Thinkst
- Company typePrivate
- Founded2010
- HeadquartersCape Town, South Africa
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
Thinkst firmographics
Firmographics- Name
- Thinkst
- Legal name
- Thinkst Applied Research
- Website
- https://thinkst.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
Thinkst industry classification
Industry- Product category
- Network Security Software
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
- akta.pro secondary industries
- Deception / Honeypot Network Security Appliances (HDAFAFAL), Deception & Honeypot-Based Network Defense (HDADABAN)
Keywords
Where Thinkst is headquartered
LocationHeadquarters
- HQ city
- Cape Town
- HQ country
- South Africa
- HQ region
- Africa
Markets served
Thinkst business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Operations, Infrastructure, Marketing or Sales
Revenue model
- Thinkst Canary Subscription: Paid subscription service for Thinkst Canary devices and management platform. Physical canary devices deployed by customers combined with cloud-based management and alerting.
- Canarytokens (Freemium): Free service available without signup. Provides value to the security community and drives awareness for the commercial Thinkst Canary product.
- Open Canary (Open Source): Open source daemon freely available for self-hosting. Community-driven project maintained by Thinkst Canary.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Canarytokens - Free |
| Subscription | Annual | Thinkst Canary - Paid tiers |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels4 records
Thinkst product offering
Product offeringCore offering
Thinkst builds deception-based security products that help organizations detect network breaches early. Its commercial offering, Thinkst Canary, provides physical and virtual canary devices and a cloud management console that alert defenders when attackers interact with them. The company also offers Canarytokens (free decoy tokens), Open Canary (open-source canary daemon), ThinkstScapes (vendor-neutral security research reports), and Citation (searchable security research index).
Product overview
Thinkst offers a portfolio of deception-based security products centered around the Thinkst Canary platform. The core offering includes Thinkst Canary (the commercial deception and breach detection product), Canarytokens (free decoy token generators), and Open Canary (open-source daemon for running canary services). ThinkstScapes provides vendor-neutral quarterly research reports synthesizing information security research and events. The products work together to help defenders detect breaches early through deceptive deployment.
Differentiator
Problem solved
Functional benefit
Brands
- Canarytokens: Free, quick way to help defenders discover they've been breached by having attackers announce themselves
- Open Canary
- ThinkstScapes
Products and services
- Thinkst Canary A deception-based security product that deploys physical and virtual canary devices on a network as high-quality markers of compromise. When attackers interact with the canaries, alerts are triggered. It is aimed at enterprise security teams that need early breach detection even when other security investments have failed.
- Canarytokens A free web tool that lets defenders plant decoy tokens (URLs, documents, credentials, and other honeypot artifacts) throughout their environment so attackers announce themselves by interacting with them. It is used by security defenders to discover breaches quickly and at no cost.
- Open Canary An open-source daemon maintained by Thinkst Canary that runs emulated canary services and triggers alerts when those services are interacted with. Alerts can be sent to Syslog, email, and a companion correlator daemon. It is intended for security teams that want a customizable, self-hosted canary.
- ThinkstScapes A free, vendor-neutral quarterly research publication that synthesizes the information security landscape by reporting on key security events, research findings, conference talks, and blog posts with context, commentary, and guidance. Distributed as PDF, EPUB, and podcast to subscribers.
- Citation A constantly updated, searchable collection of security talks, conferences, and researchers, providing a public index for navigating the information security research community.
Quantifiable outcome
- Deployable in under 3 minutes even on complex networks
Companies that use Thinkst
Customer profileSegments2 records
Ideal customer profiles2 records
Thinkst technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Thinkst partnerships and signals
Strategic signalScale indicators4 records
Recent moves5 records
Expansion highlights5 records
Thinkst competitors and assessment
Company assessmentEmerging players
- Pentera: Pentera offers automated security validation (continuous adversary simulation), adjacent to Thinkst's deception-based detection. Targets similar enterprise security buyers and budgets, with a complementary rather than directly competing offering.
- Cymulate: Cymulate provides breach and attack simulation (BAS) and exposure validation, adjacent to Thinkst's deception focus. Shares the same buyer (security validation/operations leaders) but solves a different step in the kill chain — testing vs. detecting.
Direct peers
- Acalvio Technologies: Acalvio provides enterprise deception technology (ShadowPlex) for active defense, lateral movement detection, and ransomware early warning. Directly comparable to Thinkst Canary in use case, buyer (enterprise security teams), and deployment model (on-prem + cloud).
- Smokescreen IllusionNetworks: Smokescreen IllusionNetworks delivers deception technology (IllusionBLACK) with decoys and breadcrumbs for breach detection, comparable to Thinkst Canary in category and buyer, with an India-headquartered go-to-market footprint.
- CounterCraft: CounterCraft offers a deception-based threat intelligence platform with high-interaction decoys and adversary engagement capabilities. Targets similar enterprise defenders and competes in the same deception category as Thinkst.
- Attivo Networks: Attivo Networks built a deception platform (decoys, honeytokens, misdirection) closely aligned with Thinkst Canary; acquired by SentinelOne in 2022 but continues as the deception product line within SentinelOne's broader XDR stack. Direct competitor in deception-based breach detection.
- TrapX Security: TrapX provides deception-based cybersecurity solutions (deception grids, decoy assets) for early breach detection. A direct functional peer to Thinkst Canary in the deception category, particularly for OT/ICS and on-prem network environments.
Broad incumbents
- CrowdStrike: CrowdStrike's Falcon platform is a broad XDR/EDR incumbent that has expanded into identity threat detection and adversary deception-style techniques. Overlaps with Thinkst for breach detection buyers who prefer a single-vendor stack.
- SentinelOne: SentinelOne is a large XDR/endpoint security platform that acquired Attivo Networks and now bundles deception as part of its Singularity platform. Competes with Thinkst at the broader security stack level and increasingly in deception via the Attivo product line.
- Rapid7: Rapid7 offers InsightIDR (SIEM/XDR) and Metasploit-driven testing products; competes with Thinkst for security operations budget and has overlapping use cases around breach detection, honeypots, and attacker behavior analytics.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Thinkst social profiles
Digital presenceThinkst financial estimates
Financial estimateRevenue estimate
Valuation estimate
Thinkst leadership team
Management profileNumber of profiles
Profiles1 record
Thinkst funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Thinkst M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Thinkst
What does Thinkst do?
Thinkst builds deception-based security products that help organizations detect network breaches early. Its commercial offering, Thinkst Canary, provides physical and virtual canary devices and a cloud management console that alert defenders when attackers interact with them. The company also offers Canarytokens (free decoy tokens), Open Canary (open-source canary daemon), ThinkstScapes (vendor-neutral security research reports), and Citation (searchable security research index).
Is Thinkst a public or private company?
Thinkst is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Thinkst founded?
Thinkst was founded in 2010. It employs 11 to 50 people.
Where is Thinkst based?
Thinkst is headquartered in Cape Town, South Africa, in the Africa region.
How does Thinkst make money?
Three revenue lines are on record. Thinkst Canary Subscription is the primary driver. The others are canarytokens (Freemium) and open Canary (Open Source).
Who are Thinkst's main competitors?
Emerging players on record are Pentera and Cymulate. Direct peers are Acalvio Technologies, Smokescreen IllusionNetworks, CounterCraft, Attivo Networks and TrapX Security. Broad incumbents are CrowdStrike, SentinelOne and Rapid7.
Does Thinkst have an API?
No public API is recorded for Thinkst.
What industry is Thinkst in?
Thinkst's product category is Network Security Software. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting, with a secondary code of HDAFAFAL, Deception / Honeypot Network Security Appliances. Its NAICS code is 54151 and its SIC code is 7370.