Cytomate
Cytomate is a Qatar-based AI-driven offensive cybersecurity company that builds breach-and-attack simulation, cyber deception, EASM, and OT/IoT testing platforms for enterprise customers in healthcare, financial services, government, and critical infrastructure across the MENA region and globally.
- Company typePrivate
- Founded2021
- HeadquartersDoha, Qatar
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Cytomate does
Cytomate is an AI-driven offensive cybersecurity company headquartered in Lusail, Doha (Qatar), founded in 2021 and positioned as the first offensive cybersecurity vendor in the MENA region developing its own proprietary technology. The company offers an interconnected portfolio of cybersecurity platforms designed to test, validate, and strengthen enterprise defenses across IT, OT, and IoT environments. Core products include Breach+ (a Breach and Attack Simulation platform that emulates real-world attacks and validates security controls), Sarab (a cyber deception platform that deploys decoys and maps attacker activity to MITRE ATT&CK), Racid (External Attack Surface Management), BattleTwin (safe OT/IoT security testing for ICS environments), and SnipeX (AI-driven polymorphic payload generation). Underlying these products is CYTOMIND, an AI engine for autonomous cyber defense that leverages large language models, instruction-based AI, and agentic AI for threat analysis, detection engineering, and automated defense strengthening, complemented by the Autonomous Adversarial Intelligence (A2I) feedback-loop framework.
Cytomate targets enterprise customers in healthcare, financial services, government, and critical infrastructure, supplemented by MSSPs and consulting/SI partners. The company makes money primarily through subscription-based licensing of its platforms (Breach+, Sarab, Racid, BattleTwin), professional services (Advanced Penetration Testing, Advanced Program Analysis, Cyber Reversing), and managed security services delivered through MSSP partners. Pricing is quote-based and not publicly disclosed. Go-to-market combines direct enterprise sales (consultation and demo booking), a multi-tier partner program (Registered, Silver, Gold, Strategic across Reseller, Referral, MSSP, and Consulting & SI partner types), and a Microsoft Azure Marketplace listing for Breach+. The company was founded by Hamad Hadeed and Muhammad Masoom Alam, has 11-50 employees, secured $494,460 from Qatar Development Bank in July 2022, and has been recognized as Best Startup of The Year (2025), at the Qatar Digital Business Awards (2024), the SBIG Awards (2026), and at Black Hat (2023).
Cytomate firmographics
Firmographics- Name
- Cytomate
- Legal name
- Cytomate
- Website
- https://cytomate.net
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Cytomate is a Qatar-based AI-driven offensive cybersecurity company that builds breach-and-attack simulation, cyber deception, EASM, and OT/IoT testing platforms for enterprise customers in healthcare, financial services, government, and critical infrastructure across the MENA region and globally.
- Ownership category
- akta.pro rank
Cytomate industry classification
Industry- Product category
- Cybersecurity Software
- NAICS
- Software Publishers (5132), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industries
- Endpoint Deception & Anti-Ransomware (HDADAEAL), OT Threat Detection & Monitoring (NDR/IDS for ICS) (HDADAJAF)
Keywords
Where Cytomate is headquartered
LocationHeadquarters
- HQ city
- Doha
- HQ country
- Qatar
- HQ region
- Middle East
Offices2 records
Markets served
Cytomate business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Platform Subscriptions: Cytomate generates revenue primarily through subscription-based licensing of their cybersecurity platforms including Breach+, Sarab, Racid, and BattleTwin. These platforms can work together or independently, offering flexible solutions for comprehensive or specific security needs.
- Professional Services: The company offers cybersecurity consulting, assessments, and transformation programs. Their offensive cybersecurity services include Advanced Penetration Testing, Advanced Program Analysis, and Cyber Reversing services for vulnerability research and backdoor detection.
- Managed Security Services: Through MSSP partner relationships, Cytomate powers managed cybersecurity services for customers who prefer outsourced security operations.
Go-to-market motion3 records
Distribution channels3 records
Marketing channels5 records
Cytomate product offering
Product offeringCore offering
Cytomate develops and sells an AI-driven offensive cybersecurity platform portfolio that emulates real-world cyberattacks, deploys deception decoys, monitors external attack surfaces, and tests OT/IoT environments. Its core products include Breach+ (Breach and Attack Simulation), Sarab (Cyber Deception), Racid (External Attack Surface Management), and BattleTwin (OT/IoT security testing), supported by the CYTOMIND AI engine and the SnipeX payload mutation tool. The company also offers GRC advisory and professional offensive security services.
Product overview
Cytomate is an offensive cybersecurity company offering an interconnected ecosystem of AI-driven cybersecurity products designed to help organizations proactively test, validate, and strengthen their security defenses. The product portfolio includes Breach+ as the core Breach and Attack Simulation (BAS) platform, Sarab for cyber deception, Racid for External Attack Surface Management (EASM), and BattleTwin for OT/IoT security testing. These products work together or independently, supported by the CYTOMIND AI engine for autonomous cyber defense and the SnipeX payload mutation tool. The ecosystem is complemented by GRC Advisory services.
Differentiator
Problem solved
Functional benefit
Brands
- Breach+ (BAS): Breach and Attack Simulation platform that tests security defenses by emulating real-world cyberattacks, helping identify vulnerabilities and validate existing security controls.
- Sarab (Cyber Deception)
- Racid (EASM)
- BattleTwin (Test on OT/IoT)
- CYTOMIND
- SnipeX
- Cyber Reversing
Products and services
- Breach+ (BAS) Breach and Attack Simulation (BAS) platform that tests security defenses by emulating real-world cyberattacks, helping organizations identify vulnerabilities and validate existing security controls across IT, OT, and IoT environments. Features end-to-end attack simulation, AI-driven evasion, polymorphic payload testing, and actionable remediation guidance.
- Sarab (Cyber Deception) Cyber deception platform described as a Qatari sovereign deception appliance. It deploys realistic decoys such as fake servers, databases, credentials, OT devices, and documents across the network to mislead attackers, divert threats from critical assets, and generate verified high-fidelity alerts of attacker intent mapped to the MITRE ATT&CK framework.
- Racid (EASM) External Attack Surface Management (EASM) platform providing real-time monitoring and visibility into external threats and unknown digital assets, helping organizations discover and track their internet-facing exposure.
- BattleTwin (Test on OT/IoT) Platform for creating safe, isolated simulations of ICS/OT environments that enable realistic offensive security testing of OT and IoT systems without risking production environments. Supports emulation of APT-level attacks and protocol-specific exploits.
- CYTOMIND AI engine for autonomous cyber defense that analyzes attacker behavior and helps security teams detect threats and strengthen defenses faster through intelligent automation. Powers natural language understanding, threat report generation, and detection rule creation across the Cytomate platform.
- Cyber Reversing Next-generation offensive service framework that includes Advanced Penetration Testing (APT) and Advanced Program Analysis (APA) revolving around reverse engineering for cybersecurity enhancement, vulnerability research, and backdoor detection.
- GRC Advisory Governance, Risk, and Compliance advisory service offered alongside the Cytomate product portfolio to support cybersecurity transformation and compliance programs.
Quantifiable outcome
- Near-zero false positives reported by deception platform vendors due to only malicious actors interacting with decoys
- +2 more outcomes
Companies that use Cytomate
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles3 records
Cytomate technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability8 records
Feature11 records
Cytomate partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core and strategic.
- Reseller PartnerscorePartners who resell Cytomate platforms and services to end customers. Partner benefits include deal registration protection, technical workshops, certifications, pre-sales and solution engineering support, and demo environments.
- Referral PartnerscorePartners who introduce qualified opportunities and collaborate on strategic engagements with Cytomate. Benefits include referral opportunities and strategic pricing support.
- MSSP PartnerscoreManaged Security Service Providers who deliver cybersecurity services powered by Cytomate technologies. Partners gain access to Cytomate's AI-driven security validation and threat exposure management capabilities.
- Consulting & SI PartnerscorePartners who support implementation, advisory, assessments, and cybersecurity transformation programs. Partners collaborate on deal qualification, customer engagements, proposal development, and co-selling opportunities.
- MicrosoftcoreCytomate's Breach+ platform is available on Azure Marketplace. Collaboration includes joint events such as Microsoft AI Tour and Web Summit partnerships. Strategic alignment for AI-driven cybersecurity solutions.
- Qatar Science & Technology Park (QSTP)strategicCytomate operates from QSTP with booth presence at QSTP events including QSTP AI week and workshops. QSTP affiliation provides innovation ecosystem support and resources.
- Qatar Computing Research Institute (QCRI)strategicBattleTwin showcased at QRDI's Innovation Corner, indicating collaboration with Qatar's research and innovation ecosystem for OT/IoT security testing solutions.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Cytomate competitors and assessment
Company assessmentDirect peers
- Pentera: Pentera is an automated security validation vendor that runs safe adversary emulation against production environments — directly comparable to Cytomate's Breach+ for continuous offensive validation of enterprise defenses.
- CounterCraft: CounterCraft builds deception-driven threat intelligence that creates realistic decoys to expose adversary TTPs, overlapping with Cytomate's Sarab product line in deception-based early detection and adversary engagement.
- Cymulate: Cymulate is a direct peer offering a Breach and Attack Simulation platform that emulates adversary tactics against enterprise defenses. It overlaps with Cytomate's Breach+ on BAS, exposure validation, and red-team automation for CISOs.
- AttackIQ: AttackIQ is a leading BAS vendor aligned with the MITRE ATT&CK Evaluations program, selling continuous security validation to large enterprises — a direct peer to Cytomate's Breach+ on simulation-led defensive testing.
- Acalvio: Acalvio offers a ShadowPlex cyber deception platform that deploys decoys and lures throughout IT environments — directly comparable to Cytomate's Sarab deception appliance and high-fidelity detection via MITRE-mapped decoy interactions.
- XM Cyber: XM Cyber combines attack-path management with simulated breach analytics, competing with Cytomate's Breach+ on prioritization of exploitable exposures and chain-of-attack validation.
- SafeBreach: SafeBreach runs one of the most mature BAS platforms, continuously running attack simulations against customer environments. It competes head-on with Cytomate's Breach+ for the same security-validation budget and continuously-compared-with category on Gartner.
- Picus Security: Picus Security delivers continuous security validation through attack simulation aligned to MITRE ATT&CK, overlapping directly with Cytomate's Breach+ and Sarab capabilities in offensive validation and detection engineering.
Broad incumbents
- Rapid7: Rapid7 is a broader security platform (InsightIDR, Metasploit, exposure management) that bundles attack simulation and offensive tooling — a broad incumbent whose portfolio overlaps Cytomate's BAS, EASM, and red-team-adjacent features.
- Mandiant (Google Cloud): Mandiant runs front-line offensive security services including red teaming, penetration testing, and attack simulation — comparable to Cytomate's offensive services and Advanced Penetration Testing offering as a broader cyber-defense incumbent.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Cytomate social profiles
Digital presenceCytomate financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cytomate leadership team
Management profileNumber of profiles
Profiles2 records
Cytomate funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cytomate M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cytomate
What does Cytomate do?
Cytomate develops and sells an AI-driven offensive cybersecurity platform portfolio that emulates real-world cyberattacks, deploys deception decoys, monitors external attack surfaces, and tests OT/IoT environments. Its core products include Breach+ (Breach and Attack Simulation), Sarab (Cyber Deception), Racid (External Attack Surface Management), and BattleTwin (OT/IoT security testing), supported by the CYTOMIND AI engine and the SnipeX payload mutation tool. The company also offers GRC advisory and professional offensive security services.
Is Cytomate a public or private company?
Cytomate is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cytomate founded?
Cytomate was founded in 2021. It employs 11 to 50 people.
Where is Cytomate based?
Cytomate is headquartered in Doha, Qatar, in the Middle East region.
How does Cytomate make money?
Three revenue lines are on record. Platform Subscriptions are the primary driver. The others are professional Services and managed Security Services.
Who are Cytomate's main competitors?
Direct peers on record are Pentera, CounterCraft, Cymulate, AttackIQ, Acalvio, XM Cyber, SafeBreach and Picus Security. Broad incumbents are Rapid7 and Mandiant (Google Cloud).
Does Cytomate have an API?
No public API is recorded for Cytomate.
What industry is Cytomate in?
Cytomate's product category is Cybersecurity Software. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADAEAL, Endpoint Deception & Anti-Ransomware. Its NAICS code is 5132 and its SIC code is 7371.