Synacktiv
Synacktiv is a Paris-based French offensive-security firm offering penetration testing, Red Team operations, reverse-engineering, and incident response (CSIRT), supported by five commercialized proprietary tools and CESTI/PASSI LPM/ANJ regulatory accreditations.
- Company typePrivate
- Founded2012
- HeadquartersParis, France
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Synacktiv does
Synacktiv is a French offensive-security specialist founded in 2012 and headquartered in Paris, with five additional offices across France (Toulouse, Lyon, Rennes, Lille, Bordeaux). The firm operates four service lines — penetration testing / Red Team, reverse-engineering, development, and incident response / CSIRT — delivered through approximately 30 fully remote specialists plus on-site staff organized into dedicated poles. Synacktiv holds CESTI, PASSI LPM, and ANJ accreditations, qualifying it to audit the most sensitive French state, defence, and gaming-sector information systems.
The company has cumulatively delivered 3,447 security assessments, worked with 188 recurring clients, and produced 320 publications and 310 public vulnerabilities, with a research track record anchored by repeated Pwn2Own Automotive wins (2024 Tesla full-chain $200,000 + Model 3; 2025 Tesla Wall Connector; 2026 Tesla infotainment zero-day). Synacktiv also commercializes five internally developed penetration-testing tools — Kraqozorus (password recovery), Houdini (hardware implant for physical/logical pentests), Disconet (collaborative pentest automation with 82 plugins and 375 vulnerability models), Oursin (spear-phishing campaign platform), and Leakozorus (9 billion-record credential aggregation) — plus REVEL·IO, a forensic mobile-device extraction solution targeting European law enforcement.
Revenue is generated primarily through professional services engagements (pentest, audit, incident response, reverse-engineering) priced via custom quotes on multi-year contracts, supplemented by software licensing of the commercialized tool portfolio. The company is structured as a single-shareholder SAS with €20,000 share capital, is privately held with no disclosed external funding, and is led by founders Renaud Feil (Président), Nicolas Collignon, and Renaud Dubourguais. Go-to-market is consultative enterprise sales supported by thought-leadership marketing via blog, GitHub, conference talks, and competition participation.
Synacktiv firmographics
Firmographics- Name
- Synacktiv
- Legal name
- SYNACKTIV
- Website
- https://synacktiv.com
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Synacktiv is a Paris-based French offensive-security firm offering penetration testing, Red Team operations, reverse-engineering, and incident response (CSIRT), supported by five commercialized proprietary tools and CESTI/PASSI LPM/ANJ regulatory accreditations.
- Ownership category
- akta.pro rank
Synacktiv industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Scientific and Technical Consulting Services (54169), Scientific Research and Development Services (5417)
- SIC
- Services-Management Consulting Services (8742), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Penetration Testing Platforms (PTaaS) (HDADAHAG), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Synacktiv is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices6 records
Markets served
Synacktiv business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Security Services: Core revenue stream from penetration testing/red team engagements, security audits, reverse-engineering services, and incident response/CSIRT services. These are billable professional services engagements with enterprise clients.
- Commercialized Security Tools: Synacktiv commercializes 5 proprietary security testing tools (Kraqozorus, Houdini, Disconet, Oursin, Leakozorus). These tools are sold/licensed to clients to automate and optimize their own security testing activities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Professional services (pentest, audit, incident response) - custom quotes |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels7 records
Synacktiv product offering
Product offeringCore offering
Synacktiv provides offensive security professional services including penetration testing, red team operations, reverse-engineering, security audits, and incident response (CSIRT). The firm complements its services with five commercially-licensed, internally-developed security testing tools (Kraqozorus, Houdini, Disconet, Oursin, Leakozorus) and a forensic solution (REVEL·IO) targeting European law enforcement.
Product overview
Synacktiv offers a portfolio of five commercialized penetration testing tools: Kraqozorus (password cracking), Houdini (hardware implant for physical/logical pentesting), Disconet (collaborative automation platform), Oursin (spear phishing platform), and Leakozorus (credential aggregation/search). Additionally, REVEL·IO is a forensic solution for mobile device extraction targeting law enforcement. The company also provides professional services including penetration testing/Red Team, incident response (CSIRT), reverse-engineering, security audits, and development. All tools are developed internally and can be used independently or integrated with each other.
Differentiator
Problem solved
Functional benefit
Brands
- Kraqozorus: Commercial security tool for penetration testing
- Houdini
- Disconet
- Oursin
- Leakozorus
- REVEL·IO
Products and services
- Penetration Testing / Red Team Services Engagement-based offensive security services that simulate adversary tactics to identify vulnerabilities in client systems, networks, and applications. Targeted at large enterprises and government organizations needing comprehensive security validation.
- Incident Response (CSIRT)
Quantifiable outcome
- 3,447 security assessments performed since founding
- +2 more outcomes
Companies that use Synacktiv
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
Synacktiv technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
Synacktiv partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered minor.
- MobiSkillminorMobiSkill provides recruitment process hosting services for Synacktiv, handling candidate data on servers located in France as part of the recruitment process.
- SCALEWAYminorSCALEWAY (Online SAS) is the hosting provider for Synacktiv's website and IT infrastructure, providing cloud hosting services.
Scale indicators8 records
Recent moves5 records
Expansion highlights5 records
Synacktiv competitors and assessment
Company assessmentDirect peers
- Bishop Fox: US-headquartered offensive-security consulting firm offering penetration testing, red teaming, and adversary simulation. Highly comparable in service mix, talent-led research model, and high-end enterprise/government clientele.
- NCC Group: Global cybersecurity consulting and software firm with a sizable offensive-security practice (pentest, red team, source-code review). Comparable in service breadth, though larger, listed, and more geographically diversified.
- IOActive: Specialist offensive-security consultancy focused on penetration testing, hardware/IoT security, and reverse engineering. Closely comparable niche expertise, particularly to Synacktiv's hardware (Houdini, automotive) work.
- Wavestone: French-origin IT and cybersecurity consulting firm with a substantial cyber-defence practice covering pentesting, incident response, and compliance. Comparable French/EMEA footprint and regulated-sector client base.
Broad incumbents
- Devoteam: European IT consulting firm with a dedicated cybersecurity practice offering offensive testing, managed detection, and compliance services. Broader scope than Synacktiv, but overlapping in EMEA enterprise security consulting.
- Mandiant (Google Cloud): Global incident response and cyber-defence consultancy with deep offensive-security expertise, now part of Google Cloud. Comparable IR/CSIRT capabilities and adversary simulation services, but vastly larger scale.
- Trustwave: Global cybersecurity firm offering penetration testing, managed security services, and incident response. Overlaps with Synacktiv's service portfolio, but operates at much larger scale as an MSSP.
- Thales Cyber Solutions: Cyber-defence arm of Thales, offering certified security audits, cryptography, and sovereign cybersecurity solutions. Comparable French sovereign positioning and access to defense/regulated clients, but at vastly larger scale and as part of a defense prime.
Emerging players
- YesWeHack: European bug-bounty and vulnerability disclosure platform headquartered in France. Adjacent rather than direct: shares the French offensive-security ecosystem and regulated customer base, but competes on crowd-based rather than consultant-led models.
- Sekoia.io: French cybersecurity vendor offering an extended detection and response (XDR/SOAR) platform with cyber threat intelligence. Adjacent in the French cyber ecosystem and serves similar regulated buyers, but operates a SaaS product rather than consulting.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Synacktiv social profiles
Digital presenceSynacktiv compliance and trust
Trust signalCompliance3 records
Synacktiv financial estimates
Financial estimateRevenue estimate
Valuation estimate
Synacktiv leadership team
Management profileNumber of profiles
Profiles3 records
Synacktiv funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Synacktiv M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Synacktiv
What does Synacktiv do?
Synacktiv provides offensive security professional services including penetration testing, red team operations, reverse-engineering, security audits, and incident response (CSIRT). The firm complements its services with five commercially-licensed, internally-developed security testing tools (Kraqozorus, Houdini, Disconet, Oursin, Leakozorus) and a forensic solution (REVEL·IO) targeting European law enforcement.
Is Synacktiv a public or private company?
Synacktiv is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Synacktiv founded?
Synacktiv was founded in 2012. It employs 101 to 250 people.
Where is Synacktiv based?
Synacktiv is headquartered in Paris, France, in the Europe region.
How does Synacktiv make money?
Two revenue lines are on record. Professional Security Services are the primary driver. The others are commercialized Security Tools.
Who are Synacktiv's main competitors?
Direct peers on record are Bishop Fox, NCC Group, IOActive and Wavestone. Broad incumbents are Devoteam, Mandiant (Google Cloud), Trustwave and Thales Cyber Solutions. Emerging players are YesWeHack and Sekoia.io.
Does Synacktiv have an API?
Yes. RESTful API backend powered by FastAPI and gunicorn. It is asynchronous with typed endpoints and manages all requests including searches and leak management. It also manages workers for parsing and inserting new data. Authentication is performed via JWT tokens. A command line interface is available that uses this API.
What industry is Synacktiv in?
Synacktiv's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54169 and its SIC code is 8742.