Doyensec
Doyensec is a founder-owned, self-funded application security consultancy founded in 2017 that delivers offensive security testing, source code review, and vulnerability research to Fortune 500 enterprises, tech vendors, and startups from offices in San Francisco and San Marino, while publishing open-source security tools.
- Company typePrivate
- Founded2017
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Doyensec does
Doyensec is an independent, founder-owned application security consultancy founded in 2017 by John Villamil and Luca Carettoni. The company provides offensive security services including penetration testing, source code review, reverse engineering, product security design, vulnerability research, and security automation across web applications, APIs, mobile, desktop, GraphQL, ElectronJS, cloud, IoT, smart contracts, and AI/LLM platforms. The firm serves Fortune 500 enterprises, global technology brands, software vendors, and technology startups, operating globally from offices in San Francisco (US headquarters) and Borgo Maggiore, San Marino (EMEA operations).
Doyensec has built a portfolio of open-source and commercial security testing tools that complement and signal its consulting practice. Notable tools include Electronegativity and the premium Electrong (ElectronJS scanning), InQL (GraphQL Burp Suite extension with schema brute-forcing), ELBaph (AWS load balancer auditor with SARIF reporting), maSSO (weaponized OIDC/SAML SSO identity provider for testing), Session Switcher (Burp session management), and SafeUpdater (secure Electron auto-updater reference implementation). These tools are distributed via GitHub and the PortSwigger BApp Store, with the company publishing ongoing research through its blog (CloudSecTidbits series), conference presentations (BSides, DEFCON Singapore DemoLabs), and security advisories including reports to NASA and major open-source projects.
Doyensec operates as a self-funded, bootstrapped business with no external investment or funding rounds. Revenue is generated exclusively through custom-priced professional services engagements with no public pricing, no channel partners, and no self-serve offering. The firm employs approximately 20 security engineers and vulnerability researchers drawn from big tech companies and startups, with an explicit 25% time allocation to self-directed research that fuels both tool development and vulnerability discovery (including disclosed findings such as 16 vulnerabilities in CFITSIO and a ksmbd local root privilege escalation exploit). Engagement contracts are typically multi-year and negotiated per project scope.
Doyensec firmographics
Firmographics- Name
- Doyensec
- Legal name
- Doyensec LLC
- Website
- https://www.doyensec.com/
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Doyensec is a founder-owned, self-funded application security consultancy founded in 2017 that delivers offensive security testing, source code review, and vulnerability research to Fortune 500 enterprises, tech vendors, and startups from offices in San Francisco and San Marino, while publishing open-source security tools.
- Ownership category
- akta.pro rank
Doyensec industry classification
Industry- Product category
- Application Security Consulting
- NAICS
- Other Scientific and Technical Consulting Services (54169), Other Computer Related Services (541519), Computer Systems Design Services (541512)
- SIC
- Services-Testing Laboratories (8734), Services-Engineering Services (8711), Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Smart Contract Security Tooling (static/dynamic analysis, formal verification) (FSAPABAI), Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK), Network Security Services (Firewall/VPN/ZTNA/SASE Integration) (BPAEAEAG)
Keywords
Where Doyensec is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Doyensec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Security Consulting Services: Professional services engagements providing application security testing, penetration testing, source code review, reverse engineering, and security consulting. Engagements include product security design and auditing, tooling development, and vulnerability research. Work is tailored to each client's specific needs with transparent communication throughout the engagement.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Doyensec product offering
Product offeringCore offering
Doyensec provides offensive application security consulting services including penetration testing, source code review, reverse engineering, and security design across web, mobile, desktop, GraphQL, ElectronJS, cloud, IoT, smart contract, and AI/LLM platforms. The firm also develops proprietary open-source and commercial security testing tools (e.g., Electronegativity, InQL, ELBaph, maSSO, Session Switcher) used by security practitioners worldwide.
Product overview
Doyensec is an offensive security research company that develops specialized security testing tools alongside providing professional application security consulting services. Their product portfolio includes open-source and commercial tools: Electronegativity (open-source) and Electrong (premium) for ElectronJS application scanning; InQL (Burp Suite extension) for GraphQL security testing; Session Switcher for HTTP session management in Burp Suite; ELBaph for AWS ELB configuration auditing; maSSO for OIDC/SAML identity provider testing; and SafeUpdater as a reference implementation for secure Electron auto-updates. The company also publishes extensive research including CloudSecTidbits IaC labs and CFITSIO security advisories. Services include penetration testing, source code review, reverse engineering, and security audits across web, mobile, desktop, cloud, IoT, and AI/LLM applications.
Differentiator
Problem solved
Functional benefit
Products and services
- Application Security Consulting Services Custom application security consulting engagements covering penetration testing, source code review, reverse engineering, and security design across web applications, mobile apps, desktop applications, GraphQL platforms, ElectronJS apps, cloud infrastructure, IoT devices, smart contracts, and AI/LLM systems.
- Electronegativity Open-source ElectronJS security scanning tool for identifying misconfigurations and vulnerabilities in Electron-based desktop applications, available via GitHub.
- Electrong Premium commercial ElectronJS security scanning tool offering comprehensive analysis capabilities for Electron-based desktop applications.
- InQL (InQL Scanner) GraphQL security testing tool delivered as a Burp Suite extension, providing introspection-based schema analysis, query templating, and schema brute-forcing when introspection is disabled.
- Session Switcher Burp Suite extension that lets users save, switch, and auto-update HTTP sessions directly from the request editor to streamline authorization testing workflows.
- ELBaph Read-only CLI tool written in Go that maps AWS Elastic Load Balancers, listeners, rules, and targets into a single routing model to identify exposed paths and misconfigurations.
- maSSO Weaponized compliant Single Sign-On Identity Provider used for security testing of OIDC and SAML 2.0 Service Providers, also supporting the SCIM protocol.
- SafeUpdater Secure Electron auto-updater reference implementation for macOS providing Ed25519 signature verification, SHA-512 integrity checks, immutable version manifests, and protection against downgrade, integrity, race condition, and untested version attacks.
Quantifiable outcome
- Found and reported numerous vulnerabilities in widely-deployed products
- +3 more outcomes
Companies that use Doyensec
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
Doyensec technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
Feature7 records
Doyensec partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered minor.
- TeleportminorTeleport sponsored Doyensec's MCP (Model Context Protocol) security research, enabling cutting-edge security research on MCP authentication and authorization vulnerabilities. This partnership produced significant findings on enterprise MCP deployments.
- Polytechnic University of ValenciaminorCollaborative research partnership with the Polytechnic University of Valencia during a student internship. This partnership produced SafeUpdater, a secure Electron auto-updater reference implementation developed as part of a university thesis.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Doyensec competitors and assessment
Company assessmentMarket position
Weaknesses4 records
Competitive moat4 records
Key highlights6 records
Customer concentration
Doyensec social profiles
Digital presenceDoyensec financial estimates
Financial estimateRevenue estimate
Valuation estimate
Doyensec leadership team
Management profileNumber of profiles
Profiles2 records
Doyensec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Doyensec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Doyensec
What does Doyensec do?
Doyensec provides offensive application security consulting services including penetration testing, source code review, reverse engineering, and security design across web, mobile, desktop, GraphQL, ElectronJS, cloud, IoT, smart contract, and AI/LLM platforms. The firm also develops proprietary open-source and commercial security testing tools (e.g., Electronegativity, InQL, ELBaph, maSSO, Session Switcher) used by security practitioners worldwide.
Is Doyensec a public or private company?
Doyensec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Doyensec founded?
Doyensec was founded in 2017. It employs 1 to 10 people.
Where is Doyensec based?
Doyensec is headquartered in San Francisco, United States, in the North America region.
How does Doyensec make money?
One revenue line is on record: security Consulting Services.
Does Doyensec have an API?
No public API is recorded for Doyensec.
What industry is Doyensec in?
Doyensec's product category is Application Security Consulting. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of FSAPABAI, Smart Contract Security Tooling (static/dynamic analysis, formal verification). Its NAICS code is 54169 and its SIC code is 8734.