Anvil Secure
Bespoke, employee-owned penetration testing and security consulting firm headquartered in Seattle, serving top-tier US technology companies through customized application, cloud, embedded systems, AI, and post-quantum cryptography security engagements delivered by a globally distributed expert team.
- Company typePrivate
- Founded2016
- HeadquartersSeattle, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Anvil Secure does
Anvil Secure is an employee-owned, Seattle-headquartered information security consulting firm that delivers bespoke penetration testing and security research services to large technology and internet providers. The company was founded in 2016 by Chris Elbring as Anvil Ventures, rebranded to Anvil Secure, and converted to a Washington State C Corporation in 2019 to extend equity participation to all employees through an Employee Stock Incentive Plan. Core offerings span application and cloud security, embedded systems and firmware security, and a growing portfolio of specialized assessments covering AI security testing, post-quantum cryptography (PQC) reviews, OCP SAFE testing, Microsoft UEFI reviews, and Oracle environment penetration testing. The firm invests heavily in research-driven thought leadership, publishing whitepapers, technical blog content, and approximately fifteen open-source security tools on GitHub (including CrownJewelScanner, PQCscan, HANAlyzer, and the LLM-powered ByteBanter Burp extension), and operates an internal workflow and reporting platform called Nexus that integrates AI-enabled features gated by client consent. Anvil monetizes exclusively through professional services engagements that are individually scoped and quote-priced via direct sales conversations and intake forms, with multi-year contracts and NDA/MSA execution preceding project commencement. The firm claims nearly all of the Top 10 US technology companies as clients and 8 of the Fortune 40 by end of 2018, signed its first seven-figure deal in 2019, ranked #303 on the Inc. 5000 in 2022 with reported 1,880% three-year revenue growth, and operates a global delivery model anchored by its Seattle headquarters and an Amsterdam EU subsidiary established in 2019.
Anvil Secure firmographics
Firmographics- Name
- Anvil Secure
- Legal name
- Anvil Ventures, LLC
- Website
- https://anvilsecure.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Bespoke, employee-owned penetration testing and security consulting firm headquartered in Seattle, serving top-tier US technology companies through customized application, cloud, embedded systems, AI, and post-quantum cryptography security engagements delivered by a globally distributed expert team.
- Ownership category
- akta.pro rank
Anvil Secure industry classification
Industry- Product category
- Cybersecurity Consulting
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Anvil Secure is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Anvil Secure business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Bespoke Penetration Testing and Security Consulting: Anvil Secure generates revenue exclusively through professional services engagements, primarily bespoke penetration testing across applications, cloud, embedded systems, and specialized domains. Each engagement is tailored and individually scoped, representing a custom consulting engagement with pricing determined through direct sales conversations and intake forms.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom professional services engagement — no published tiers |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Anvil Secure product offering
Product offeringCore offering
Anvil Secure is an information security consulting firm that provides bespoke penetration testing and security assessment services to enterprise technology companies. Its portfolio spans core Penetration Testing, Application & Cloud Security, and Embedded Security Services, plus specialized practices in AI Security Testing, OCP SAFE Testing, PQC Security Reviews, Microsoft UEFI Reviews, and Oracle 3rd Party Pen Testing. Engagements are individually scoped, delivered by employee-owned expert consultants, and supported by a research pipeline that produces open-source tools (e.g., CrownJewelScanner, PQCscan, ByteBanter) and published whitepapers.
Product overview
Anvil Secure is a penetration testing and security consulting firm offering bespoke services through employee-owned experts. The core service portfolio includes Penetration Testing, Application & Cloud Security, and Embedded Security Services, supplemented by specialized offerings such as AI Security Testing, OCP SAFE Testing, PQC Security Reviews, Microsoft UEFI Reviews, and Oracle 3rd Party Pen Testing. The company also maintains an internal workflow platform called Nexus with AI-enabled features. Beyond consulting, Anvil develops and publishes open-source security tools including CrownJewelScanner (Ruby gem analyzer), PQCscan (post-quantum crypto scanner), HANAlyzer (SAP HANA security checker), ByteBanter (LLM-based Burp Intruder payload generator), awssig (AWS SigV4 Burp extension), aqlmap (ArangoDB exploitation tool), and various other research tools for embedded systems, mobile, and firmware security research.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Bespoke, expert-led penetration testing engagements covering complex, technically challenging security assessments for enterprise technology clients.
- Application & Cloud Security Security assessment services for applications and cloud environments, including web, mobile, and cloud infrastructure security testing.
- Embedded Security Services Specialized security testing for embedded systems, firmware, hardware, and IoT devices, leveraging reverse engineering and hardware security research capabilities.
- AI Security Testing Security testing services for AI and LLM/GenAI systems, including threat modeling, attack surface mapping, jailbreaks, and prompt injection testing.
- OCP SAFE Testing Open Compute Project (OCP) Accepted|Security, Safety, and Fungibility Evaluations testing for open source hardware and data center infrastructure.
- PQC Security Reviews Post-Quantum Cryptography security reviews assessing readiness for quantum computing threats and evaluating PQC algorithm implementations.
- Microsoft UEFI Reviews Security reviews for Microsoft Unified Extensible Firmware Interface (UEFI) implementations and boot security.
- Oracle 3rd Party Pen Testing Penetration testing services specifically for Oracle environments, including Oracle Cloud Infrastructure (OCI), with over 5 years of Oracle testing experience.
Quantifiable outcome
- 1,880% three-year revenue growth, ranking Anvil 303 on Inc. 5000 list of fastest-growing US companies (2022)
- +3 more outcomes
Companies that use Anvil Secure
Customer profileNamed customers2 records
Segments1 record
Ideal customer profiles1 record
Anvil Secure technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability6 records
Feature16 records
Anvil Secure partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- D-OrbitcoreAnvil Secure and D-Orbit co-authored a white paper on securing satellites across the mission cycle. The research emphasizes securing radio communications, managing hosted payloads, and safeguarding firmware, with a focus on D-Orbit's ION Satellite Carrier. Alberto Volpatto of Anvil Secure and Davide Avanzi of D-Orbit co-authored the whitepaper titled 'Knockin' on Space's Door'.
Scale indicators9 records
Recent moves8 records
Expansion highlights5 records
Anvil Secure competitors and assessment
Company assessmentBroad incumbents
- Coalfire: Large cybersecurity advisory and assessment firm offering penetration testing alongside broader GRC, FedRAMP, and compliance services. Comparable penetration testing capabilities but operates at much larger scale with a more diversified portfolio.
- Mandiant (Google Cloud): Global incident response and threat intelligence firm with a strong offensive security and red team practice. Overlaps with Anvil on bespoke penetration testing and security consulting for large enterprises and government, but offers a much broader threat intelligence and IR portfolio.
- SecureWorks: Global cybersecurity services firm offering penetration testing, managed detection and response, and threat intelligence. Overlaps with Anvil on enterprise penetration testing engagements but competes through scale and recurring managed services rather than bespoke boutique delivery.
- Optiv: Large cybersecurity solutions integrator and services provider offering penetration testing, advisory, and managed security. Comparable enterprise customer base but with a much broader, channel-oriented delivery model.
- NCC Group: Global cybersecurity consulting and assurance firm with deep penetration testing, red team, and security research capabilities. Comparable to Anvil's bespoke offensive security offerings but with significantly broader geographic reach and a wider portfolio.
Direct peers
- Bishop Fox: Elite boutique cybersecurity consulting firm specializing in offensive security, penetration testing, and red teaming for large enterprises. Closely comparable to Anvil in customer profile (Fortune 500 tech), bespoke engagement model, and research-driven culture.
- Praetorian: Cybersecurity advisory and engineering firm focused on offensive security, application security, and cloud security for Fortune 1000 clients. Closely aligned with Anvil in enterprise-targeted bespoke consulting and research-driven practice.
- Trail of Bits: Boutique security research and consulting firm focused on application security, cryptography, and reverse engineering. Highly comparable to Anvil's bespoke consulting model, open-source tooling output (e.g., CodeQL-adjacent tooling), and engagement with sophisticated technology clients.
- NetSPI: Enterprise penetration testing and attack surface management firm serving large technology and financial services organizations. Comparable in offering breadth (application, cloud, network pentesting) and enterprise customer profile, though with a more productized delivery model.
- IOActive: Specialized security consultancy offering penetration testing and security research for hardware, embedded systems, and complex enterprise environments. Anvil CEO Chris Elbring previously served as SVP at IOActive, and the firm's embedded/UEFI security focus is highly comparable.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Anvil Secure social profiles
Digital presenceAnvil Secure financial estimates
Financial estimateRevenue estimate
Valuation estimate
Anvil Secure leadership team
Management profileNumber of profiles
Profiles17 records
Anvil Secure subsidiaries and ownership
Company hierarchySubsidiaries1 record
Anvil Secure funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Anvil Secure M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Anvil Secure
What does Anvil Secure do?
Anvil Secure is an information security consulting firm that provides bespoke penetration testing and security assessment services to enterprise technology companies. Its portfolio spans core Penetration Testing, Application & Cloud Security, and Embedded Security Services, plus specialized practices in AI Security Testing, OCP SAFE Testing, PQC Security Reviews, Microsoft UEFI Reviews, and Oracle 3rd Party Pen Testing. Engagements are individually scoped, delivered by employee-owned expert consultants, and supported by a research pipeline that produces open-source tools (e.g., CrownJewelScanner, PQCscan, ByteBanter) and published whitepapers.
Is Anvil Secure a public or private company?
Anvil Secure is a private company. It is classified as management employee owned and is currently operating.
When was Anvil Secure founded?
Anvil Secure was founded in 2016. It employs 11 to 50 people.
Where is Anvil Secure based?
Anvil Secure is headquartered in Seattle, United States, in the North America region.
How does Anvil Secure make money?
One revenue line is on record: bespoke Penetration Testing and Security Consulting.
Who are Anvil Secure's main competitors?
Broad incumbents on record are Coalfire, Mandiant (Google Cloud), SecureWorks, Optiv and NCC Group. Direct peers are Bishop Fox, Praetorian, Trail of Bits, NetSPI and IOActive.
Does Anvil Secure have an API?
No public API is recorded for Anvil Secure.
What industry is Anvil Secure in?
Anvil Secure's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services.