TrustedSec
TrustedSec is a privately held Ohio-based cybersecurity consultancy founded in 2012, providing penetration testing, red teaming, incident response, Active Directory security, and AI cybersecurity advisory to enterprise and government clients, supported by a portfolio of 52 open-source security tools.
- Company typePrivate
- Founded2012
- HeadquartersStrongsville, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What TrustedSec does
TrustedSec, LLC is a privately held cybersecurity consulting firm founded in 2012 by David Kennedy, headquartered in Fairlawn, Ohio. The firm delivers professional security services across four practice areas — Design, Evaluate, Harden, and Respond — including penetration testing, red teaming, incident response, cloud security architecture, Active Directory security, and (as of 2025) AI cybersecurity consulting. Its delivery model is staff-intensive advisory work: clients engage TrustedSec for time-boxed assessments, retainer-based incident response, and continuous security advisory, with engagement scope and price quoted per project. The firm is notable for maintaining 52 open-source security tools, the most prominent being the Social-Engineer Toolkit (SET), which has exceeded 2 million downloads and functions as both a community asset and an inbound demand-generation channel.
TrustedSec serves a mix of regulated enterprises and government agencies, with named clients spanning financial services (KeyBank), healthcare (CareSource), consumer products (SharkNinja), trust services (Equity Trust, 8451, Speedeon), and federal defense (United States Marines), and has completed more than 7,400 custom engagements since inception. The company reports a 92% Net Promoter Score, reflecting strong client retention and referral economics typical of high-trust professional services. It is bootstrapped, with no disclosed outside funding, and pursues growth through a combination of organic service-line expansion, selective acquisitions (Trimarc Security, March 2025), credentialing (CREST, April 2025), and senior talent hires (Ryan Macfarlane, former FBI). Revenue is generated entirely through fee-for-service engagements and subscription retainers; pricing is quote-based and varies with engagement type and complexity.
TrustedSec firmographics
Firmographics- Name
- TrustedSec
- Legal name
- TrustedSec, LLC
- Website
- https://trustedsec.com
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- TrustedSec is a privately held Ohio-based cybersecurity consultancy founded in 2012, providing penetration testing, red teaming, incident response, Active Directory security, and AI cybersecurity advisory to enterprise and government clients, supported by a portfolio of 52 open-source security tools.
- Ownership category
- akta.pro rank
TrustedSec industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Computer Systems Design and Related Services (54151), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industries
- Insider Threat Program Design & Risk Assessments (BPAKADAM), Email Phishing & BEC Protection (HDADAKAB)
Keywords
Where TrustedSec is headquartered
LocationHeadquarters
- HQ city
- Strongsville
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
TrustedSec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Professional Security Consulting Services: TrustedSec generates revenue through custom security consulting engagements. Services include design (security program development), evaluate (security assessments), harden (security improvements), and respond (incident response). These are project-based and subscription consulting engagements tailored to client needs across various security domains.
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
TrustedSec product offering
Product offeringCore offering
TrustedSec is a professional cybersecurity consulting firm that delivers custom security services across four practice lines: Design (security program development), Evaluate (penetration testing, red team, and security assessments), Harden (infrastructure and cloud hardening), and Respond (incident response). The firm supplements its consulting with a portfolio of 52 open-source offensive security tools and offers specialized Active Directory, cloud, and AI security consulting for enterprise and government clients.
Product overview
TrustedSec is a cybersecurity consulting firm founded in 2012 by David Kennedy, offering professional security services organized around four service lines: Design, Evaluate, Harden, and Respond. The company maintains an open-source portfolio of 12 security tools including the Social Engineering Toolkit (SET), Specula, JS-Tap, WPUPDATE, TScopy, TAP, SPRAYWMI, SPOONMAP, SIMPLYEMAIL, SHIPS, RISINGSUN, and RID_ENUM. In March 2025, TrustedSec acquired Trimarc Security, an Active Directory security company, integrating its services and founder Sean Metcalf into the organization.
Differentiator
Problem solved
Functional benefit
Products and services
- Design Services Custom security program design service where TrustedSec security experts partner with clients to build tailored cybersecurity programs aligned to organizational risk and objectives. For leadership, operations, infrastructure, and assurance teams.
- Evaluate Services Security program evaluation service that uses proven assessment methodologies including penetration testing, red team engagements, security assessments, and attack path effectiveness evaluations. For enterprise and government clients seeking to validate security posture.
- Harden Services Security program hardening service focused on remediating vulnerabilities, hardening Active Directory and cloud environments, securing backups against ransomware, and implementing core security controls frameworks. For infrastructure and IT teams.
- Respond Services Threat response and incident response service delivered by experts including former FBI cyber agents, providing 24/7 incident response, threat containment, eradication, and recovery. For security operations and SOC teams facing active breaches.
- AI Cybersecurity Consulting Cybersecurity consulting services focused on securing AI systems, governing AI adoption, and defending against threat actors already using AI, while preserving human judgment in security operations. For enterprise security and risk leaders.
- Social Engineering Toolkit (SET) An open-source Python-driven tool for social-engineering penetration testing, created by TrustedSec founder David Kennedy. The toolkit has over two million downloads and is the industry-standard framework for social engineering tests. For penetration testers and red team operators.
Quantifiable outcome
- 7,400+ custom security engagements completed
- +3 more outcomes
Companies that use TrustedSec
Customer profileNamed customers8 records
Segments6 records
Ideal customer profiles3 records
TrustedSec technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature12 records
TrustedSec partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core, flagship and minor.
- Trimarc SecuritycoreTrustedSec acquired Trimarc Security, an Active Directory security company. All Trimarc services are now provided through TrustedSec, with CEO Sean Metcalf joining TrustedSec. The integration enhances TrustedSec's capabilities in identity security, cloud hardening, and advanced attack prevention. Trimarc founder Sean Metcalf is a Microsoft Certified Master in Active Directory and brings deep knowledge of Active Directory security, Microsoft cloud environments, and identity-based attack defense.
- Cleveland CavaliersflagshipTrustedSec serves as the Official Cybersecurity Partner for the Cleveland Cavaliers since 2019. They protect the arena's free Wi-Fi, local area network, and Cavs online and digital ecosystem including 11 web properties and two mobile apps. The partnership includes TrustedSec logo featured on the Cleveland Monsters (AHL) helmet and showcases the TrustedSec brand to diverse audiences on local, national, and international levels.
- Binary DefenseminorTrustedSec co-hosts webinars with Binary Defense, including 'Offense Meets Defense: A Candid Conversation on AI in Detection Engineering'. Joint webinar focused on bringing together offensive and defensive practitioners to explore how AI is reshaping detection engineering.
- GitHubcoreTrustedSec publishes 52 open-source security tools on GitHub including the Social Engineering Toolkit, JS-Tap, Specula, RisingSun, SHIPS, TScopy, SPOoNMAP, SPRAYWMI, SimplyEmail, RID_ENUM, WPUpdate, and the TrustedSec Attack Platform. GitHub serves as the primary distribution platform for their open-source tool portfolio.
Scale indicators8 records
Recent moves5 records
Expansion highlights5 records
TrustedSec competitors and assessment
Company assessmentBroad incumbents
- Palo Alto Networks Unit 42: Palo Alto Networks' threat intelligence and incident response consulting arm. Comparable IR and offensive security services but embedded within a major security platform vendor with substantially greater resources.
- Optiv: Large cybersecurity solutions integrator offering advisory, implementation, and managed security services. Overlaps with TrustedSec's advisory and assessment offerings but operates at broader scale with product resale as a core motion.
- Mandiant (Google Cloud): Now part of Google Cloud, Mandiant is a leading incident response and threat intelligence firm with deep offensive security capabilities. Comparable incident response and adversary simulation services, but at significantly greater scale and broader portfolio.
- CrowdStrike Services: CrowdStrike's services arm provides incident response, proactive services, and tabletop exercises alongside its dominant endpoint platform. Overlaps with TrustedSec's incident response and assessment practice but as part of a broader security platform offering.
Direct peers
- NCC Group: Global cybersecurity consulting firm offering penetration testing, red teaming, and incident response services. Larger-scale peer in the same offensive security category, serving similar enterprise clients.
- Specter Ops: Offensive security consultancy focused on Active Directory, identity attack paths, and adversary simulation. Strong overlap with TrustedSec's identity security practice, particularly post-Trimarc acquisition, with comparable services and customer base.
- Coalfire: Cybersecurity advisory and assessment firm offering penetration testing, compliance assessments (PCI, HITRUST, FedRAMP), and risk advisory. Comparable to TrustedSec's assurance and evaluation services, particularly in regulated verticals.
- Black Hills Information Security: Boutique penetration testing and adversary simulation firm known for community content, webinars, and training. Comparable to TrustedSec's expertise-led, community-driven GTM and offensive security focus.
- Bishop Fox: Elite offensive security consulting firm specializing in penetration testing, red teaming, and adversary simulation for Fortune 500 clients. Closest direct peer to TrustedSec given shared boutique positioning, expertise-led GTM, and similar enterprise customer profile.
- Red Siege: Offensive security consultancy providing penetration testing, red team operations, and adversary emulation. Direct peer in size, service mix, and target market for offensive security engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
TrustedSec social profiles
Digital presenceTrustedSec compliance and trust
Trust signalCompliance1 record
TrustedSec financial estimates
Financial estimateRevenue estimate
Valuation estimate
TrustedSec leadership team
Management profileNumber of profiles
Profiles7 records
TrustedSec subsidiaries and ownership
Company hierarchySubsidiaries1 record
TrustedSec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TrustedSec M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TrustedSec
What does TrustedSec do?
TrustedSec is a professional cybersecurity consulting firm that delivers custom security services across four practice lines: Design (security program development), Evaluate (penetration testing, red team, and security assessments), Harden (infrastructure and cloud hardening), and Respond (incident response). The firm supplements its consulting with a portfolio of 52 open-source offensive security tools and offers specialized Active Directory, cloud, and AI security consulting for enterprise and government clients.
Is TrustedSec a public or private company?
TrustedSec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was TrustedSec founded?
TrustedSec was founded in 2012. It employs 1 to 10 people.
Where is TrustedSec based?
TrustedSec is headquartered in Strongsville, United States, in the North America region.
How does TrustedSec make money?
One revenue line is on record: professional Security Consulting Services.
Who are TrustedSec's main competitors?
Broad incumbents on record are Palo Alto Networks Unit 42, Optiv, Mandiant (Google Cloud) and CrowdStrike Services. Direct peers are NCC Group, Specter Ops, Coalfire, Black Hills Information Security, Bishop Fox and Red Siege.
Does TrustedSec have an API?
No public API is recorded for TrustedSec.
What industry is TrustedSec in?
TrustedSec's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAKADAM, Insider Threat Program Design & Risk Assessments. Its NAICS code is 54151 and its SIC code is 8742.