Secureflag
SecureFlag Limited is a London-based secure coding training platform serving enterprise software, DevOps, cloud, and QA engineers with hands-on labs across 45+ technologies and 150+ vulnerabilities, complemented by ThreatCanvas, an AI-assisted automated threat modeling tool.
- Company typePrivate
- Founded2019
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Secureflag does
SecureFlag Limited, a privately held company registered in England and Wales and headquartered in London, operates a hands-on secure coding training platform aimed at software developers, DevOps engineers, cloud engineers, QA engineers, architects, and the security teams that support them. The platform delivers training through virtualized desktop environments that simulate real development setups, spanning 45+ technologies and 150+ vulnerability types, with content covering web, mobile, cloud, infrastructure-as-code, legacy languages (COBOL), and emerging AI-application security surfaces. Pricing is quote-based and structured around annual subscriptions: a Training Unlimited tier for full catalog access, a Training Credits tier for usage-based consumption (with volume discounts at 30+ seats), and add-ons for SOC Analyst Labs and AI-Assisted Development Labs. A 7-day free trial with five lab credits serves as the individual self-serve funnel into enterprise contracts.
The company's second product, ThreatCanvas, is an AI-assisted threat modeling tool that generates threat models in seconds from textual descriptions, IaC templates, and architecture diagrams, mapping them to frameworks such as OWASP, STRIDE, PCI DSS, and HIPAA; ThreatCanvas 2.0 (November 2024) updated the default risk template and is offered as SaaS or private cloud, bundled for OWASP members and available as a subscription add-on to enterprise customers. Distribution combines direct enterprise field sales, an authorized reseller channel, and a reserved-instance OWASP partnership, with named customers spanning financial services (Wise, ING, Abrantix), government (HM Government), technology (VMware, Motorola Solutions), telecommunications (Vodafone), manufacturing (Michelin), media (ACIVISION), and professional services (Aon, Thomson Reuters). SecureFlag is ISO 27001 certified and operates under GDPR, CCPA/CalOPPA, and VCDPA-compliant privacy practices. Investor backing disclosed on the About Us page includes CoPilot and Aliasnet, alongside an early 2020 round from GELLIFY; co-founder and director Andrea Scaduto leads the company.
Secureflag firmographics
Firmographics- Name
- Secureflag
- Legal name
- SecureFlag Limited
- Website
- https://secureflag.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- SecureFlag Limited is a London-based secure coding training platform serving enterprise software, DevOps, cloud, and QA engineers with hands-on labs across 45+ technologies and 150+ vulnerabilities, complemented by ThreatCanvas, an AI-assisted automated threat modeling tool.
- Ownership category
- akta.pro rank
Secureflag industry classification
Industry- Product category
- Application Security Training
- NAICS
- Custom Computer Programming Services (541511), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
- akta.pro secondary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
Keywords
Where Secureflag is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Secureflag business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise Software Subscriptions: Annual or multi-year subscription licenses for organizations on Training Unlimited or Training Credits plans with features including unlimited training catalog access, SSO, APIs, management interface, reporting, and dedicated Customer Success Manager
- Training Credits Model: Credit-based subscription model where organizations purchase credits to access training labs on an as-needed basis, with volume discounts for teams of at least 30 people
- ThreatCanvas Subscription: Dedicated threat modeling subscription (ThreatCanvas) with optional add-ons for ThreatCanvas and SOC Analyst Labs available for Unlimited and Credits plans
- OWASP Member Access: Reserved instance access provided to OWASP members with annual limits on labs permitted, access to user interface without management interface capabilities
- Individual Free Trial: 7-day free trial with 5 credits for hands-on training labs, designed to convert individual users to organizational subscriptions
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Training Unlimited - Full platform access with unlimited training catalog and threat modeling capabilities |
| Subscription | Annual | Training Credits - Credit-based access to training catalog with core platform features |
| Subscription | Annual | Threat Modeling (ThreatCanvas) - Dedicated threat modeling platform subscription |
| Freemium | Pay-as-you-go | Free Trial - 7-day trial with 5 hands-on training lab credits |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels6 records
Secureflag product offering
Product offeringCore offering
SecureFlag operates a cloud-based hands-on secure coding training platform that delivers thousands of real-world labs through browser-based virtualized desktop computers, covering 45+ technologies and 150+ vulnerability types for developers, DevOps, cloud, and QA engineers. The company also offers ThreatCanvas, an AI-powered automated threat modeling tool that generates threat models from textual descriptions, IaC templates, and architecture diagrams aligned with OWASP, STRIDE, PCI DSS, and HIPAA frameworks. Enterprise customers license the platform on annual subscriptions (Training Unlimited or Training Credits) with SSO, SCIM, LMS, and CI/CD integrations, and receive a dedicated Customer Success Manager.
Product overview
SecureFlag is a hands-on secure coding training platform providing a portfolio of products including the core SecureFlag Training Platform and ThreatCanvas (automated threat modeling). The platform offers hands-on labs covering 45+ technologies and 150+ vulnerability types with virtualized desktop computers. Pricing tiers include Training Unlimited (full catalog access) and Training Credits, with optional add-ons for SOC Analyst Labs and AI-Assisted Development Labs. The platform integrates with development pipelines via APIs and supports SSO/SAML authentication. ThreatCanvas generates automated threat models from IaC templates and textual descriptions using AI.
Differentiator
Problem solved
Functional benefit
Brands
- ThreatCanvas: Automated threat modeling tool that generates threat models from textual descriptions, IaC templates, and architecture diagrams. Available as SaaS or Private Cloud deployments. Integrates with SecureFlag's training platform.
Products and services
- SecureFlag Training Platform Cloud-based hands-on secure coding training platform providing thousands of real-world labs through browser-based virtualized desktop computers for developers, DevOps, cloud, QA engineers, architects, and technical managers.
- ThreatCanvas AI-powered automated threat modeling tool that generates threat models from textual descriptions, Infrastructure-as-Code templates (Terraform, CloudFormation, Kubernetes YAML), and architecture diagrams in seconds, aligned with OWASP, STRIDE, PCI DSS, and HIPAA frameworks. Available as SaaS or Private Cloud deployments.
- SOC Analyst Labs Security Operations Center analyst training labs available as add-ons to Training Unlimited and Training Credits plans, covering Linux security and other SOC analyst topics.
- AI-Assisted Development Labs Hands-on labs teaching developers how to work directly with AI coding assistants, including secure prompting, reviewing AI-generated output, and fixing vulnerabilities introduced by AI-generated code.
- OWASP Membership Access Reserved instance of the SecureFlag platform offered to OWASP members, providing access to ThreatCanvas and hands-on security training labs with annual lab limits and restricted feature set.
Quantifiable outcome
- 21% 12-month average reduction in time spent performing security rework
- +3 more outcomes
Companies that use Secureflag
Customer profileNamed customers10 records
Segments7 records
Ideal customer profiles2 records
Secureflag technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability5 records
Feature7 records
Secureflag partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- OWASP (Open Worldwide Application Security Project)coreSecureFlag and OWASP partnered to offer OWASP members access to the SecureFlag platform and ThreatCanvas threat modeling automation tool. The partnership builds on a four-year collaboration providing OWASP members access to a reserved instance of the SecureFlag Secure Coding Training platform. OWASP members receive unlimited threat model generation, refinement, saving, revision browsing, and export capabilities through ThreatCanvas Pro features. Andrew van der Stock, OWASP Executive Director, endorsed ThreatCanvas as a welcome addition to the OWASP member benefit.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Secureflag competitors and assessment
Company assessmentDirect peers
- AppSecEngineer: AppSecEngineer (now part of Kroll) delivers hands-on application security and cloud security training for developers with lab-based learning. It mirrors SecureFlag's lab-centric approach and overlaps in DevOps/cloud engineering content.
- Secure Code Warrior: Secure Code Warrior is the closest direct competitor, offering hands-on secure coding training via in-app and tournament-based labs for developers. It targets the same enterprise persona (AppSec leaders, CISOs, developers) with very similar subscription pricing and lab-based pedagogy.
- Security Journey: Security Journey provides role-based secure coding and AppSec awareness training with hands-on labs and a learning management platform. It competes head-to-head with SecureFlag in the same secure-coding training category, with overlapping customer segments and similar learning-path structures.
- Cybrary: Cybrary is a cybersecurity skills development platform offering hands-on labs and certification prep across offensive, defensive, and AppSec domains. Its developer/AppSec training tracks overlap with SecureFlag's catalog and buyer (security training budget owners).
Emerging players
- Immersive Labs: Immersive Labs provides hands-on cyber resilience exercises spanning SDLC, cloud, and SOC scenarios. Its SDLC track overlaps SecureFlag's developer catalog and SOC Analyst Labs compete with SecureFlag's add-on.
- KnowBe4: KnowBe4 is the leading security awareness and phishing simulation platform increasingly expanding into developer/AppSec training. Its adjacent positioning and channel reach represent both a competitor and a potential upsell partner for SecureFlag-style content.
Broad incumbents
- Pluralsight: Pluralsight is a broad technology skills platform with cloud and security learning paths including assessment-led secure-coding training. It competes for enterprise training budget though with a less lab-driven, more video-heavy methodology.
- Snyk: Snyk is a developer-first security platform covering SAST, SCA, container, and IaC security with developer learning content. Snyk Learn overlaps with SecureFlag's catalog while Snyk's broader tooling competes with ThreatCanvas in the IaC threat-modeling adjacency.
- Checkmarx: Checkmarx is an enterprise AppSec suite with SAST, SCA, and IaC scanning plus secure-code training content (Codebashing). Its training modules compete with SecureFlag from inside broader scanning contracts.
- Veracode: Veracode is a broad incumbent AppSec platform (SAST, DAST, SCA) that also offers eLearning and secure-coding training modules to enterprise customers. Its learning offerings compete indirectly with SecureFlag by bundling training into larger AppSec deals.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Secureflag social profiles
Digital presenceSecureflag compliance and trust
Trust signalCompliance4 records
Secureflag financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secureflag leadership team
Management profileNumber of profiles
Profiles1 record
Secureflag funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secureflag M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secureflag
What does Secureflag do?
SecureFlag operates a cloud-based hands-on secure coding training platform that delivers thousands of real-world labs through browser-based virtualized desktop computers, covering 45+ technologies and 150+ vulnerability types for developers, DevOps, cloud, and QA engineers. The company also offers ThreatCanvas, an AI-powered automated threat modeling tool that generates threat models from textual descriptions, IaC templates, and architecture diagrams aligned with OWASP, STRIDE, PCI DSS, and HIPAA frameworks. Enterprise customers license the platform on annual subscriptions (Training Unlimited or Training Credits) with SSO, SCIM, LMS, and CI/CD integrations, and receive a dedicated Customer Success Manager.
Is Secureflag a public or private company?
Secureflag is a private company. It is classified as venture growth investor backed and is currently operating.
When was Secureflag founded?
Secureflag was founded in 2019. It employs 1 to 10 people.
Where is Secureflag based?
Secureflag is headquartered in London, United Kingdom, in the Europe region.
How does Secureflag make money?
Five revenue lines are on record. Enterprise Software Subscriptions are the primary driver. The others are training Credits Model, threatCanvas Subscription, OWASP Member Access and individual Free Trial.
Who are Secureflag's main competitors?
Direct peers on record are AppSecEngineer, Secure Code Warrior, Security Journey and Cybrary. Emerging players are Immersive Labs and KnowBe4. Broad incumbents are Pluralsight, Snyk, Checkmarx and Veracode.
Does Secureflag have an API?
Yes. SecureFlag offers APIs that enable custom integrations, allowing organizations to create a bespoke security ecosystem. The APIs support Single Sign-On (SSO) via SAML or OAuth-based identity providers, SCIM for automated user provisioning, and integration with Development Pipelines to tailor training programs based on detected vulnerabilities. APIs are available for enterprise customers as part of the Training Unlimited and Training Credits plans.
What industry is Secureflag in?
Secureflag's product category is Application Security Training. Its primary akta.pro industry code is EDABAGAN, Secure Software & DevOps Awareness (Secure Coding Basics), with a secondary code of HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing). Its NAICS code is 541511 and its SIC code is 7372.