Crowdfense
- Company typePrivate
- Founded2017
- HeadquartersAbu Dhabi, United Arab Emirates
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
Crowdfense firmographics
Firmographics- Name
- Crowdfense
- Legal name
- Crowdfense
- Website
- https://crowdfense.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
Crowdfense industry classification
Industry- Product category
- Offensive Cybersecurity / Vulnerability Research and Exploit Acquisition
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
- akta.pro secondary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where Crowdfense is headquartered
LocationHeadquarters
- HQ city
- Abu Dhabi
- HQ country
- United Arab Emirates
- HQ region
- Middle East
Offices1 record
Markets served
Crowdfense business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Supply Chain, Personnel, Operations, Marketing or Sales, Infrastructure
Revenue model
- Zero-Day Exploit Acquisition and Resale: Crowdfense acquires zero-day vulnerabilities and exploits directly from independent security researchers through its VRH platform. After technical validation and documentation, acquired capabilities are delivered to vetted institutional clients (governments, intelligence agencies, LEAs, system integrators) under strict legal, compliance, and export control frameworks. Revenue is generated through the margin between acquisition costs and resale to clients.
- N-Day Vulnerability Feed Subscription: Subscription-based intelligence service providing real-time exploits and technical analysis for publicly disclosed high-risk vulnerabilities. Red Team Package includes 30+ root cause/patch analysis reports and 24+ weaponized exploits annually. APT Simulation Package adds version-porting support and up to 1 zero-day exploit annually.
- Custom Exploit Development: Clients can submit tailored requirements for custom exploit development targeting specific capabilities not already in the portfolio. Crowdfense coordinates with its global researcher network to fulfill custom development requests.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | Android Zero Click Full Chain (WhatsApp, RCS): up to $5M |
| One time/ perpetual license | Multi-year contract | iOS Zero Click Full Chain (iMessage): up to $7M |
| One time/ perpetual license | Multi-year contract | Chrome One Click Full Chain (RCE + v8 SBX + SBX + LPE): $2M-$3M |
| One time/ perpetual license | Multi-year contract | Microsoft Windows Zero Click Full Chain: $1M |
| Subscription | Annual | Red Team Package: subscription service |
| Subscription | Annual | APT Simulation Package: subscription service |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels4 records
Crowdfense product offering
Product offeringCore offering
Crowdfense operates as a vulnerability research hub and acquisition platform that purchases fully functional zero-day exploits and advanced vulnerability research from independent security researchers through its private Vulnerability Research Hub (VRH). Acquired capabilities are validated, documented, and resold under strict export control and compliance frameworks to vetted institutional clients including governments, intelligence agencies, law enforcement agencies, and trusted system integrators. The company also operates an N-Day Vulnerability Feed subscription service delivering weaponized exploits and detailed technical analyses of high-risk vulnerabilities for red team and threat emulation use cases.
Product overview
Crowdfense operates as a vulnerability research hub and acquisition platform with two core offerings: an Exploit Acquisition Program that purchases zero-day exploits from independent researchers, and an N-Day Vulnerability Feed subscription service. The Vulnerability Research Hub (VRH) serves as the private platform facilitating secure researcher submissions. The N-Day Feed delivers curated vulnerability intelligence and weaponized exploits through two subscription tiers (Red Team Package and APT Simulation Package) for threat simulation and vulnerability prioritization. The company connects elite independent researchers with vetted institutional clients including governments and intelligence agencies.
Differentiator
Problem solved
Functional benefit
Products and services
- Exploit Acquisition Program A vulnerability acquisition program that purchases fully functional zero-day exploits and previously unreported capabilities from independent security researchers, offering rewards ranging from USD 10,000 to USD 7 million for full exploit chains.
- Vulnerability Research Hub (VRH) An exclusive, private platform for top-tier security researchers to anonymously submit, track, discuss, and monetize zero-day vulnerabilities and exploit chains in a secure confidential environment featuring encrypted communications, hardware security modules, and standardized submission templates.
- N-Day Vulnerability Feed A subscription-based intelligence service providing real-time vulnerability intelligence, fully weaponized exploits, and detailed technical analysis for high-risk vulnerabilities actively exploited in the wild by APT groups, ransomware operators, and cybercriminals, covering Microsoft, Google, Adobe, Fortinet, Ivanti, Juniper, and other major vendors.
Quantifiable outcome
- Access to weaponized intelligence used by APT groups and nation-state operators for defense validation
- +2 more outcomes
Companies that use Crowdfense
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles4 records
Crowdfense technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Crowdfense partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- NDAY SecuritycoreStrategic partnership where Crowdfense's N-Day Vulnerability Feed is integrated into NDAY Security's proprietary continuous exploitability platform and AttackBench autonomous penetration testing agent. The integration provides security teams with real-world weaponized exploits for threat validation, enabling customers to test defenses against actively exploited vulnerabilities. Combined offering available to select customers beginning Q2 2026.
Scale indicators4 records
Recent moves3 records
Expansion highlights5 records
Crowdfense competitors and assessment
Company assessmentEmerging players
- NSO Group: NSO Group develops and licenses offensive spyware (Pegasus) to government clients. While it operates further down the stack (full spyware products) than Crowdfense, it competes for the same government cyber budgets and increasingly faces the same regulatory and reputational headwinds.
- DEVCORE: DEVCORE is an offensive security research firm known for high-impact vulnerability disclosures (e.g., ProxyLogon, Exchange Server exploits) supplying both vendor patches and offensive customers; it competes for elite researcher talent and is a credible alternative supplier in the APAC region.
- NDAY Security: NDAY Security operates a continuous exploitability platform and AttackBench autonomous AI penetration testing agent, now integrating Crowdfense's N-Day Feed. It is a partner but also a thematic peer in offensive-security productization, with potential to develop in-house vulnerability capabilities over time.
Broad incumbents
- Bugcrowd: Bugcrowd runs a crowdsourced vulnerability disclosure and bug-bounty platform for enterprise customers. Like HackerOne, it competes for security researcher attention and adjacent budget, but addresses n-day and responsible disclosure rather than offensive zero-day acquisition.
- HackerOne: HackerOne operates a large-scale vulnerability disclosure and bug-bounty platform serving enterprise and government clients. It overlaps with Crowdfense at the researcher-engagement layer (N-Day and bug-bounty style work) but is not a zero-day broker.
- Trend Micro Zero Day Initiative (ZDI): ZDI is the largest and longest-running public bug-bounty and vulnerability acquisition program, run by Trend Micro. It is broader in scope and vendor-oriented (responsible disclosure) rather than offensive-only, but directly competes for top researcher talent and shapes market pricing for zero-day research.
Direct peers
- Q-CORE (formerly Q) Security: Q-CORE runs an exploit acquisition program that pays for zero-day vulnerabilities targeting iOS, Android, Windows, and enterprise software and supplies them to government clients, directly comparable in target surface and buyer profile to Crowdfense.
- Exodus Intelligence: Exodus Intelligence operates a zero-day vulnerability research and acquisition program with a Vulnerability Research subscription product for vetted subscribers (governments and enterprises), closely matching Crowdfense's VRH + N-Day Feed dual model.
- Operation Zero: Operation Zero is an exploit acquisition program paying for full-chain zero-day vulnerabilities on major platforms, with disclosed bounties up to USD 20M. It is a direct competitor in zero-day brokering, with a similar target surface and government buyer profile.
- Zerodium: Zerodium is the most direct competitor: a vulnerability acquisition platform headquartered in the US/EU that buys zero-day exploits from researchers and resells to vetted government clients under a similar brokering model with multi-million-dollar bounties.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Crowdfense social profiles
Digital presenceCrowdfense financial estimates
Financial estimateRevenue estimate
Valuation estimate
Crowdfense leadership team
Management profileNumber of profiles
Profiles1 record
Crowdfense funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Crowdfense M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Crowdfense
What does Crowdfense do?
Crowdfense operates as a vulnerability research hub and acquisition platform that purchases fully functional zero-day exploits and advanced vulnerability research from independent security researchers through its private Vulnerability Research Hub (VRH). Acquired capabilities are validated, documented, and resold under strict export control and compliance frameworks to vetted institutional clients including governments, intelligence agencies, law enforcement agencies, and trusted system integrators. The company also operates an N-Day Vulnerability Feed subscription service delivering weaponized exploits and detailed technical analyses of high-risk vulnerabilities for red team and threat emulation use cases.
Is Crowdfense a public or private company?
Crowdfense is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Crowdfense founded?
Crowdfense was founded in 2017. It employs 11 to 50 people.
Where is Crowdfense based?
Crowdfense is headquartered in Abu Dhabi, United Arab Emirates, in the Middle East region.
How does Crowdfense make money?
Three revenue lines are on record. Zero-Day Exploit Acquisition and Resale is the primary driver. The others are N-Day Vulnerability Feed Subscription and custom Exploit Development.
Who are Crowdfense's main competitors?
Emerging players on record are NSO Group, DEVCORE and NDAY Security. Broad incumbents are Bugcrowd, HackerOne and Trend Micro Zero Day Initiative (ZDI). Direct peers are Q-CORE (formerly Q) Security, Exodus Intelligence, Operation Zero and Zerodium.
Does Crowdfense have an API?
No public API is recorded for Crowdfense.
What industry is Crowdfense in?
Crowdfense's product category is Offensive Cybersecurity / Vulnerability Research and Exploit Acquisition. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction, with a secondary code of FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services.