ZERODIUM
ZERODIUM is a Washington, D.C.-based premium broker, founded in 2015 by Chaouki Bekrar, that acquires zero-day exploits from independent security researchers and resells them under confidential terms to a vetted roster of government agencies and large corporations.
- Company typePrivate
- Founded2015
- HeadquartersWashington, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
ZERODIUM firmographics
Firmographics- Name
- ZERODIUM
- Website
- https://zerodium.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ZERODIUM is a Washington, D.C.-based premium broker, founded in 2015 by Chaouki Bekrar, that acquires zero-day exploits from independent security researchers and resells them under confidential terms to a vetted roster of government agencies and large corporations.
- Ownership category
- akta.pro rank
ZERODIUM industry classification
Industry- Product category
- Cybersecurity Exploit Brokerage
- NAICS
- Investigation, Guard, and Armored Car Services (56161)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
Keywords
Where ZERODIUM is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Markets served
ZERODIUM business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D
ZERODIUM product offering
Product offeringCore offering
ZERODIUM operates as a premium exploit acquisition platform that purchases zero-day exploits and previously undisclosed security vulnerabilities from independent security researchers and brokers them to vetted buyers, primarily government agencies and large corporations. The company runs a confidential, quote-based acquisition process paying researchers for high-impact vulnerability research and reselling/exclusively distributing those capabilities to its institutional client base.
Differentiator
Problem solved
Functional benefit
Products and services
- ZERODIUM Exploit Acquisition Platform
Companies that use ZERODIUM
Customer profileIdeal customer profiles3 records
ZERODIUM technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
ZERODIUM competitors and assessment
Company assessmentEmerging players
- VulnCheck: Emerging vulnerability intelligence platform providing exploit and vulnerability data to enterprise and government. Smaller scale than ZERODIUM with partial overlap in vulnerability research services and emerging customer base.
- Bugcrowd: Crowdsourced cybersecurity platform with bug-bounty and vulnerability disclosure programs. Adjacent in researcher-to-buyer matchmaking, though focused on legitimate enterprise disclosure rather than offensive exploit sales to governments.
- HackerOne: Bug-bounty platform connecting researchers with enterprise and government programs. Operates a different model (legitimate disclosure, lower payouts) but competes for the same researcher talent pool and overlaps on government buyers.
Broad incumbents
- CrowdStrike: Major endpoint and threat intelligence platform with adversary-focused intelligence services that overlap with ZERODIUM's intelligence delivery. Operates from a defensive rather than offensive-cyber posture at much larger scale.
- Mandiant (Google Cloud): Major threat intelligence and incident response firm (now part of Google Cloud). Adjacent through vulnerability intelligence services, though focused more on defensive analysis and attribution than offensive exploit acquisition.
- Recorded Future: Large threat intelligence platform serving government and enterprise with broad intelligence services. Comparable buyer base and intelligence mission to ZERODIUM, though delivers defensive threat data rather than offensive exploits.
- NSO Group: Israeli offensive cyber company that develops and sells surveillance exploits to government clients. Overlaps with ZERODIUM in offensive cyber capabilities and government buyer base, though operates as an integrated product company rather than an exploit marketplace.
- iDefense (Accenture): Accenture's vulnerability intelligence unit, providing threat data to government and enterprise customers. Adjacent in vulnerability research services and customer overlap with ZERODIUM, though embedded in a much larger consulting franchise.
Direct peers
- Crowdfense: UAE-based exploit acquisition platform that pays researchers for zero-day vulnerabilities and resells them to government clients. Directly competes with ZERODIUM in the same exploit-broker market with a similar marketplace model and government buyer base.
- Exodus Intelligence: Austin-based vulnerability research firm that acquires zero-day exploits and provides intelligence to government and enterprise customers. Closest US-based direct competitor to ZERODIUM with overlapping researcher supply and buyer demand.
Market position
Customer concentration
ZERODIUM social profiles
Digital presenceZERODIUM financial estimates
Financial estimateRevenue estimate
Valuation estimate
ZERODIUM leadership team
Management profileNumber of profiles
Profiles1 record
ZERODIUM funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ZERODIUM M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ZERODIUM
What does ZERODIUM do?
ZERODIUM operates as a premium exploit acquisition platform that purchases zero-day exploits and previously undisclosed security vulnerabilities from independent security researchers and brokers them to vetted buyers, primarily government agencies and large corporations. The company runs a confidential, quote-based acquisition process paying researchers for high-impact vulnerability research and reselling/exclusively distributing those capabilities to its institutional client base.
Is ZERODIUM a public or private company?
ZERODIUM is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was ZERODIUM founded?
ZERODIUM was founded in 2015. It employs 11 to 50 people.
Where is ZERODIUM based?
ZERODIUM is headquartered in Washington, United States, in the North America region.
Who are ZERODIUM's main competitors?
Emerging players on record are VulnCheck, Bugcrowd and HackerOne. Broad incumbents are CrowdStrike, Mandiant (Google Cloud), Recorded Future, NSO Group and iDefense (Accenture). Direct peers are Crowdfense and Exodus Intelligence.
Does ZERODIUM have an API?
No public API is recorded for ZERODIUM.
What industry is ZERODIUM in?
ZERODIUM's product category is Cybersecurity Exploit Brokerage. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction. Its NAICS code is 56161 and its SIC code is 7381.