HostedScan Security
HostedScan Security is a self-funded Seattle-based SaaS company that aggregates multiple industry-leading vulnerability scanners (OpenVAS, Tenable Nessus, OWASP ZAP, Nmap, Nuclei) into a single cloud platform, serving MSPs and internal IT/security teams with subscription-based continuous vulnerability scanning, compliance reporting, and API-driven DevSecOps workflows.
- Company typePrivate
- Founded2019
- HeadquartersSeattle, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What HostedScan Security does
HostedScan Security, founded in 2019 in Seattle, Washington and operating as HostedScan, LLC (Delaware-registered), is a private, self-funded cybersecurity SaaS company offering a unified vulnerability scanning and management platform. The platform aggregates multiple industry-standard scanners - Greenbone OpenVAS, Tenable Nessus, Rapid7 InsightVM, OWASP ZAP, Nmap, SSLyze, and Nuclei - behind a single management interface, with daily feed updates and capabilities including attack surface mapping, authenticated web application scanning, internal network scanning, and subdomain discovery. The product is delivered as cloud-based, multi-tenant SaaS with a REST API and webhooks for DevSecOps workflows, and supports integrations with AWS, Azure, DigitalOcean, Vanta, Slack, Snyk, and GitHub Dependabot.
HostedScan generates revenue primarily through tiered subscriptions ($39/month Basic, $109/month Premium, $189/month Professional) plus a dedicated $189/month MSP plan with 20 targets and white-label reporting, with usage-based expansion as customers add targets beyond plan limits. Go-to-market combines product-led growth (14-day self-serve free trial, PLG sign-up) with a dedicated MSP/MSSP partner program for managed service resellers and a 30% recurring affiliate program for cybersecurity creators. Customer segments are managed service providers and internal IT/security teams of small-to-enterprise organizations; named logos include Porsche, Expedia Group, University of Oxford, Yamaha, CoinMe, BB Americas, WonderProxy, Principle Networks, and Cobrowse.io, with quantified claims of 5,000+ MSPs and IT teams served. The leadership team consists of CEO Kyle Cooper, Head of Product Richard Bliss, and Head of Enterprise Solutions John Snyder, with no external institutional funding.
HostedScan Security firmographics
Firmographics- Name
- HostedScan Security
- Legal name
- HostedScan, LLC
- Website
- https://hostedscan.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- HostedScan Security is a self-funded Seattle-based SaaS company that aggregates multiple industry-leading vulnerability scanners (OpenVAS, Tenable Nessus, OWASP ZAP, Nmap, Nuclei) into a single cloud platform, serving MSPs and internal IT/security teams with subscription-based continuous vulnerability scanning, compliance reporting, and API-driven DevSecOps workflows.
- Ownership category
- akta.pro rank
HostedScan Security industry classification
Industry- Product category
- Vulnerability Management Software
- NAICS
- Other Computer Related Services (541519), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industries
- Configuration & Exposure Hardening (CIS/Benchmarking) (HDADAHAH), Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
Keywords
Where HostedScan Security is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
HostedScan Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure, Others
Revenue model
- Subscription Plans: Tiered subscription model with Basic ($39/mo), Premium ($109/mo), and Professional ($189/mo) plans. All plans include 5 targets with additional targets available at scale. Annual billing offers up to 34% savings.
- Target-based Expansion: Usage-based expansion based on number of targets scanned. Customers can add more targets beyond the included 5 per plan at scaled pricing.
- MSP/MSSP Program: Reseller-friendly MSP program with reduced rates, starting at $189/mo for 20 targets with white-label capabilities and multi-tenant workspaces.
- Affiliate Referrals: 30% recurring commission for affiliates who refer new customers to the platform.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Basic plan for small teams - $39/mo |
| Subscription | Monthly | Premium plan with authenticated scans - $109/mo |
| Subscription | Monthly | Professional plan with enterprise features - $189/mo |
| Subscription | Monthly | MSP Plan for managed service providers - $189/mo |
| Unit Pricing | Monthly | Additional targets pricing |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
HostedScan Security product offering
Product offeringCore offering
HostedScan Security delivers a unified, cloud-based vulnerability scanning-as-a-service platform that consolidates multiple industry-leading commercial and open-source scanners (Greenbone OpenVAS, Tenable Nessus, Rapid7 InsightVM, OWASP ZAP, Nmap, SSLyze, and Nuclei) under a single management dashboard. The platform performs continuous external and internal scanning of websites, servers, networks, and APIs, surfaces CVEs and OWASP Top 10 risks with CVSS and EPSS prioritization, automates scheduling and alerting, and produces audit-ready compliance reports for SOC 2, ISO 27001, GDPR, and TPN use cases.
Product overview
HostedScan Security is a unified vulnerability scanning-as-a-service platform that aggregates multiple industry-leading open-source and commercial scanners into a single integrated platform. The core HostedScan Platform provides centralized vulnerability management with attack surface mapping, compliance reporting, and automated alerting. The portfolio includes scanner modules: OpenVAS (network), Tenable Nessus (enterprise vulnerability), Rapid7 InsightVM (enterprise), OWASP ZAP (web application), Nmap (port), SSLyze (TLS/SSL), Nuclei (template-based), and API Security scanning. Additional modules cover authenticated web scanning, internal network scanning, and WordPress-specific scanning. The Custom Reporting Engine and White Label Reporting add-ons enable branded compliance reports. The platform also offers standalone cybersecurity tools (Subdomain Discovery, SPF/DKIM/DMARC Checker) and specialized MSP/MSSP and Enterprise/Reseller programs with multi-tenant workspaces and self-hosted options.
Differentiator
Problem solved
Functional benefit
Products and services
- HostedScan Vulnerability Scanning Platform Cloud-based SaaS that aggregates Greenbone OpenVAS, Tenable Nessus, Rapid7 InsightVM, OWASP ZAP, Nmap, SSLyze, and Nuclei scanners under a unified dashboard, providing external and internal vulnerability scanning, attack surface mapping, CVE and OWASP Top 10 detection with CVSS and EPSS scoring, scheduling, alerting, compliance reporting, and DevSecOps API and webhook integration for IT and security teams.
- MSP/MSSP Partner Program Dedicated channel offering for managed service providers and MSSPs that bundles the HostedScan platform with reseller pricing starting at $189 per month for 20 targets, multi-tenant workspaces, client-specific data isolation, white-label branded client reporting, and priority support so providers can deliver managed vulnerability scanning to their end clients.
- Subdomain Discovery Tool Free standalone cybersecurity utility that uses Certificate Transparency Logs and DNS data to automatically discover subdomains associated with an organization and surface potentially forgotten or exposed assets in the external attack surface.
- SPF DKIM DMARC Security Tool Free standalone email authentication checker that validates SPF, DKIM selector, and DMARC DNS records for a domain and returns actionable recommendations to improve email deliverability and prevent spoofing.
Quantifiable outcome
- Cost savings of up to $3,850 per year compared to alternative vulnerability scanning products
- +3 more outcomes
Companies that use HostedScan Security
Customer profileNamed customers12 records
Segments3 records
Ideal customer profiles3 records
HostedScan Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
Feature9 records
HostedScan Security partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core.
- AWS (Amazon Web Services)coreIntegration with AWS allows customers to automatically import targets from AWS infrastructure and manage vulnerability scanning from HostedScan platform. Read-only integration for secure target discovery.
- Azure (Microsoft)coreIntegration with Azure allows automatic import of cloud targets from Microsoft Azure environment. Enables continuous vulnerability scanning of Azure-hosted infrastructure.
- VantacoreIntegration with Vanta GRC platform allows pushing vulnerability scan results into Vanta's governance, risk, and compliance management system for unified security posture reporting.
- SlackcoreSlack integration enables real-time notifications and alerts when new vulnerabilities are discovered, allowing security teams to receive and act on findings within their existing communication workflows.
- Greenbone / OpenVAScorePlatform leverages OpenVAS (Greenbone) as primary network vulnerability scanner with 170,000+ Network Vulnerability Tests, updated daily. Core scanning engine for server and network vulnerability detection.
- TenablecoreTenable Nessus scanner included with Professional plan for industry-leading vulnerability detection. Available as add-on scanner for comprehensive enterprise-grade scanning coverage.
- Rapid7coreRapid7 InsightVM scanner available for enterprise-grade vulnerability management with live monitoring and prioritized risk assessment.
- OWASP ZAPcoreOWASP Zed Attack Proxy integrated as primary web application vulnerability scanner. Detects OWASP Top 10 risks, SQL injection, XSS, and other web vulnerabilities. Also used for API security scanning via OpenAPI/Swagger import.
- NmapcoreIndustry-standard Nmap port scanner for TCP and UDP port discovery, network mapping, and firewall configuration verification. Powers external attack surface mapping.
- Project Discovery (Nuclei)coreNuclei vulnerability scanner with community-driven template engine (4,000+ templates) for fast, template-based CVE and misconfiguration detection.
- SSLyzecoreSSLyze TLS/SSL vulnerability scanner for detecting weak ciphers, expired certificates, Heartbleed, ROBOT vulnerability, and TLS version support issues.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
HostedScan Security competitors and assessment
Company assessmentDirect peers
- Tenable: Tenable is the vendor behind Nessus, which HostedScan embeds in its Professional plan. Tenable also sells Tenable.io / Tenable One as a direct vulnerability management SaaS competing for the same buyers (Porsche, Expedia, etc.), making it the most direct incumbent competitor.
- Rapid7: Rapid7's InsightVM is offered as a scanner module inside HostedScan and is also sold as a standalone cloud vulnerability management platform targeting the same mid-market and enterprise IT security buyers.
- Qualys: Qualys VMDR is a long-standing enterprise vulnerability management SaaS that competes directly with HostedScan on continuous scanning, asset discovery, and compliance reporting for IT teams and MSSPs.
- Intruder: Intruder is a vulnerability scanning SaaS targeted at SMB and mid-market IT teams with continuous scanning, attack surface monitoring, and simple onboarding — a close analog to HostedScan's product-led, multi-scanner approach.
- Detectify: Detectify combines external attack surface management with continuous DAST/web application scanning, competing for the same SaaS buyers prioritizing automated, cloud-based vulnerability assessment without on-prem installs.
- Probely: Probely offers DAST and API vulnerability scanning as a SaaS targeted at developers, security teams, and MSSPs with white-label and multi-tenant options — directly comparable to HostedScan's mid-tier authenticated and web application scanning modules.
- Greenbone / OpenVAS: Greenbone produces the OpenVAS scanner engine that HostedScan uses as its primary network vulnerability scanner, and also sells commercial Greenbone Enterprise Edition appliances and cloud editions that compete directly with HostedScan's network scanning offering.
- StackHawk: StackHawk is a DAST platform purpose-built for developers and DevSecOps workflows, with CI/CD integration — directly comparable to HostedScan's API and authenticated web application scanning capabilities.
- Indusface: Indusface offers application vulnerability scanning, DAST, and managed services targeted at SMB and mid-market customers with compliance reporting — overlapping with HostedScan's web application scanning and compliance use cases.
- BreachLock: BreachLock delivers vulnerability scanning and penetration testing as a service for SMBs and MSSPs, including white-label options — closely mirroring HostedScan's MSP/MSSP program and SaaS delivery model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks3 records
Key highlights7 records
Customer concentration
HostedScan Security social profiles
Digital presenceHostedScan Security compliance and trust
Trust signalCompliance5 records
HostedScan Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
HostedScan Security leadership team
Management profileNumber of profiles
Profiles3 records
HostedScan Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
HostedScan Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about HostedScan Security
What does HostedScan Security do?
HostedScan Security delivers a unified, cloud-based vulnerability scanning-as-a-service platform that consolidates multiple industry-leading commercial and open-source scanners (Greenbone OpenVAS, Tenable Nessus, Rapid7 InsightVM, OWASP ZAP, Nmap, SSLyze, and Nuclei) under a single management dashboard. The platform performs continuous external and internal scanning of websites, servers, networks, and APIs, surfaces CVEs and OWASP Top 10 risks with CVSS and EPSS prioritization, automates scheduling and alerting, and produces audit-ready compliance reports for SOC 2, ISO 27001, GDPR, and TPN use cases.
Is HostedScan Security a public or private company?
HostedScan Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was HostedScan Security founded?
HostedScan Security was founded in 2019. It employs 1 to 10 people.
Where is HostedScan Security based?
HostedScan Security is headquartered in Seattle, United States, in the North America region.
How does HostedScan Security make money?
Four revenue lines are on record. Subscription Plans are the primary driver. The others are target-based Expansion, MSP/MSSP Program and affiliate Referrals.
Who are HostedScan Security's main competitors?
Direct peers on record are Tenable, Rapid7, Qualys, Intruder, Detectify, Probely, Greenbone / OpenVAS, StackHawk, Indusface and BreachLock.
Does HostedScan Security have an API?
Yes. REST API and webhooks for programmatically managing targets, triggering scans, and receiving vulnerability scan results. Enables CI/CD integration with GitHub Actions, CircleCI, Azure, and AWS. Users can embed HostedScan into their own products and services. Developer documentation is at docs.hostedscan.com/api.
What industry is HostedScan Security in?
HostedScan Security's product category is Vulnerability Management Software. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADAHAH, Configuration & Exposure Hardening (CIS/Benchmarking). Its NAICS code is 541519 and its SIC code is 7372.