset discovery, identity threat detection, and exposure management. As a major integration partner for ThreatAware, CrowdStrike also competes indirectly by offering native asset visibility that could reduce the need for a dedicated CAASM layer in some customer environments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
ThreatAware social profiles
Digital presenceThreatAware compliance and trust
Trust signalCompliance10 records
ThreatAware financial estimates
Financial estimateRevenue estimate
Valuation estimate
ThreatAware leadership team
Management profileNumber of profiles
Profiles12 records
ThreatAware funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ThreatAware M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ThreatAware
What does ThreatAware do?
ThreatAware is a cloud-based Cyber Asset Management platform that integrates via API with an organization's existing security and IT tools to provide a single, unified inventory of every device and to validate that security controls are installed, operational and effective. It is sold as a three-tier SaaS subscription (Connect, Discover, Protect) using patented Timeline Matching technology to discover 20-30% more assets than conventional methods, and includes automated remediation workflows and AI-powered reporting for cyber hygiene, CAASM, and compliance use cases.
Is ThreatAware a public or private company?
ThreatAware is a private company. It is classified as venture growth investor backed and is currently operating.
When was ThreatAware founded?
ThreatAware was founded in 2018. It employs 11 to 50 people.
Where is ThreatAware based?
ThreatAware is headquartered in London, United Kingdom, in the Europe region.
How does ThreatAware make money?
One revenue line is on record: saaS Platform Subscription.
Who are ThreatAware's main competitors?
Direct peers on record are Axonius, Claroty, Armis, JupiterOne, runZero, Noetic Cyber and Sevco Security. Broad incumbents are Wiz, Tenable and CrowdStrike.
Does ThreatAware have an API?
Yes. ThreatAware connects to existing security and IT tools via API integrations. The platform uses API connections to gather data from security tools and display unified, actionable intelligence. Setup takes 2-5 minutes per integration, providing read-only access with no risk to the environment. An on-premise connector is available for internal tools. Developer documentation is at threataware.com/integrations.
What industry is ThreatAware in?
ThreatAware's product category is Cyber Asset Attack Surface Management (CAASM) Software. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE). Its NAICS code is 561621 and its SIC code is 7381.