SHIFT SECURITY
SHIFT SECURITY is a Tokyo-based private cybersecurity firm founded in 2016 that standardizes white-hat hacker techniques to deliver tiered vulnerability assessment, 24x365 SOC monitoring, and the S4 SaaS vulnerability management platform to Japanese enterprise, mid-market, and SMB customers.
- Company typePrivate
- Founded2016
- HeadquartersTokyo, Japan
- Headcount—
- GTM typeB2B
- OfferingServices
What SHIFT SECURITY does
SHIFT SECURITY (株式会社SHIFT SECURITY) is a Tokyo-based private cybersecurity company founded in June 2016 by Shinichi Matsuno (who led the firm until December 2024 when Shinobu Kanauchi assumed the Representative Director role). The company's core proposition is the standardization and systematization of white-hat hacker techniques — proprietary methodology that decomposes expert diagnostic skills into fine-grained OK/NG evaluable steps — to deliver vulnerability assessment and security monitoring services that are consistent in quality, lower in cost, and shorter in lead time than traditional expert-dependent offerings. SHIFT SECURITY maintains a 250+ engineer diagnostic team described as "domestic top-class" in Japan and has delivered 13,000+ assessments since founding, with a 90% repeat customer rate.
The product portfolio spans web application, smartphone (OWASP MASVS), cloud (CIS Benchmarks), generative AI system (OWASP Top10 for LLMs), penetration testing (NIST SP 800-115, PCI DSS), platform, and source code diagnostics, complemented by a 24x365 Security Operations Center-as-a-Service covering 200+ security products and 18+ cloud services, backed by a proprietary 1M+ indicator threat intelligence database. Additional offerings include the S4 SaaS vulnerability management platform (100+ subscribers), cloud digital forensics (Fast Forensics at ¥600,000 fixed), VAndS internalization support (combining VAddy automated tools with manual diagnostics), ASM quick scans, and IR-1 incident response via Blackpanda partnership. A wholly-owned subsidiary, Maslab (established April 2021), focuses on penetration testing services.
Revenue is generated through three primary streams: per-assessment tiered fees (Bronze/Silver/Gold/Platinum plans), recurring subscriptions (SOC monitoring from ¥50,000/month; VAndS from ¥598,000/year; S4 SaaS), and professional services (forensics, consulting). Distribution is sales-led through direct engagement, supported by SI partnerships (Forgevision), vendor MSSP programs (Palo Alto Networks NextWave, Orca Security), and heavy content/event marketing (Security Days, Interop Tokyo, 89-sai annual event). Customer concentration is low — only one named enterprise customer (Nissen Holdings) is publicly disclosed — and the firm targets a distributed base across finance, manufacturing, retail, public sector, and increasingly SMB and critical infrastructure/OT segments in Japan, with a first international partnership (IXT in Norway, April 2026) marking initial geographic optionality.
SHIFT SECURITY firmographics
Firmographics- Name
- SHIFT SECURITY
- Legal name
- 株式会社SHIFT SECURITY
- Website
- https://shiftsecurity.jp
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Short description
- SHIFT SECURITY is a Tokyo-based private cybersecurity firm founded in 2016 that standardizes white-hat hacker techniques to deliver tiered vulnerability assessment, 24x365 SOC monitoring, and the S4 SaaS vulnerability management platform to Japanese enterprise, mid-market, and SMB customers.
- Ownership category
- akta.pro rank
SHIFT SECURITY industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (56162), Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industries
- Patch & Remediation Orchestration (HDADAHAB), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG), Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Configuration & Exposure Hardening (CIS/Benchmarking) (HDADAHAH), Continuous Controls Monitoring (CCM) (HDADAHAE)
Keywords
Where SHIFT SECURITY is headquartered
LocationHeadquarters
- HQ city
- Tokyo
- HQ country
- Japan
- HQ region
- Asia
Offices1 record
Markets served
SHIFT SECURITY business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Vulnerability Assessment Services: Per-assessment fees structured in tiers (Bronze, Silver, Gold, Platinum) based on scope and depth of testing. Customers select plans by diagnostic scope (number of items, request count). Additional services include penetration testing, cloud diagnostics, smartphone app diagnostics, AI system diagnostics, platform diagnostics, and source code diagnostics.
- Security Monitoring & SOC Services: Monthly subscription fees based on monitoring scope, with ticket-based additional service purchases. Monitoring covers UTM, EDR, SASE/CASB, IaaS, CNAPP, and customized SOC services. Small-start possible from ¥50,000/month.
- Vulnerability Management S4: SaaS-based vulnerability management subscription service with tiered plans. Unlimited registered assets and users. Targets SMEs and organizations seeking to manage vulnerability information without dedicated security staff.
- Cloud Digital Forensics: Incident response and forensic investigation services for cloud environments. 'Fast Forensics' fixed-price service at ¥600,000, with additional investigation at ticket-based pricing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Unit Pricing | One time/ perpetual license | Bronze - Budget-focused, 22 items (OWASP Top10 basis) |
| Unit Pricing | One time/ perpetual license | Silver - High-severity vulnerabilities, 92 items (OWASP Top10 basis) |
| Unit Pricing | One time/ perpetual license | Gold (Popular) - Comprehensive, 128 items (ASVS basis) |
| Unit Pricing | One time/ perpetual license | Platinum - Advanced custom inspection per customer requirements |
| Subscription | Monthly | Security Monitoring - Starting from ¥50,000/month |
| Subscription | Annual | VAndS Professional+ - VAddy annual license + 20 manual tickets |
| Subscription | Annual | VAndS Professional+50 - VAddy annual license + 50 manual tickets |
| Outcome Based/ Performance | One time/ perpetual license | Cloud Digital Forensics - Fast Forensics |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels9 records
SHIFT SECURITY product offering
Product offeringCore offering
SHIFT SECURITY delivers manual vulnerability assessment and security monitoring services built on a proprietary, standardized methodology that decomposes white-hat hacker techniques into OK/NG evaluable steps. The portfolio covers web, smartphone, cloud, generative-AI, platform, source-code, and endpoint diagnostics, alongside 24x365 SOC monitoring (UTM, EDR, SASE/CASB, IaaS, CNAPP, custom SOC), incident response/digital forensics, and the S4 SaaS vulnerability management platform for SMEs.
Product overview
SHIFT SECURITY operates as a security services company offering a unified platform-plus-services architecture. The core offering consists of vulnerability assessment services (web application, mobile app, cloud, AI systems, penetration testing, platform/server, source code) delivered by a standardized methodology with 250+ engineers. The monitoring division provides 24x365 SOC services (SOCaaS) with tiered products for UTM, EDR, SASE/CASB, IaaS, and CNAPP monitoring. The portfolio includes S4, a SaaS vulnerability management platform for automated risk analysis, and supplementary services including consulting, incident response (IR-1/Blackpanda), digital forensics, and ASM quick scans. The company standardizes and modularizes security expertise to deliver consistent quality at reduced cost.
Differentiator
Problem solved
Functional benefit
Brands
- S4: 脆弱性管理システム - 人材不足・技術不足・資金不足でセキュリティ対策の難しい企業へ提供するSaaS型の脆弱性管理サービス
- SOC運用支援(SOCaaS)
- VAndS
Products and services
- Web Application Vulnerability Assessment (Webアプリケーション診断) Dynamic-analysis-based vulnerability assessment for web applications detecting SQL injection, XSS, CSRF, and other OWASP Top 10 / ASVS issues through manual testing by standardized engineers combined with automated tools. For corporate and EC sites.
- Smartphone Application Vulnerability Assessment (スマートフォンアプリケーション診断)
Quantifiable outcome
- 13,000+ vulnerability assessments delivered since founding in 2016
- +5 more outcomes
Companies that use SHIFT SECURITY
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
SHIFT SECURITY technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
Feature3 records
SHIFT SECURITY partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered notable, core and flagship.
- IXT (Norway-based MVNO)notableIXT, a Norway-based full MVNO specializing in secure IoT connectivity, integrated Zscaler's Zero Trust Network Access (ZTNA) into its SecureNet cellular platform. SHIFT SECURITY collaborated on the implementation, supporting the deployment of Zero Trust security policies at the SIM level for IoT and OT devices without VPN infrastructure. The solution routes all device traffic through Zscaler's Zero Trust Exchange platform for inspection and policy enforcement, targeting critical infrastructure sectors (energy, water, manufacturing, transport) for NIS2 compliance.
- Orca SecuritycoreSHIFT SECURITY entered an MSSP (Managed Security Service Provider) contract with Orca Security to strengthen its cloud native security monitoring capabilities. Orca Security provides an agentless CNAPP (Cloud Native Application Protection Platform) solution, which SHIFT SECURITY incorporates into its monitoring service offering for AWS, Azure, and GCP environments. The partnership enables SHIFT SECURITY to offer CSPM and CWPP-based monitoring.
- Blackpanda (IR-1)coreSHIFT SECURITY partnered with Blackpanda to offer IR-1 incident response services, providing rapid digital forensics and incident response for customers experiencing security incidents. Blackpanda's expertise complements SHIFT SECURITY's monitoring and assessment services with post-incident investigation capabilities.
- フォージビジョン株式会社 (Forgevision Co., Ltd.)flagshipBusiness partnership with Forgevision, a system development and cloud integration company. The partnership embeds SHIFT SECURITY's vulnerability assessment and security monitoring services into Forgevision's system construction lifecycle, enabling 'Shift Left' security — integrating security from the design phase of system development. Joint go-to-market for secure software development.
- パロアルトネットワークス株式会社 (Palo Alto Networks Japan)coreSHIFT SECURITY was certified as a Palo Alto Networks NextWave MSSP (Managed Security Service Provider) partner. This certification validates SHIFT SECURITY's capability to deliver managed security services based on Palo Alto Networks' security platforms. The partnership enables provision of advanced firewall, SIEM, and cloud security monitoring services.
- ビットフォレスト株式会社 (Bitforest Corporation)notableSHIFT SECURITY partnered with Bitforest to offer VAndS (Vulnerability Assessment + DevOps Support), combining Bitforest's VAddy automated vulnerability scanning tool with SHIFT SECURITY's manual expert assessment and support. The VAndS service enables organizations to internalize vulnerability testing with automated tools plus expert guidance at accessible price points.
Scale indicators7 records
Recent moves9 records
Expansion highlights8 records
SHIFT SECURITY competitors and assessment
Company assessmentDirect peers
- NRI Secure Technologies: One of Japan's largest pure-play cybersecurity service providers, offering vulnerability assessment, penetration testing, SOC monitoring, and consulting. Directly comparable to SHIFT SECURITY's assessment and monitoring portfolio with deeper enterprise/government footprint.
- LAC Co., Ltd. Japanese cybersecurity firm specializing in vulnerability diagnostics, security monitoring (JSOC), and incident response. Closely mirrors SHIFT SECURITY's assessment-plus-SOC service model in the Japan market.
- Mitsui Bussan Secure Directions: Japan-based vulnerability assessment and penetration testing specialist with strong brand recognition. Directly competes with SHIFT SECURITY in web app and platform diagnostics for enterprise customers.
- Bishop Fox: US-based offensive security firm specializing in penetration testing, red teaming, and vulnerability research. Highly comparable methodology and service model to SHIFT SECURITY's pentest and assessment practice, though serving US/enterprise market.
Broad incumbents
- Internet Initiative Japan (IIJ): Large Japanese internet/network provider with a security services division (IIJ Security) offering managed SOC, assessment, and consulting. Overlaps with SHIFT SECURITY's monitoring and assessment offerings as part of a broader portfolio.
- Trend Micro (Japan): Global cybersecurity vendor with significant Japan operations providing products, managed services, and assessment. Comparable as a broad incumbent with overlapping vulnerability management and SOC capabilities, though product-led rather than service-led.
- NCC Group: Global cybersecurity services firm offering vulnerability assessment, managed SOC, and incident response. Comparable broad portfolio to SHIFT SECURITY's combined assessment + monitoring offering, with much larger international footprint.
- SecureWorks: Global managed security services provider (MSSP) offering SOC, vulnerability management, and incident response. Comparable in its recurring SOC and vulnerability management value proposition to SHIFT SECURITY's SOCaaS and S4 services.
Emerging players
- Tenable (Japan): Global vulnerability management platform vendor (Nessus, Tenable One) increasingly competing in continuous vulnerability assessment. Partially overlaps with SHIFT SECURITY's S4 SaaS and assessment services as a product-led alternative.
- Flatt Security: Japan-based startup providing web application security assessment and developer-focused security tooling (Shisho Cloud). Comparable to SHIFT SECURITY in web app diagnostic focus with a more product/SaaS orientation, serving similar Japanese mid-market and enterprise customers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
SHIFT SECURITY social profiles
Digital presenceSHIFT SECURITY compliance and trust
Trust signalCompliance3 records
SHIFT SECURITY financial estimates
Financial estimateRevenue estimate
Valuation estimate
SHIFT SECURITY leadership team
Management profileNumber of profiles
Profiles5 records
SHIFT SECURITY subsidiaries and ownership
Company hierarchySubsidiaries1 record
SHIFT SECURITY funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SHIFT SECURITY M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SHIFT SECURITY
What does SHIFT SECURITY do?
SHIFT SECURITY delivers manual vulnerability assessment and security monitoring services built on a proprietary, standardized methodology that decomposes white-hat hacker techniques into OK/NG evaluable steps. The portfolio covers web, smartphone, cloud, generative-AI, platform, source-code, and endpoint diagnostics, alongside 24x365 SOC monitoring (UTM, EDR, SASE/CASB, IaaS, CNAPP, custom SOC), incident response/digital forensics, and the S4 SaaS vulnerability management platform for SMEs.
Is SHIFT SECURITY a public or private company?
SHIFT SECURITY is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SHIFT SECURITY founded?
SHIFT SECURITY was founded in 2016.
Where is SHIFT SECURITY based?
SHIFT SECURITY is headquartered in Tokyo, Japan, in the Asia region.
How does SHIFT SECURITY make money?
Four revenue lines are on record. Vulnerability Assessment Services are the primary driver. The others are security Monitoring & SOC Services, vulnerability Management S4 and cloud Digital Forensics.
Who are SHIFT SECURITY's main competitors?
Direct peers on record are NRI Secure Technologies, LAC Co., Ltd., Mitsui Bussan Secure Directions and Bishop Fox. Broad incumbents are Internet Initiative Japan (IIJ), Trend Micro (Japan), NCC Group and SecureWorks. Emerging players are Tenable (Japan) and Flatt Security.
Does SHIFT SECURITY have an API?
No public API is recorded for SHIFT SECURITY.
What industry is SHIFT SECURITY in?
SHIFT SECURITY's product category is Cybersecurity Services. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADAHAB, Patch & Remediation Orchestration. Its NAICS code is 56162 and its SIC code is 7373.