Cure53
Cure53 is a Berlin-based, founder-owned application security firm founded in 2007 that delivers manual penetration testing, code audits, and infrastructure/cryptography assessments to enterprise clients in VPN, password management, cryptocurrency, and privacy verticals, operated by a network of ~30 independent security experts.
- Company typePrivate
- Founded2007
- HeadquartersBerlin, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Cure53 does
Cure53 is a Berlin-based, founder-owned application security firm founded in 2007 by Dr.-Ing. Mario Heiderich. The company operates as a network of approximately 30 independent security experts, including seven PhD-credentialed researchers, who deliver manual penetration testing, code audits, and infrastructure/cryptography assessments to enterprise clients. Its methodology emphasizes black-box and white-box testing across web, mobile, hardware, and crypto targets, with a stated preference for human-driven analysis, close communication with client development teams, and short, substantive reports without analyst-padding artifacts.
Cure53's commercial model is project-based professional services with custom quote-based pricing and multi-year engagements; deliverables are detailed written security reports rather than software products. The firm serves a concentrated set of high-profile enterprise clients — including ExpressVPN, 1Password, Coinbase, MetaMask, NordVPN, Proton, Mullvad, TunnelBear, Threema, Mozilla, and Obsidian — primarily in VPN, password management, cryptocurrency/wallets, and privacy/messaging verticals. Distribution is direct enterprise engagement (no resellers or marketplaces), supplemented by a content-led marketing strategy anchored on a public archive of 30+ audit reports.
The company also maintains an open-source security tooling ecosystem — most notably DOMPurify (a widely deployed XSS sanitization library), HTTPLeaks, and the HTML5 Security Cheatsheet — which functions as both a credibility asset and a top-of-funnel developer-relations channel. Cure53 is privately held, bootstrapped, and reports no external venture or institutional investors; revenue, headcount expansion metrics, and financial results are not publicly disclosed.
Cure53 firmographics
Firmographics- Name
- Cure53
- Legal name
- Cure53
- Website
- https://cure53.de
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Cure53 is a Berlin-based, founder-owned application security firm founded in 2007 that delivers manual penetration testing, code audits, and infrastructure/cryptography assessments to enterprise clients in VPN, password management, cryptocurrency, and privacy verticals, operated by a network of ~30 independent security experts.
- Ownership category
- akta.pro rank
Cure53 industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Computer Related Services (541519)
- akta.pro primary industry
- Managed Detection & Response (MDR) (BPAEADAA)
- akta.pro secondary industries
- Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK), Identity Threat Detection & Response (ITDR) (HDAEAJAH)
Keywords
Where Cure53 is headquartered
LocationHeadquarters
- HQ city
- Berlin
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Cure53 business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Security Assessment Services: Cure53 generates revenue through project-based security assessments including penetration tests, code audits, infrastructure security reviews, and cryptographic system evaluations. Engagements are custom-quoted based on scope and complexity. The company has performed several hundreds of penetration tests since founding in 2007.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom project-based security assessments |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels7 records
Cure53 product offering
Product offeringCore offering
Cure53 is a Berlin-based security assessment firm that delivers project-based penetration tests, code audits, and architecture and cryptography reviews for web applications, mobile apps, infrastructure, and crypto tools. Engagements are custom-scoped, performed by a network of independent security experts, and concluded with detailed written penetration test reports. The firm also maintains widely used open-source security tools such as DOMPurify, HTTPLeaks, and the HTML5 Security Cheatsheet.
Product overview
Cure53 operates as a security assessment firm offering a portfolio of professional services including penetration testing, security architecture consulting, and infrastructure/cryptography audits. The company maintains and publishes several open-source security tools—DOMPurify (XSS protection library), HTTPLeaks (leak detection tool), and the HTML5 Security Cheatsheet—available on GitHub. Deliverables consist primarily of detailed written security reports rather than software products. Founded in 2007, the company has conducted hundreds of penetration tests across web applications, mobile apps, hardware interfaces, libraries, and crypto tools.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Black-box and white-box penetration testing services for web applications, mobile apps, online services, hardware interfaces, and libraries, covering languages including PHP, JavaScript, ActionScript, Java, Ruby, Python, Perl, C++, and Delphi. Offered to enterprise clients and software vendors.
- Security Analysis and Architectural Advice Pre-development security consulting that evaluates architecture and design choices, assesses the trustworthiness of third-party components, reviews the security posture of open-source dependencies, and identifies architectural pitfalls before code is written. Targeted at early-stage or fast-moving projects.
- Infrastructure, Platform and Cryptography Audits Detailed security audits of cloud infrastructure, server configurations, cryptographic algorithms, key management systems, encryption protocols, and platform security posture, assessing both hardware and software aspects of client systems.
- DOMPurify Open-source client-side HTML sanitization library that protects against XSS (Cross-Site Scripting) attacks by filtering and sanitizing HTML markup before rendering in the browser. Available for free use on GitHub.
- HTTPLeaks Open-source security testing tool for detecting HTTP leak vulnerabilities in web applications, helping identify where data may inadvertently be transmitted outside the intended secure context.
- HTML5 Security Cheatsheet (H5SC) Comprehensive open-source reference resource documenting security considerations and attack vectors related to HTML5 features and APIs.
Companies that use Cure53
Customer profileNamed customers17 records
Segments4 records
Ideal customer profiles4 records
Cure53 technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Cure53 partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Gothaer Allgemeine Versicherung AGminorCure53 maintains professional liability insurance through Gothaer Allgemeine Versicherung AG (and Gothaer Versicherungsbank VVaG per impressum) for their security assessment engagements. Insurance coverage is worldwide per their legal disclosures.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Cure53 competitors and assessment
Company assessmentDirect peers
- Secarma: UK-based penetration testing and cybersecurity consultancy. Closely comparable boutique consulting model with similar enterprise buyer focus and manual testing emphasis.
- Nviso: European (Swiss/Belgian) cybersecurity firm specializing in penetration testing, red teaming, and security research. Closely comparable to Cure53 in geographic positioning, boutique consulting model, and high-end enterprise client base.
- Trail of Bits: US-based boutique cybersecurity firm specializing in manual penetration testing, cryptographic audits, and security research with deep Web3 focus. Highly comparable to Cure53 in target clientele (crypto, privacy) and delivery model (expert-led, research-driven consulting).
- Bishop Fox: US-based offensive security firm focused on penetration testing, red teaming, and security research. Closely comparable to Cure53 in its specialist consulting model, research culture, and enterprise client base for high-end security assessments.
Emerging players
- Sigma Prime: Specialized blockchain security firm focused on Ethereum 2.0 and proof-of-stake audit work. Comparable to Cure53's crypto security vertical as a specialist direct competitor.
- OpenZeppelin: Specialized in smart contract security audits and Web3 security tooling. A direct competitor in Cure53's crypto security audit vertical, with a broader product ecosystem (security libraries, monitoring).
Broad incumbents
- HackerOne: Operates a platform connecting enterprises to ethical hackers for bug bounties and penetration testing. Comparable as an alternative procurement channel for vulnerability discovery services, though platform-based rather than boutique consulting.
- NCC Group: Global cybersecurity services firm offering penetration testing, managed detection, and software resilience services. Represents a larger incumbent competing with Cure53 in the same enterprise security assessment market but with a much broader portfolio and global footprint.
- Kudelski Security: Enterprise cybersecurity and managed security services provider with strong cryptographic and incident response capabilities. Competes with Cure53 for high-assurance security engagements including crypto and infrastructure audits.
- NCC Group (ex-Accenture Security, divested): Large-scale cybersecurity consulting with pen testing offerings. Relevant for benchmarking pricing and enterprise procurement dynamics in the same service category as Cure53.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights6 records
Customer concentration
Cure53 social profiles
Digital presenceCure53 financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cure53 leadership team
Management profileNumber of profiles
Profiles10 records
Cure53 funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cure53 M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cure53
What does Cure53 do?
Cure53 is a Berlin-based security assessment firm that delivers project-based penetration tests, code audits, and architecture and cryptography reviews for web applications, mobile apps, infrastructure, and crypto tools. Engagements are custom-scoped, performed by a network of independent security experts, and concluded with detailed written penetration test reports. The firm also maintains widely used open-source security tools such as DOMPurify, HTTPLeaks, and the HTML5 Security Cheatsheet.
Is Cure53 a public or private company?
Cure53 is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cure53 founded?
Cure53 was founded in 2007. It employs 11 to 50 people.
Where is Cure53 based?
Cure53 is headquartered in Berlin, Germany, in the Europe region.
How does Cure53 make money?
One revenue line is on record: security Assessment Services.
Who are Cure53's main competitors?
Direct peers on record are Secarma, Nviso, Trail of Bits and Bishop Fox. Emerging players are Sigma Prime and OpenZeppelin. Broad incumbents are HackerOne, NCC Group, Kudelski Security and NCC Group (ex-Accenture Security, divested).
Does Cure53 have an API?
No public API is recorded for Cure53.
What industry is Cure53 in?
Cure53's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAA, Managed Detection & Response (MDR), with a secondary code of FSAPAJAK, Security Testing Tooling (SAST/DAST for smart contracts, fuzzing). Its NAICS code is 541519.